[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fCDVnjeftkSTD3PvrFfR8WkAMK1Z9fXYti_nye-M2Qnk":3},{"article":4,"iocs":38,"watch_terms":43},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":18,"category":19,"article_tags":22},"2aca5db4-0a8b-4ac8-9f03-0c5dead3a37a","TeamPCP Breaches Cloud, SaaS Instances With Stolen Credentials","teampcp-breaches-cloud-saas-instances-with-stolen-credentials","The threat group's shift to speedy attacks on AWS, Azure, and SaaS instances shows organizations need to respond quickly to compromised credentials.","TeamPCP has shifted its attack strategy to target AWS, Azure, and SaaS instances using compromised credentials, demonstrating a focus on rapid exploitation of cloud environments. The group's ability to quickly pivot to cloud infrastructure highlights the critical need for organizations to implement faster detection and response protocols for credential compromise incidents.","TeamPCP threat group breaches cloud and SaaS instances using stolen credentials.",null,"https:\u002F\u002Fwww.darkreading.com\u002Fcloud-security\u002Fteampcp-breaches-cloud-saas-instances-stolen-credentials","https:\u002F\u002Feu-images.contentstack.com\u002Fv3\u002Fassets\u002Fblt6d90778a997de1cd\u002Fbltc0adc75ba38320bc\u002F69cc20666d4b6c62a6224f3a\u002Fcloud_RanczAndrei_Alamy.jpg?width=1280&auto=webp&quality=80&disable=upscale","2026-03-31T20:02:28+00:00","2026-03-31T22:00:21.138073+00:00",7,[],"2e06f76c-d5b9-4f54-9eef-4d3447b10730",{"id":18,"icon":11,"name":20,"slug":21},"Breaches","breaches",[23,28,33],{"category":24},{"id":25,"icon":11,"name":26,"slug":27},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":29},{"id":30,"icon":11,"name":31,"slug":32},"c70f3a41-2f0c-4608-870d-b8cbcd8be076","Cloud Security","cloud-security",{"category":34},{"id":35,"icon":11,"name":36,"slug":37},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[39],{"type":40,"value":41,"context":42},"malware","TeamPCP","Threat actor group conducting credential-based attacks against cloud and SaaS instances",[]]