← Back to Daily Briefing (#LawEnforcement)

TeamPCP: Open-Source Software Supply Chain Campaign

Published August 29, 2026

A joint international operation led by the Australian Federal Police (AFP), the FBI, and the Western Australia Police Force (WAPF) has resulted in the arrest of two key members of the TeamPCP cybercrime group. The group specialized in high-impact supply chain attacks by injecting malicious code into widely utilized open-source software repositories. This technique facilitated large-scale credential theft, successfully exfiltrating over 500,000 user and organizational credentials from a global victim base. The arrests target Ruben Thomson, the alleged group leader, and Louis Gaebler, marking a significant disruption to a major global threat actor responsible for one of the most damaging hacking campaigns of the current year.

  • Incident Overview: Multi-Agency Law Enforcement Action
    • Coordinated operation involving the AFP, FBI, and WAPF.
    • Targeted arrests executed in Cottesloe and Mandurah, Western Australia.
    • Focused on dismantling the operational capacity of the TeamPCP group.
  • Attack Vector: Software Supply Chain Poisoning
    • Utilization of "poisoning" tactics within the open-source software ecosystem.
    • Injection of malicious code into legitimate software libraries to compromise downstream users.
    • Exploitation of trusted software update mechanisms to bypass organizational perimeters.
  • Threat Group Profile: TeamPCP Capabilities
    • Alleged leadership by 21-year-old Ruben Thomson.
    • Identified as a high-scale threat actor responsible for massive global breaches.
    • Specialization in automated, high-volume credential harvesting.
  • Impact Scale: Mass Credential Exfiltration
    • Successful exfiltration of over 500,000 sets of user and organizational credentials.
    • Global impact affecting diverse organizations through compromised dependencies.
    • Primary objective achieved through sophisticated malicious code injections.
  • Conclusion: Defense and Strategic Implications
    • Highlights the critical systemic risk posed by unvetted open-source dependencies.
    • Demonstrates the necessity of international law enforcement and intelligence collaboration.
    • Underscores the requirement for enhanced Software Bill of Materials (SBOM) and dependency integrity auditing.

Related posts

  1. Cybersecurity News — Two Australians Charged Over TeamPCP Supply-Chain Attacks That Hit 1,000+ Organizations
  2. Risky Business Newsletters — Risky Bulletin: Two TeamPCP members arrested in Australia
  3. iTnews — Two Aussies alleged to be "principal participants" of TeamPCP hacking group
  4. thehackernews.com — Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
  5. The Record by Recorded Future — Australia charges two men for TeamPCP supply-chain hacking spree
  6. www.helpnetsecurity.com — Two alleged TeamPCP hackers arrested over global supply chain attacks
  7. Security Affairs — Australian Police Charge Two Over TeamPCP Credential Theft
  8. cyberscoop.com — Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos
  9. esecurityplanet.com — Two Arrested in Australia Over TeamPCP Supply Chain Attacks
  10. news.risky.biz — Risky Bulletin: Two TeamPCP members arrested in Australia
  11. Frpafraudviewer
  12. Cybersecpods
  13. F4n6
  14. Ramimac
  15. Facebook
  16. Secarma
  17. Facebook
  18. SecurityWeek — Australia Arrests 2 Alleged TeamPCP Hackers

LINK COPIED TO CLIPBOARD