Australian authorities have arrested two young men accused of being principal participants in TeamPCP, a cybercrime syndicate linked to a major series of software supply-chain attacks. The suspects, Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, were arrested in Perth, Western Australia, after a joint investigation involving the Australian Federal Police, Western Australia Police Force and the FBI. Both men appeared in Perth Magistrates Court on August 27, 2026, and face a combined 14 charges.

Police allege that TeamPCP inserted malicious code into open-source software that developers around the world trusted and used in their own systems. The infected software could then reach government agencies, academic institutions and private companies without the users immediately knowing that it had been compromised. Investigators say the campaign potentially affected more than 1,000 organisations worldwide and enabled the theft of more than 500,000 credentials and authentication materials. At least 300 gigabytes of data is also believed to have been taken.

The group’s attacks focused heavily on software used by developers and technology companies, turning trusted development tools into a path for further attacks. TeamPCP has been linked to compromises involving tools and projects including Aqua Security’s Trivy, Checkmarx KICS and the AI gateway LiteLLM, with the campaign also affecting other developer platforms and software ecosystems. The attackers allegedly used stolen publishing credentials to place harmful versions of software into trusted distribution channels. This allowed malicious code to spread through normal software-development processes.

The Australian investigation began in April 2026 after the AFP and FBI received information from cybersecurity companies about the suspected syndicate. Authorities later carried out searches at properties in Cottesloe, Hamilton Hill and Mandurah, where electronic devices and other evidence were seized for forensic examination. Police allege that the two men were involved in a highly organised operation that included data intrusion, identity crime and cryptocurrency-based money laundering. Investigators also believe the suspects received cryptocurrency payments for their alleged activities, although the amount is still being determined.

Thomson faces eight charges, including alleged unauthorised modification of data, possessing and supplying data for computer offences, dealing with proceeds of crime worth $100,000 or more and failing to comply with an order relating to electronic data. Gaebler faces six computer-related charges. The offences carry serious maximum penalties, with some charges carrying possible sentences of up to 20 years. The suspects remain accused persons at this stage, and the charges have not been proven in court. Police have also warned that more arrests and charges could follow as investigators examine the seized evidence.

Authorities say the case shows how a relatively small number of compromised software components can create a much wider security problem. Australian police estimate that the global remediation costs connected to the campaign have reached hundreds of millions of dollars, while the stolen credentials could continue to create risks if they are misused later. The investigation remains active, with a large amount of seized data still being examined. The arrests represent a major international law-enforcement action against the alleged TeamPCP operation, but investigators have not yet ruled out further developments.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news