Abstract:
Australian police recently arrested two people suspected of participating in the hacker organization TeamPCP in Perth. The group has recently been accused of orchestrating a number of high-profile cyberattacks against large technology companies. The two suspects face more than a dozen charges related to hacking, money laundering and other cyber crimes and are expected to appear in court later Thursday.

The Australian Federal Police issued a statement stating that the two men were suspected of widespread intrusion and tampering with multiple popular open source projects. Investigators believe the attackers intended to infect a large number of computers, steal account credentials and data, and then extort ransom from the victims.
Brett Leatherman, head of the FBI's cyber division, said that two suspects identified as members of TeamPCP were suspected of invading more than 1,000 organizations in a series of attacks. It was unclear whether the Justice Department planned to seek extradition to the United States; an FBI spokesman did not immediately respond to a request for comment.
TeamPCP is an active cybercriminal group known for multiple large-scale attacks targeting the software supply chain. Its usual method is to invade popular open source software tools used by many enterprises and implant malicious modifications. When contaminated software is installed on enterprise or developer systems, the malicious code steals private keys and other sensitive credentials, which can be used to access cloud storage systems and, in many cases, further expose customer data.
Law enforcement authorities said the attackers had stolen more than 500,000 sets of credentials and used the information to expand the attack to more businesses. Previously, TeamPCP was considered to be related to the attack on the well-known vulnerability scanning tool Trivy. All companies that rely on this tool may be affected, including LiteLLM, AI recruitment startup Mercor, etc.

In addition, the organization is also suspected of invading the European Commission's cloud infrastructure and targeting other open source projects and developer applications to gain access to the systems of technology giants such as GitHub and OpenAI.
Australian officials stated that the relevant investigation was launched in April 2026 after a number of cybersecurity companies provided clues to the police. Police have not yet released the identities of the two arrested men.
However, independent cybersecurity reporter Brian Krebs reported that one of the arrested suspects was Reuben Thomson, whose hacker codename was "Ellis." Krebs said he has been in contact with Ellis over the past few months, and Ellis has stated that he will serve as the leader of TeamPCP until March 2026. Krebs also pointed out that Ellis made mistakes during the event, and his true identity was eventually confirmed by the investigation.
At a press conference on Wednesday, Australian law enforcement said it had seized a large amount of suspected stolen data, as well as equipment and other electronics from the suspects. Police said they would proceed to notify the victims of the attack.
Comments