Australian police have arrested two people in Perth, accusing them of being members of the TeamPCP hacking group. The individuals face more than a dozen charges, including hacking, money laundering, and other cybercrime offenses, and are expected in court later today, Thursday.
According to the Australian Federal Police, the two men are accused of widespread breaches involving the compromise and tampering of popular open-source projects. The hackers reportedly aimed to infect numerous computers to steal credentials and data, then extort victims for ransom. The FBI's cyber division chief, Brett Leatherman, stated that the alleged TeamPCP members are accused of hacking into over a thousand organisations.
TeamPCP is known for campaigns targeting the software supply chain, where hackers would modify open-source software tools. This malicious code, once installed, could steal private keys and sensitive credentials, including those used to access cloud storage and customer data. Authorities stated that over half a million credentials were stolen to facilitate further attacks.
The group is blamed for a cyberattack on the vulnerability scanner tool Trivy, which impacted companies like LiteLLM and AI recruiting startup Mercor. They are also suspected of breaching the European Commission's cloud infrastructure and targeting other open-source projects and developer apps that allowed access to tech giants such as GitHub and OpenAI. Investigations began in April 2026 after information was received from multiple cybersecurity companies.
Police have not publicly named the arrested men. However, cybersecurity journalist Brian Krebs reported that one of the alleged hackers is Ruben Thomson, who used the handle Ellis and reportedly claimed to be the leader of TeamPCP until March 2026. Australian officials announced on Wednesday that they had seized a large quantity of allegedly stolen data, devices, and other electronics, and plan to notify victims.