← Latest briefing

Technology

Australian police arrest two alleged TeamPCP hackers

The suspects face multiple cybercrime and money laundering charges in connection with widespread software supply chain attacks.

The short version

  • Australian federal police arrested two men in Perth accused of being members of the prolific cybercriminal group TeamPCP.
  • The hackers are accused of compromising popular open-source software tools to infect more than 1,000 organizations and steal private credentials.
  • Prominent targets and victims of the group's campaigns include OpenAI, GitHub, the European Commission, and AI recruiting startup Mercor.

Key facts

  • Australian authorities arrested two men in Perth on charges including hacking, money laundering, and other cybercrime offenses.[TechCrunch]
  • According to the FBI, the suspects are accused of breaching more than a thousand organizations by compromising open-source software projects.[TechCrunch]
  • The group's tactics involved tampering with open-source tools to steal credentials and data, and then extorting victims for ransom.[TechCrunch]
  • Security incidents linked to TeamPCP affected the vulnerability scanner Trivy, LiteLLM, Mercor, the European Commission's cloud infrastructure, GitHub, and OpenAI.[TechCrunch]
  • Independent cybersecurity journalist Brian Krebs identified one of the arrested suspects as Ruben Thomson, known online as 'Ellis', who claimed to have led TeamPCP until March 2026.[TechCrunch]
  • Australian police, who began their investigation in April 2026, seized stolen data and electronics and announced plans to notify affected victims.[TechCrunch]

What remains uncertain

  • It remains unclear if the United States Department of Justice will seek the extradition of the suspects from Australia.[TechCrunch]

Sources