Technology
Australian police arrest two alleged TeamPCP hackers
The suspects face multiple cybercrime and money laundering charges in connection with widespread software supply chain attacks.
The short version
- Australian federal police arrested two men in Perth accused of being members of the prolific cybercriminal group TeamPCP.
- The hackers are accused of compromising popular open-source software tools to infect more than 1,000 organizations and steal private credentials.
- Prominent targets and victims of the group's campaigns include OpenAI, GitHub, the European Commission, and AI recruiting startup Mercor.
Key facts
- Australian authorities arrested two men in Perth on charges including hacking, money laundering, and other cybercrime offenses.[TechCrunch]
- According to the FBI, the suspects are accused of breaching more than a thousand organizations by compromising open-source software projects.[TechCrunch]
- The group's tactics involved tampering with open-source tools to steal credentials and data, and then extorting victims for ransom.[TechCrunch]
- Security incidents linked to TeamPCP affected the vulnerability scanner Trivy, LiteLLM, Mercor, the European Commission's cloud infrastructure, GitHub, and OpenAI.[TechCrunch]
- Independent cybersecurity journalist Brian Krebs identified one of the arrested suspects as Ruben Thomson, known online as 'Ellis', who claimed to have led TeamPCP until March 2026.[TechCrunch]
- Australian police, who began their investigation in April 2026, seized stolen data and electronics and announced plans to notify affected victims.[TechCrunch]
What remains uncertain
- It remains unclear if the United States Department of Justice will seek the extradition of the suspects from Australia.[TechCrunch]