Key facts
- Two Australian men have been charged with participating in a cybercrime syndicate known as TeamPCP.
- The syndicate allegedly inserted malicious code into widely used open-source software to compromise thousands of global businesses.
- The men face a combined 14 charges in Australia.
- The FBI announced a U.S. indictment against one of the men, Ruben Ian Thomson.
- The cybercrime potentially compromised over 1,000 organizations, leading to the theft of over 500,000 credentials and 300 gigabytes of data.
Australian police have announced charges against two men accused of being part of a cybercrime syndicate that targeted widely used open-source software to compromise thousands of businesses globally. The men, identified as Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, face a combined 14 charges in Australia for their alleged roles in the group known as TeamPCP.
TeamPCP is accused of inserting malicious code into popular software tools, which then compromised businesses. Some of these businesses were subsequently extorted, according to an FBI advisory. The code potentially compromised over 1,000 organizations worldwide, leading to the theft of more than 500,000 credentials and over 300 gigabytes of data.
The Australian Federal Police and the FBI initiated a parallel investigation in April after receiving information from cybersecurity threat assessment companies. FBI Cyber Division Assistant Director Brett Leatherman stated that the agencies worked together to impose costs on criminal actors and combat the growing threat of software supply-chain attacks.
In addition to the Australian charges, the U.S. Attorney's Office for the Northern District of California announced a U.S. indictment against Thomson, charging him with conspiracy to commit Computer Fraud and Abuse Act violations and obtaining information from a protected computer. A threat analyst described TeamPCP as one of the most impactful threat actors of 2026, characterizing it as a "peer community of individually skilled actors."