All NewsEducationTVBrokers
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to AI & Technology

Australian police arrest two men accused of widespread open-source software hacking

Created at 31 Aug · 4:11 PM1 source↑ Market-relevant
IN SHORT

Australian police have charged two men, identified as Ruben Ian Thomson and Louis Michael Gaebler, with participating in a cybercrime syndicate that compromised thousands of global businesses by inserting malicious code into open-source software. The FBI also announced a U.S. indictment against Thomson.

Key Numbers

14combined charges against the two men
1,000+organizations potentially compromised globally
500,000+credentials stolen
300gigabytes of data stolen

Who's Involved

Ruben Ian Thomson
21-year-old Australian man charged in cybercrime syndicate
Louis Michael Gaebler
23-year-old Australian man charged in cybercrime syndicate
TeamPCP
Hacking collective accused of compromising businesses via open-source software
Australian Federal Police
Law enforcement agency that announced charges against the two men
FBI
Agency that conducted a parallel investigation and announced a U.S. indictment
Brett Leatherman
FBI Cyber Division Assistant Director
Austin Larsen
Principal threat analyst with Google Threat Intelligence Group

↳ Why This Matters

The arrests highlight the significant threat posed by software supply-chain attacks, where vulnerabilities in widely used open-source software can impact thousands of organizations globally, leading to data theft and extortion.

Key facts

  • Two Australian men have been charged with participating in a cybercrime syndicate known as TeamPCP.
  • The syndicate allegedly inserted malicious code into widely used open-source software to compromise thousands of global businesses.
  • The men face a combined 14 charges in Australia.
  • The FBI announced a U.S. indictment against one of the men, Ruben Ian Thomson.
  • The cybercrime potentially compromised over 1,000 organizations, leading to the theft of over 500,000 credentials and 300 gigabytes of data.

Australian police have announced charges against two men accused of being part of a cybercrime syndicate that targeted widely used open-source software to compromise thousands of businesses globally. The men, identified as Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, face a combined 14 charges in Australia for their alleged roles in the group known as TeamPCP.

TeamPCP is accused of inserting malicious code into popular software tools, which then compromised businesses. Some of these businesses were subsequently extorted, according to an FBI advisory. The code potentially compromised over 1,000 organizations worldwide, leading to the theft of more than 500,000 credentials and over 300 gigabytes of data.

The Australian Federal Police and the FBI initiated a parallel investigation in April after receiving information from cybersecurity threat assessment companies. FBI Cyber Division Assistant Director Brett Leatherman stated that the agencies worked together to impose costs on criminal actors and combat the growing threat of software supply-chain attacks.

In addition to the Australian charges, the U.S. Attorney's Office for the Northern District of California announced a U.S. indictment against Thomson, charging him with conspiracy to commit Computer Fraud and Abuse Act violations and obtaining information from a protected computer. A threat analyst described TeamPCP as one of the most impactful threat actors of 2026, characterizing it as a "peer community of individually skilled actors."

Frequently asked questions

TeamPCP is described as a hacking collective or a "peer community of individually skilled actors" that allegedly inserted malicious code into open-source software to compromise businesses.

The syndicate targeted widely used open-source software tools, inserting malicious code into them.

The malicious code potentially compromised over 1,000 organizations globally, leading to the theft of more than 500,000 credentials and over 300 gigabytes of data. Some businesses were also extorted.

In Australia, they face a combined 14 charges. In the U.S., Thomson faces charges of conspiracy to commit Computer Fraud and Abuse Act violations and obtaining information from a protected computer.

What Happens Next

01Further legal proceedings are expected in both Australia and the United States for the accused individuals.

How It Developed

Australian police announced charges against two men accused of participating in the TeamPCP hacking collective.
The men allegedly inserted malicious code into popular open-source software tools to compromise businesses.
The FBI stated that some compromised businesses were later extorted.
The malicious code potentially compromised over 1,000 organizations globally, leading to the theft of over 500,000 credentials and 300 gigabytes of data.
The Australian Federal Police and FBI began a parallel investigation in April.
The U.S. Attorney's Office for the Northern District of California announced a U.S. indictment against Thomson.
A threat analyst described TeamPCP as one of the most impactful threat actors of 2026.

Sources

T1
Australian police arrest two men accused of widespread open-source software hackingReuters

Related Stories

AI cyber risk top global financial stability concern, watchdog warns
31 Aug · 6:04 AM
Meta removes ads for fraud apps posing as porn after India sounds alarm
31 Aug · 1:24 PM
EU places ChatGPT, Reddit, Roblox under strict Digital Services Act rules
31 Aug · 10:12 AM
Sony, Warner Music sue Anthropic over AI training data
31 Aug · 2:40 PM
Adobe offers free AI tools in Saudi Arabia via $4B deal
31 Aug · 10:16 AM