Key facts
- Two individuals were arrested in Perth, Australia, in connection with the TeamPCP hacking group.
- The accused face charges including hacking, money laundering, and cybercrime offenses.
- TeamPCP is known for targeting software supply chains by modifying open-source tools.
- The hackers allegedly stole over half a million credentials to infiltrate systems.
- Attacks impacted companies like Mercor and LiteLLM, and potentially affected cloud infrastructure of the European Commission, GitHub, and OpenAI.
- The investigation began in April 2026 following information from cybersecurity firms.
Australian police have arrested two individuals in Perth, accusing them of being members of the hacking group TeamPCP. The group is known for targeting software supply chains by compromising popular open-source projects to steal credentials and extort victims. The arrests follow an investigation that began in April 2026, prompted by information from multiple cybersecurity companies.
According to the Australian Federal Police, the two men face over a dozen charges related to hacking, money laundering, and other cybercrime offenses. The FBI indicated that the alleged TeamPCP members are responsible for hacking into more than a thousand organizations. The hackers' method involved infecting computers to steal sensitive data, including credentials for cloud storage systems and customer information, with over half a million credentials reportedly stolen.
TeamPCP's attacks have previously been linked to a cyberattack on the vulnerability scanner tool Trivy, affecting companies such as LiteLLM and AI recruiting startup Mercor. The group is also suspected of breaching the European Commission's cloud infrastructure and targeting other open-source projects and developer applications that provided access to major tech firms like GitHub and OpenAI.
Independent cybersecurity journalist Brian Krebs reported that one of the arrested individuals is allegedly Ruben Thomson, who uses the hacker handle Ellis and claimed to be the leader of TeamPCP until March 2026. Australian officials stated that during the arrests, a significant quantity of allegedly stolen data, along with devices and electronics, were seized. Victims of the attacks are expected to be notified.
