All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to AI & Technology

Australian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and others

Created at 27 Aug · 2:56 PM1 source↑ Market-relevant
IN SHORT

Australian police have arrested two individuals in Perth accused of being members of the hacking group TeamPCP. The group is linked to widespread cyberattacks targeting open-source projects, aiming to steal credentials and extort victims. The arrests follow an investigation initiated in April 2026.

Key Numbers

twopeople arrested in Perth
more than a thousandorganizations hacked
over half a millioncredentials stolen
April 2026investigation start date

Who's Involved

Australian Federal Police
arrested two individuals accused of TeamPCP membership
TeamPCP
prolific hacking group blamed for high-profile hacks
Brett Leatherman
FBI cyber division chief
Ruben Thomson
alleged hacker, also known as Ellis
Brian Krebs
independent cybersecurity journalist
Australian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and others

↳ Why This Matters

The arrests highlight ongoing efforts to combat sophisticated cybercrime operations that target the software supply chain, impacting numerous organizations and potentially compromising sensitive data.

Key facts

  • Two individuals were arrested in Perth, Australia, in connection with the TeamPCP hacking group.
  • The accused face charges including hacking, money laundering, and cybercrime offenses.
  • TeamPCP is known for targeting software supply chains by modifying open-source tools.
  • The hackers allegedly stole over half a million credentials to infiltrate systems.
  • Attacks impacted companies like Mercor and LiteLLM, and potentially affected cloud infrastructure of the European Commission, GitHub, and OpenAI.
  • The investigation began in April 2026 following information from cybersecurity firms.

Australian police have arrested two individuals in Perth, accusing them of being members of the hacking group TeamPCP. The group is known for targeting software supply chains by compromising popular open-source projects to steal credentials and extort victims. The arrests follow an investigation that began in April 2026, prompted by information from multiple cybersecurity companies.

According to the Australian Federal Police, the two men face over a dozen charges related to hacking, money laundering, and other cybercrime offenses. The FBI indicated that the alleged TeamPCP members are responsible for hacking into more than a thousand organizations. The hackers' method involved infecting computers to steal sensitive data, including credentials for cloud storage systems and customer information, with over half a million credentials reportedly stolen.

TeamPCP's attacks have previously been linked to a cyberattack on the vulnerability scanner tool Trivy, affecting companies such as LiteLLM and AI recruiting startup Mercor. The group is also suspected of breaching the European Commission's cloud infrastructure and targeting other open-source projects and developer applications that provided access to major tech firms like GitHub and OpenAI.

Independent cybersecurity journalist Brian Krebs reported that one of the arrested individuals is allegedly Ruben Thomson, who uses the hacker handle Ellis and claimed to be the leader of TeamPCP until March 2026. Australian officials stated that during the arrests, a significant quantity of allegedly stolen data, along with devices and electronics, were seized. Victims of the attacks are expected to be notified.

Frequently asked questions

TeamPCP is a hacking group known for targeting software supply chains by maliciously modifying popular open-source software tools to steal credentials and extort victims.

The group is accused of compromising open-source projects, infecting computers to steal credentials and sensitive data, and targeting over a thousand organizations, including major tech companies and cloud infrastructure.

Australian officials seized a large quantity of allegedly stolen data, along with devices and other electronics from the hackers.

The investigation by Australian officials began in April 2026 after receiving information from multiple cybersecurity companies.

What Happens Next

01The arrested individuals are expected in court later on Thursday.
02Authorities plan to notify victims of the attacks.

How It Developed

Australian police arrested two individuals in Perth.
The arrested individuals are accused of being members of the hacking group TeamPCP.
TeamPCP is accused of compromising and tampering with open-source projects.
The hackers aimed to steal credentials and data to extort victims.
The FBI stated the accused hacked over a thousand organizations.
Authorities seized allegedly stolen data and electronic devices.
Victims of the attacks will be notified.

Sources

T1
Australian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and othersTechCrunch

Related Stories

OpenAI AI agents breached Hugging Face during tests, investigators say
26 Aug · 7:04 PM
AI Models Go Rogue, Hacking Third Parties in Multiple Incidents
27 Aug · 2:26 PM
Cyber insurers adapt policies as AI agents pose new risks
27 Aug · 10:06 AM
AI agents install unowned code in corporate networks
27 Aug · 2:06 PM
OpenAI agents gamed test, breached Hugging Face network
27 Aug · 1:06 PM