Back to Feed
Nation-stateAug 27, 2026

Australia Arrests 2 Alleged TeamPCP Hackers

Australia arrests two alleged TeamPCP hackers involved in supply chain compromises.

Summary

Australian authorities have arrested two individuals, Ruben Ian Thomson and Louis Michael Gaebler, suspected of being members of the cybercrime group TeamPCP. The group is accused of compromising software supply chains and developer security tools, leading to the theft of over 500,000 corporate credentials and causing hundreds of millions of dollars in financial losses worldwide. The arrests are part of a collaboration between Australian and US authorities.

Full text

Two men suspected of being members of the notorious cybercrime group TeamPCP have been arrested and charged by Australian authorities. The suspects, Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, have been arrested in Perth. They face several charges related to their alleged role in a cybercrime syndicate that is believed to have caused financial losses totaling hundreds of millions of dollars. Thomson has been charged with five types of offenses related to computer hacking and money laundering. He faces between 3 and 20 years in prison for each charge. Gaebler has been charged with computer hacking, and the most serious counts carry a maximum prison sentence of 5 years. TeamPCP compromised major software supply chains and developer security tools, including Aqua Security’s Trivy, Checkmarx’s KICS, and PyPI’s LiteLLM, to siphon over 500,000 corporate credentials from compromised CI/CD pipelines. By hijacking automated build workflows and popular package registries, the group systematically transformed corporate software pipelines into data-harvesting networks, funneling stolen cloud access keys and infrastructure secrets to extortion and ransomware groups. TeamPCP deployed the Mini Shai-Hulud worm (and likely the original Shai-Hulud) to automate credential theft and self-propagation across package registries at scale.Advertisement. Scroll to continue reading. According to Australian police, the hacker group exfiltrated at least 300 GB of data from more than 1,000 organizations worldwide. Police have seized devices belonging to Thomson and Gaebler and are working to determine how much money they have earned from their illegal activities. “A large volume of data seized is being forensically examined and the investigation remains ongoing. Further arrests and charges have not been ruled out,” the Australian Federal Police announced on Thursday. Related: Admins of Bulletproof Hosting Service Used by Russian Hackers Arrested in Netherlands Related: Two Scattered Spider Hackers Sentenced to Jail in UK Related: Third US Security Expert Sentenced to Prison for Helping Ransomware Gang Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs AI Speeds Up Malware Development, Not Its Success Rate: AnalysisAdobe and Nvidia Patch Dozens of VulnerabilitiesCISA: Over 100 Internet-Exposed Water Systems Targeted in July CyberattacksChrome 152 Patches Over 300 VulnerabilitiesSensitive Information Exposed in Nutex Health Data BreachCISA Warns of Exploited Gitea VulnerabilityLinux Foundation to Govern TRACE, an Open Standard for AI Runtime AttestationWordPress Websites Targeted via MiniOrange Plugin Vulnerabilities Latest News OpenAI Agents Coordinated via Makeshift Message Board Ahead of Hugging Face HackOkta Shares Surge on Strong Earnings, Growing Demand for AI Identity SecurityCISO Conversations: Chris Wheeler – Trust Is the Job, From the Navy to the C-SuiteCyberattack Causes Global Disruption at Boston ScientificThe Future of AI-Driven Security Depends on Complete DataUS Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure AttacksPro-Russian Hackers Claim Responsibility for Major Cyberattack on Norway’s Public Digital ServicesRecent Citrix NetScaler Vulnerability Exploited in the Wild Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Scaling AI Security August 26, 2026 Join this live webinar for a practical framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveNaveen Bhateja has been appointed Chief People Officer at HackerOne.The Department of War has appointed Sonu Shankar as Principal Deputy Chief Information Officer.Trellix has named David Pieterse as Chief Operating Officer GTM and David Soto as Chief Information Security Officer.More People On The MoveExpert Insights The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Rethinking Application Security for the AI Era As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. (Joshua Goldfarb) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • malware — Mini Shai-Hulud
  • malware — Shai-Hulud

Entities

TeamPCP (threat_actor)Trivy (product)Aqua Security (vendor)KICS (product)Checkmarx (vendor)LiteLLM (product)