Australia arrests alleged TeamPCP hackers behind supply-chain attacks
Australia arrests two men linked to TeamPCP, a hacking group behind supply-chain attacks.
Summary
Australian authorities have arrested two young men accused of being part of the TeamPCP hacking group, which is responsible for numerous supply-chain attacks targeting open-source software and developer platforms. These attacks have compromised over a thousand organizations globally, leading to the theft of hundreds of thousands of credentials and significant data exfiltration. The investigation, a collaboration between Australian and US law enforcement, highlights the global impact of these attacks, with remediation costs estimated in the hundreds of millions of dollars.
Full text
Australia arrests alleged TeamPCP hackers behind supply-chain attacks By Bill Toulas August 27, 2026 09:31 AM 0 Australian authorities have arrested and charged two young men accused of belonging to TeamPCP, a hacking group linked to a string of far-reaching developer supply chain attacks. TeamPCP is a hacking group known for widespread supply-chain attacks over the past year that targeted open-source software and developer platforms to steal credentials, authentication secrets, and source code. High-profile attacks attributed to TeamPCP have impacted Trivy, LiteLLM, Telnyx, SAP, and TanStack packages, while the group has also breached the European Commission, Mistral AI, OpenAI, and GitHub. To carry out their attacks, the threat actors injected malicious code into software hosted on open-source repositories, which developers then unknowingly incorporated into their own applications on systems used by government, academic, and private-sector organizations. Rather than a cohesive group, the malicious activity is believed to have been carried out by a loose-knit collective of threat actors who all frequent the same hacking forums, Discord servers, and Telegram channels. According to the Australian Federal Police (AFP), the FBI, and Western Australia Police, malicious code distributed by TeamPCP has potentially compromised over a thousand organizations worldwide, enabling the theft of half a million credentials and the exfiltration of at least 300GB of data. "The alleged compromise of a small number of trusted software components had a significant global impact," reads the AFP announcement. "To date, the financial impact includes global remediation costs estimated to be hundreds of millions of dollars." The investigation began in April 2026, after the AFP and FBI received key information from cybersecurity firms. The two men, aged 21 and 23, were arrested in the western Australian cities of Cottesloe and Mandurah on August 26, 2026. Photographs of the two arrestsSource: AFP During the law enforcement action, investigators also seized electronic devices and other evidence for forensic analysis. Police allege the two men received an undisclosed amount in cryptocurrency payments for their involvement in TeamPCP operations. After the arrests were announced, both Flare and Brian Krebs published separate investigations detailing how Telegram activity, reused aliases, accounts, and other online traces linked alleged TeamPCP members to real-world identities. The two suspects now face a combined 14 charges related to possessing and supplying data for computer offenses and modifying data to facilitate serious crimes. The younger of the two also faces charges for allegedly dealing with at least $100,000 in criminal proceeds and failing to comply with an order requiring access to electronic data. The charges carry maximum penalties of 3 to 20 years' imprisonment per charge. The AFP said further arrests or charges have not been ruled out at this stage, as it examines seized evidence. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report Related Articles: Police seize “First VPN” service used in ransomware, data theft attacksUkraine shuts down 94 fraudulent call centers, seize millions in cashPolice dismantle Kratos phishing platform, arrest developerDutch police bust investment fraud ring stealing over €100 millionSpanish Police take down €140 million cyber fraud ring, arrest four