Australia arrests alleged TeamPCP hackers behind supply-chain attacks

TeamPCP

Australian authorities have arrested and charged two young men accused of being part of the TeamPCP hacking group linked to a string of far-reaching developer supply chain attacks.

TeamPCP is a hacking group known for widespread supply-chain attacks over the past year that targeted open-source software and developer platforms to steal credentials, authentication secrets, and source code.

High-profile attacks attributed to TeamPCP have impacted Trivy, LiteLLM, Telnyx, SAP, and TanStack packages, while the group has also breached the European Commission, Mistral AI, OpenAI, and GitHub.

image

To carry out their attacks, the threat actors injected malicious code into software hosted on open-source repositories, which developers then unknowingly incorporated into their own applications on systems used by government, academic, and private-sector organizations.

Rather than a cohesive group, the malicious activity is believed to have been carried out by a loose-knit collective of threat actors who all frequent the same hacking forums, Discord servers, and Telegram channels.

According to the Australian Federal Police (AFP), the FBI, and Western Australia Police, malicious code distributed by TeamPCP has potentially compromised over a thousand organizations worldwide, enabling the theft of half a million credentials and the exfiltration of at least 300GB of data.

“The alleged compromise of a small number of trusted software components had a significant global impact,” reads the AFP announcement.

“To date, the financial impact includes global remediation costs estimated to be hundreds of millions of dollars.”

The investigation began in April 2026, after the AFP and FBI received key information from cybersecurity firms.

The two men, aged 21 and 23, were arrested in the western Australian cities of Cottesloe and Mandurah on August 26, 2026.

Photographs of the arrests
Photographs of the two arrests
Source: AFP

During the law enforcement action, investigators also seized electronic devices and other evidence for forensic analysis.

Police allege the two men received an undisclosed amount in cryptocurrency payments for their involvement in TeamPCP operations.

After the arrests were announced, both Flare and Brian Krebs published separate investigations detailing how Telegram activity, reused aliases, accounts, and other online traces linked alleged TeamPCP members to real-world identities.

The two suspects now face a combined 14 charges related to possessing and supplying data for computer offenses and modifying data to facilitate serious crimes.

The younger of the two also faces charges for allegedly dealing with at least $100,000 in criminal proceeds and failing to comply with an order requiring access to electronic data. The charges carry maximum penalties of 3 to 20 years’ imprisonment per charge.

The AFP said further arrests or charges have not been ruled out at this stage, as it examines seized evidence.

article image

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report