Australian police arrest two over TeamPCP attacks

Police say the suspects were tied to TeamPCP attacks on open source tools, a case that raised concerns for companies relying on shared software.
Australian police have arrested two men in Perth in connection with TeamPCP, a hacking group accused of carrying out a string of high-profile cyberattacks. The case stands out because the group is linked to breaches that may have hit not just individual companies, but the broader software supply chain used by thousands of organizations. Authorities say the attackers aimed to steal credentials and data, then use that access to extort victims.
The arrests were announced as investigators described a campaign they say stretched well beyond Australia. According to police, the two men face more than a dozen charges related to hacking, money laundering, and other cybercrime offenses, and they were expected in court later on Thursday.
Police say TeamPCP tampered with open source projects
In a statement, the Australian Federal Police said the suspects are accused of widespread breaches involving the compromise and tampering of popular open source projects. Authorities say the goal was to infect as many computers as possible, steal credentials and data, and then demand ransom payments.
That tactic is especially troubling because open source tools are often reused across many businesses and developer environments. A malicious version of one widely used tool can spread damage from a single project to many users. Police said the hackers stole more than half a million credentials to support further attacks on other companies.
The FBI’s cyber division chief Brett Leatherman said the two alleged TeamPCP members are accused of hacking into more than a thousand organizations as part of the campaign.
Trivy breach put major tech users in focus
One of the attacks linked to TeamPCP involved Trivy, a popular vulnerability scanner. According to the source, the incident affected any company relying on the tool, including LiteLLM, AI recruiting startup Mercor, and others.
The group was also suspected of breaching the European Commission’s cloud infrastructure. Investigators further linked TeamPCP to attacks on other open source projects and developer apps that provided access to tech companies such as GitHub and OpenAI.
That helps explain why the case has drawn attention beyond cybersecurity circles. When attackers compromise software that developers and companies trust, the fallout can move through ordinary business operations, cloud access, and customer data systems. As IT-PUB News notes, the source does not say how many victims were directly affected in each case, but it does show why supply-chain attacks are treated as a serious threat.
The investigation started with tips from cybersecurity firms
Australian officials said their investigation began in April 2026 after they received information from multiple cybersecurity companies. The arrests followed a months-long inquiry, not a response to a single incident.
Police have not named the two men who were arrested. Independent cybersecurity journalist Brian Krebs, however, reported that one of them is Ruben Thomson, who uses the hacker handle Ellis. Krebs said he had been in contact with Ellis over the past several months and that the hacker told him he had led TeamPCP until March 2026.
Krebs also said Ellis made mistakes that allowed him to identify the person’s real identity. Police did not confirm that detail in the source text, but it helps explain how the alleged suspect became publicly linked to the case.
Seized data could help police find more victims
During a press conference on Wednesday, Australian officials said they had seized a large amount of allegedly stolen data, along with devices and other electronics taken from the hackers. They also said they planned to notify victims of the attacks.
The source does not say what kind of data was recovered or how many victims will be contacted. Even so, the seizure suggests investigators may now have material that could help trace the scale of the campaign and identify affected organizations.
It also remains unclear whether the U.S. Justice Department plans to seek extradition, and an FBI spokesperson did not immediately comment when contacted by TechCrunch. So while the arrests mark a major step in the Australian investigation, the international legal side of the case is still unresolved.
For companies that depend on open source tools, the case underlines how much trust is built into everyday software. One malicious change in a widely used project can ripple through cloud systems, developer accounts, and business data.