TeamPCP Hackers Arrested for Major Supply Chain Attacks

TeamPCP Hackers Arrested for Major Supply Chain Attacks

First seen 27 Aug 2026, 11:59 UTC Abc.AuFeeds.FeedburnerThehackernewsDatabreachesBleepingcomputer+15 70.2

Article Content

Browse articles
ThreatCluster

On August 26, 2026, Australian Federal Police arrested two men, Ruben Thomson and Louis Gaebler, linked to the TeamPCP hacking group. This group is notorious for sophisticated supply chain attacks that compromised over 1,000 organizations globally, stealing more than 500,000 credentials and exfiltrating at least 300GB of data. The attacks involved injecting malicious code into popular open-source software, including Trivy, LiteLLM, and Telnyx, which developers unknowingly integrated into their applications. The investigation, which began in April 2026, involved collaboration between the AFP and the FBI. Both suspects face multiple charges, including unauthorized data modification and dealing in criminal proceeds. The financial impact of their actions is estimated to be in the hundreds of millions of dollars. Further arrests may occur as the investigation continues.

Key Points: • Two alleged TeamPCP hackers arrested in Australia for supply chain attacks. • Over 1,000 organizations compromised, with more than 500,000 credentials stolen. • Malicious code was injected into popular open-source software, impacting global businesses.

Timeline

2026-04-01
Investigation into TeamPCP begins
The AFP and FBI started investigating TeamPCP after receiving information from cybersecurity firms.
BleepingComputer
2026-07-29
Public exploit for CVE-2026-60004 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2026-08-26
Arrests made in Perth
Ruben Thomson and Louis Gaebler were arrested in connection with TeamPCP's cybercrime activities.
TechCrunch
2026-08-27
Charges announced
Both men were charged with a total of 14 offenses related to their cybercrime activities.
Cyberscoop