Australian Federal Police have arrested two men in Perth suspected to be members of the notorious hacking group TeamPCP. The suspects face over a dozen charges including hacking and money laundering related to a series of cyberattacks targeting major tech companies earlier this year. These breaches focused on popular open source software projects, allowing the hackers to install malicious code that stole credentials and sensitive data from thousands of organizations globally.
The hackers reportedly compromised widely used tools like the vulnerability scanner Trivy, affecting firms such as AI recruiting startup Mercor and developer platforms including GitHub and OpenAI. According to FBI cyber division chief Brett Leatherman, the attackers targeted more than a thousand organizations, leveraging stolen credentials to escalate their attacks and demand ransom payments. Australian authorities have seized significant quantities of stolen data and electronic devices from the suspects during the investigation, which began in April 2026.
Independent reports identify one of the arrested individuals as Ruben Thomson, also known by the hacker alias Ellis, who purportedly led TeamPCP until March 2026. Thomson’s errors allowed cybersecurity journalists to uncover his real identity, aiding law enforcement efforts. The Australian Federal Police plan to notify all victims impacted by these cyber intrusions as legal proceedings move forward.
TeamPCP is known for its sophisticated supply chain attacks on open source software, posing a serious threat to the global tech ecosystem by compromising critical development tools. The arrests mark a significant milestone in disrupting this cybercriminal network responsible for one of the most extensive hacking campaigns of recent years, underscoring growing international cooperation in combating cybersecurity threats.
Start the discussion with a take, question, or market read.