← All stories
● Covered by 5 sources · 5 reportsHigh impact5 neutral

Australian Police Charge Two Men in Connection with TeamPCP Supply Chain Attacks

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Two men charged with 14 offenses related to TeamPCP.
  • TeamPCP allegedly compromised over 1,000 organizations.
  • Over 500,000 corporate credentials were exfiltrated.
  • Attacks targeted open-source projects and developer tools.
  • FBI advised organizations to treat exfiltrated data as persistent risk.

Arrests and Charges

The Australian Federal Police (AFP) and Western Australia Police Force (WAPF) have charged Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, in connection with the TeamPCP cybercrime group. The two men appeared in Perth Magistrates Court on August 27, 2026, following search warrants executed at properties in Cottesloe, Hamilton Hill, and Mandurah.

Gaebler faces six charges, while Thomson faces eight, including unauthorized modification of data, supplying and possessing data for computer offenses, and dealing with proceeds of crime worth $100,000 or more. Police allege both men were principal participants in the syndicate and received cryptocurrency payments.

TeamPCP's Activities

TeamPCP is accused of conducting widespread supply chain attacks that compromised over 1,000 organizations globally. These attacks involved injecting malicious code into software hosted on open-source repositories, which developers then incorporated into their applications.

The group targeted open-source security scanners and AI gateways, including Aqua Security’s Trivy, Checkmarx’s KICS, and PyPI’s LiteLLM. Other reported targets include Telnyx, SAP, TanStack packages, the European Commission, Mistral AI, OpenAI, and GitHub.

Impact of the Attacks

The attacks led to the exfiltration of over 500,000 corporate credentials from compromised continuous integration and continuous delivery (CI/CD) pipelines. TeamPCP allegedly transformed corporate software pipelines into data-harvesting networks, funneling stolen cloud access keys and infrastructure secrets to extortion and ransomware groups.

The Federal Bureau of Investigation (FBI) issued an advisory on July 2, stating that organizations impacted by the campaign should consider exfiltrated data and credentials as a persistent risk. The FBI recommended rotating all CI/CD secrets, publishing tokens, and cloud credentials accessible during the exposure.

Legal Proceedings and Potential Penalties

Thomson faces potential prison sentences ranging from 3 to 20 years for each of his charges, which include computer hacking and money laundering. Gaebler's most serious computer hacking charges carry a maximum sentence of 5 years. The value of the cryptocurrency payments received by the alleged syndicate members is currently under investigation.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~20 min · 17 stories · Aug 27

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Australian Federal Police arrested two individuals in Perth, accused of being members of the TeamPCP hacking group. The group is responsible for compromising open-source projects to steal credentials and data from over a thousand organizations, including attacks on Mercor and suspected breaches targeting OpenAI and the European Commission.

Australian authorities have arrested and charged two individuals suspected of being part of the TeamPCP hacking group, which is linked to widespread developer supply chain attacks. These attacks compromised open-source software and developer platforms, leading to the theft of credentials and source code from over a thousand organizations globally, with remediation costs estimated in the hundreds of millions of dollars.

Australian authorities have charged two men, Ruben Ian Thomson and Louis Michael Gaebler, with a combined 14 offenses for their alleged roles in the TeamPCP cybercrime group. TeamPCP is accused of conducting supply-chain attacks that compromised over 1,000 organizations worldwide and exposed more than 500,000 credentials, impacting developer tools and AI systems.

Australian authorities arrested Ruben Ian Thomson and Louis Michael Gaebler, suspected members of the cybercrime group TeamPCP, on charges related to computer hacking and money laundering. TeamPCP compromised software supply chains and developer tools to steal over 500,000 corporate credentials, impacting more than 1,000 organizations worldwide.

The Australian Federal Police (AFP) has charged two men from Western Australia with 14 offenses related to their alleged involvement in TeamPCP, a cybercrime group responsible for supply chain attacks on open-source projects like Trivy, Checkmarx KICS, and LiteLLM. These charges follow an FBI advisory warning organizations about persistent risks from exfiltrated data and credentials due to the group's activities.