Australian police arrest two TeamPCP cyberattack suspects
Australian Federal Police arrested two men in Perth suspected of involvement with the TeamPCP hacking group. They face more than a dozen charges, including hacking computer systems, money laundering and other cybercrimes. The detainees are due to appear in court on Thursday, TechCrunch reports.
Attacks on open-source projects
According to the Australian Federal Police, the suspects are accused of large-scale hacks involving the compromise and modification of popular open-source projects. According to law enforcement, the aim was to infect a large number of computers to steal credentials and other information, and later extort ransom from the victims.
FBI Cyber Division chief Brett Leatherman said that two alleged TeamPCP members are suspected of hacking more than a thousand organizations. Law enforcement also claims that the attackers stole more than half a million credentials, which they could have used for further intrusions into other companies' systems.
More current news is available on the UA.News Telegram channel Telegram.
Possible targets of the group
TeamPCP has been linked to software supply-chain attack campaigns. Under this scheme, the attackers gained access to widely used open-source tools and introduced malicious changes into them. After such software was installed, the malicious code could steal private keys and other confidential data to access cloud storage and, often, customer data.
The group was accused of an attack on Trivy, a popular vulnerability-scanning tool. It affected companies using the product, including LiteLLM and the AI recruitment startup Mercor. The hackers are also suspected of infiltrating the European Commission's cloud infrastructure and attacking other open-source projects and developer tools that could provide access to GitHub and OpenAI.
Australian police launched an investigation in April 2026 after receiving information from several cybersecurity companies. At a press conference dedicated to the arrests, officials reported the seizure of a significant volume of allegedly stolen data, devices and other electronics. Police also said they intended to notify the victims of the attacks.