Australian Police Charge Two Men Over TeamPCP Hacking Group Linked to Open-Source Supply Chain Breaches

The Australian Federal Police, working with the FBI and the Western Australia Police Force, arrested and charged two Perth-area men on August 26, 2026 over their alleged roles in TeamPCP, a cybercrime group blamed for a string of high-profile breaches this year. Louis Michael Gaebler, 23, of Mandurah, and Ruben Ian Thomson, 21, of Cottesloe, appeared in Perth Magistrates Court on August 27 facing a combined 14 charges, according to the AFP and reporting from TechCrunch, The Hacker News and Help Net Security.

Investigators allege the pair were principal participants in a syndicate that planted malicious code in popular open-source software projects, which was then unwittingly incorporated by developers and organizations worldwide, according to the AFP statement cited by ABC News Australia. The Hacker News reported that TeamPCP has been tied to the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS, as well as the AI gateway LiteLLM, while TechCrunch reported the group has also been blamed for hacks affecting Mercor and OpenAI.

According to Help Net Security’s account of the charges, the Cottesloe man faces eight offenses including possessing and supplying data for use in computer offenses, unauthorized modification of data, failing to comply with a data-access order, and dealing with proceeds of crime worth more than AU$100,000; the maximum penalties involved range from three to twenty years’ imprisonment. Investigators searched properties in Cottesloe, Hamilton Hill and Mandurah, seizing electronic devices now undergoing forensic examination.

The AFP said the investigation began in April 2026 after it and the FBI received tips about a syndicate inserting malicious code into open-source packages used by other developers, and that “further arrests and charges have not been ruled out” as the forensic review of seized data continues, per SecurityWeek’s reporting.

The case highlights the continuing risk that open-source software supply chains pose as a vector for widescale compromise: a single tampered dependency or scanning tool can propagate into the environments of every organization that pulls it into a build pipeline, a dynamic security teams have increasingly had to account for in software composition analysis and dependency-vetting programs.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *