< Back to all clusters
[CRIME] · Australia · 4 sources

started · updated

Australia charges two men in TeamPCP supply chain cyberattacks

Two men from Western Australia, aged 21 and 23, have been charged in connection with the TeamPCP cybercrime syndicate. The group is allegedly responsible for major supply chain attacks in early 2026 that targeted open-source security tools, including Trivy, Checkmarx KICS, and the AI gateway LiteLLM.

The Australian Federal Police and Western Australia Police Force executed search warrants in Cottesloe, Hamilton Hill, and Mandurah, seizing electronic devices for analysis. Authorities allege the suspects were principal participants in the syndicate and received cryptocurrency payments. The attacks potentially compromised more than a thousand organizations worldwide, with reports indicating the theft of approximately 500,000 credentials.

The FBI has advised impacted organizations to treat exfiltrated data as a persistent risk and to rotate all CI/CD secrets, publishing tokens, and cloud credentials. The scale of the breach includes significant remediation costs and impacts high-profile entities, including the European Commission.

Entities

Australian Federal Police · Federal Bureau of Investigation · Louis Michael Gaebler · Ruben Ian Thomson · TeamPCP