< Back to all clusters
[TECHNOLOGY] · Australia, United States · 3 sources

started · updated

Australian men arrested for alleged TeamPCP supply chain attacks

Two men in Western Australia have been arrested and charged in connection with the cybercriminal group TeamPCP. The group is allegedly responsible for a massive wave of software supply chain attacks that impacted the open-source coding community throughout 2026.

A joint investigation involving the Australian Federal Police, the Western Australia Police Force, and the US Federal Bureau of Investigation revealed that the group’s malicious code potentially compromised more than 1,000 organisations globally. The campaign targeted government, academic, and private sector entities, resulting in the theft of over 300 gigabytes of data and more than 500,000 credentials.

Authorities estimate the global remediation costs stemming from these attacks reach hundreds of millions of dollars. The group’s tactics involved exploiting trusted software components, such as a misconfigured GitHub Actions workflow and poisoning CI/CD pipelines, to spread malicious code through widely used tools.

Entities

Australian Federal Police · Federal Bureau of Investigation · TeamPCP · Western Australia Police Force