Australia Charges 2 Alleged TeamPCP Members Over Global Supply-Chain Attacks

Australian authorities charged 2 alleged TeamPCP participants over supply-chain attacks blamed for stealing 500,000 credentials from organizations worldwide.
Australian police escort a man during an operation targeting alleged TeamPCP members in Western Australia.
Australian authorities arrest one of 2 men accused of participating in TeamPCP's global software supply-chain attacks. Image credit: Australian Federal Police (AFP). Watch the AFP arrest vision.

Australian authorities have arrested and charged 2 men accused of being principal participants in TeamPCP, the cybercrime group linked to a sprawling series of software supply-chain attacks that potentially compromised more than 1,000 organizations worldwide.

The Australian Federal Police (AFP), Western Australia Police Force and FBI arrested the 21-year-old and 23-year-old men on Aug. 26 following searches at properties in Cottesloe, Hamilton Hill and Mandurah in Western Australia.

Authorities allege the pair participated in TeamPCP, a loose-knit cybercrime operation that has spent much of 2026 targeting trusted open-source software, developer infrastructure and CI/CD environments to steal credentials and gain access to downstream organizations.

According to an AFP announcement, malicious code associated with the operation potentially compromised more than 1,000 organizations globally, enabling the theft of more than 500,000 credentials and the exfiltration of at least 300GB of data.

Authorities estimate the resulting global remediation costs could reach hundreds of millions of dollars.

Police allege pair were principal TeamPCP participants

The investigation began in April 2026 after the AFP and FBI received information from multiple cybersecurity companies about a cybercrime operation allegedly inserting malicious code into software distributed through open-source repositories.

Developers and organizations that trusted those components could then unknowingly execute the malicious code inside their own environments, giving the attackers opportunities to harvest credentials and authentication material.

Investigators allege the stolen credentials allowed TeamPCP members to impersonate legitimate users, bypass security controls and gain unauthorized access to networks and cloud environments.

Electronic devices and other material were seized during the Aug. 26 searches and are now undergoing forensic examination. Police also allege the 2 men received cryptocurrency payments for their participation in the operation, although authorities have not disclosed the total amount allegedly received.

Australian police escort a handcuffed man from a vehicle during an operation targeting alleged TeamPCP members in Western Australia.
Police escort one of 2 men arrested in Western Australia over alleged involvement in TeamPCP’s global software supply-chain attacks. Image credit: Australian Federal Police (AFP). Watch the AFP arrest vision.

The FBI publicly identified the cybercrime group involved in the investigation as TeamPCP.

14 charges filed after Western Australia raids

The 2 defendants face a combined 14 charges related to the alleged possession, modification and supply of data for computer offenses.

The 21-year-old man faces 8 charges, including possession of data with intent to commit a computer offense, 4 counts of unauthorized modification of data with intent to commit a serious offense and supplying data with intent to commit a computer offense.

He is also charged with allegedly dealing with criminal proceeds worth at least $100,000 and failing to comply with an order requiring access to electronic data. The proceeds-of-crime charge carries a maximum penalty of 20 years in prison, while failure to comply with the access order carries a maximum penalty of 10 years.

The 23-year-old faces 6 charges, including possession and supply of data with intent to commit a computer offense and 4 counts relating to unauthorized modification of data.

Both men were scheduled to appear in Perth Magistrates Court on Aug. 27. The charges remain allegations and have not been proven in court.

TeamPCP turned trusted software into an attack vector

TeamPCP emerged as one of the most consequential software supply-chain threat actors of 2026 by targeting components that developers and automated build systems inherently trusted.

Security researchers have linked the group to compromises involving widely used projects including Trivy, Checkmarx KICS and LiteLLM. Rather than attacking every downstream organization individually, the attackers poisoned software or development infrastructure that was already being executed inside other organizations.

In March, malicious versions of LiteLLM were distributed through PyPI after attackers reportedly obtained publishing credentials through an earlier compromise involving the Trivy security scanner. The malicious packages were designed to harvest sensitive material including cloud credentials, API keys, SSH keys, Kubernetes secrets and environment variables.

The campaign later expanded into additional developer and package ecosystems, illustrating how credentials stolen during one supply-chain compromise could potentially provide the access needed to launch another.

That cascading model became particularly damaging because CI/CD systems frequently hold publishing tokens, cloud credentials and other secrets capable of granting access far beyond the initially compromised software project.

Campaign reached major organizations

The downstream impact extended beyond open-source maintainers. TeamPCP activity has been associated with incidents affecting technology companies, government organizations and other enterprises that consumed compromised software or whose development environments were exposed through the campaign.

OpenAI, for example, confirmed in May that 2 employee devices were affected by the TanStack supply-chain attack. The company said attackers gained unauthorized access to a limited subset of internal source code repositories and successfully exfiltrated a limited amount of credential material. OpenAI found no evidence that customer data, production systems or intellectual property were compromised.

The European Commission was also affected by a supply-chain compromise that CERT-EU assessed with high confidence originated through the compromised Trivy software. Approximately 91.7GB of compressed data was exfiltrated from an affected AWS account, with information belonging to at least 29 other European Union entities potentially impacted.

BreachNews previously reported on the European Commission incident and the roles attributed to TeamPCP and ShinyHunters, highlighting how access obtained through the software supply chain could ultimately feed into broader data theft and extortion operations.

Arrests may not end the investigation

The arrests represent a significant disruption for TeamPCP, but authorities have not described the operation as dismantled.

Public reporting and security research have characterized TeamPCP as a loose collective rather than a conventional cybercrime group with a rigid hierarchy. Participants reportedly interacted across cybercrime forums and messaging platforms, potentially complicating efforts to determine which individuals were responsible for specific stages of the group’s campaigns.

The AFP said its investigation remains ongoing and has not ruled out additional arrests or charges as investigators analyze the electronic evidence seized during the Western Australia searches.

The case also illustrates the disproportionate reach of software supply-chain compromises. By gaining control of a relatively small number of trusted development components, TeamPCP allegedly created pathways into more than 1,000 downstream organizations and exposed hundreds of thousands of credentials without needing to breach each target directly.

For TeamPCP, the arrests are the first major publicly announced law enforcement action against alleged participants in an operation that has repeatedly exploited trust relationships across the open-source software ecosystem throughout 2026.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site