Two Aussies alleged to be "principal participants" of TeamPCP hacking group
Key points
- Two Western Australian men, aged 21 and 23, have been charged as alleged principal participants of hacking group TeamPCP following raids in Cottesloe, Hamilton Hill and Mandurah.
- The joint AFP, WA Police and FBI operation alleges TeamPCP inserted malicious code into open-source software, potentially compromising more than 1000 organisations worldwide.
- Police estimate the campaign enabled the theft of more than 500,000 credentials and the exfiltration of at least 300 gigabytes of data, with remediation costs potentially running into hundreds of millions of dollars.
Image credit: Australian Federal Police.
A pair of Western Australian men have been arrested and charged as alleged “principal participants” of the hacking group TeamPCP, known for its run of high-profile software supply chain attacks across 2026.
A joint operation by the Australian Federal Police, WA Police and the FBI led to raids at properties in Cottesloe, Hamilton Hill and Mandurah on Wednesday.
Police have laid charges against a 21-year-old man from Cottesloe and a 23-year-old man from Mandurah.
“These men are allegedly members of the cybercriminal group TeamPCP, whose malicious code potentially compromised more than a thousand organisations worldwide,” FBI cyber division assistant director Brett E. Leatherman said in a statement.
“We are proud to work with the Australian Federal Police and the Western Australia Police Force to … combat the growing threat of software supply chain attacks.”
Authorities said that “parallel investigations” by the Australian Federal Police and the FBI started in April, based on information “from multiple cyber threat assessment companies regarding a syndicate that allegedly inserted malicious code into software available on an open-source repository, which was then unwittingly used by other developers.”
“Police will allege infected software was then distributed into computer systems at other organisations across government, academia and the private sector,” the authorities said in a joint statement.
“The software allegedly enabled the syndicate to infiltrate those organisations to steal or harvest sensitive data, including user credentials and authentication materials.”
Police estimate that more than 1000 organisations worldwide were “potentially compromised”, “enabling the theft of more than 500,000 credentials, and the exfiltration of at least 300 gigabytes of data.”
Authorities said that remediation costs could run into the “hundreds of millions of dollars.”
TeamPCP is known to have compromised an open-source vulnerability scanner, publishing malicious versions that organisations unwittingly downloaded.
The group’s campaigns also hit the artificial intelligence application programming interface proxy library LiteLLM, and Checkmarx’s GitHub Actions workflows and OpenVSX plugins.
As iTnews reported earlier this month, the National Disability Insurance Agency (NDIA) was among the domestic victims of TeamPCP, although the agency suggested little damage was incurred courtesy of its defence-in-depth approach and layered tooling.
The Australian Federal Police said that industry and international cooperation was critical in positioning authorities to take action.
“The most effective law enforcement outcomes are achieved when agencies share intelligence, expertise, and resources across borders,” commander Graeme Marshall said.
“In this matter, the information provided to authorities by a number of threat assessment companies proved crucial for investigators.
“Early reporting and sustained cooperation between organisations and law enforcement play a critical role in supporting cybercrime investigations, protecting affected individuals, and mitigating the broader impact of cybercrime across the Australian community.”