AUTO-UPDATED

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Australian authorities have arrested two men in Perth, identified as Ruben Thomson and Michael Gaebler, for their roles in the prolific TeamPCP cybercrime syndicate’s global software supply chain attacks.

Key Points

  • The Australian Federal Police arrested the two suspects, aged 21 and 23, for allegedly creating malicious open-source software to target thousands of businesses.
  • TeamPCP utilized a self-propagating worm called Shai-Hulud to compromise corporate cloud environments and steal credentials from public repositories like GitHub and NPM.
  • The group’s activities included a March 2026 attack on the AI gateway LiteLLM, which exposed cloud service keys for over 2,500 organizations.
  • Investigations linked the group to a "Cybercats" chat server, where members coordinated attacks and taunted victims, often leaving significant digital footprints.
  • The arrests follow a series of high-profile breaches affecting major companies, including Honda, Toyota, and Novo Nordisk.

Why it Matters

The dismantling of TeamPCP highlights the growing danger posed by loosely organized, tech-savvy threat actors who leverage AI and open-source vulnerabilities to operate at massive scale. While their disruptive tactics forced major platforms like GitHub to implement critical security safeguards, their lack of operational discipline ultimately led to their identification and capture.
Krebs on Security Published by BrianKrebs
Read original