Australian Police Arrest Two in TeamPCP Global Supply Chain Hack Case
Australian authorities have charged two Perth men for their roles in TeamPCP, a hacking group accused of breaching over 1,000 organizations worldwide by tampering with open-source software, underscoring escalating cybercrime challenges.
By Oliver Hartmann · First published 27 Aug 2026
In brief
- Australian police arrested two Perth men, Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, on August 27, 2026.
- The men are charged with hacking, credential theft, and money laundering linked to the TeamPCP cybercrime group.
- TeamPCP is accused of breaching over 1,000 organizations worldwide, including major tech firms like OpenAI and Mercor.
- The group's malware campaign reportedly stole over 500,000 login credentials by inserting malicious code into open-source software.
- Investigations are ongoing, with authorities focusing on the full scope of TeamPCP's activities and potential further arrests.
Timeline · 6 moments
Two Australians charged for principal roles in TeamPCP hacks
iTnews ↗Australian Federal Police detain alleged TeamPCP hackers in Perth
Krebs on Security ↗OpenAI and others targeted in TeamPCP supply chain attacks
TechCrunch ↗Australian authorities, FBI arrest alleged TeamPCP masterminds
The Register - Security ↗Shai-Hulud hackers charged over global supply chain crime spree
Graham Cluley ↗Authorities arrest two alleged TeamPCP members in major cybercrime case
Ars Technica ↗How it started
The cybercrime group known as TeamPCP emerged as a significant threat by targeting the software supply chain. According to BleepingComputer and other outlets, the group specialized in planting malicious code within open-source software projects. This method allowed them to reach a wide range of organizations indirectly, as these compromised projects were integrated into the systems of major companies and services.
SecurityWeek reported that TeamPCP's campaign resulted in breaches of more than 1,000 organizations globally. Among the affected were high-profile technology firms, including OpenAI. The attacks often involved stealing login credentials through hidden malware, as noted by Security Affairs.
For months, Australian authorities worked to uncover those responsible, tracking activity that led back to Western Australia. The investigation highlighted the vulnerability of open-source software and the growing sophistication of cybercriminal syndicates.
How it unfolded
On August 27, 2026, news broke that the Australian Federal Police had arrested two men in Perth in connection with TeamPCP. Outlets including BankInfoSecurity.com, iTnews, and Krebs on Security reported that the suspects were Ruben Ian Thomson, aged 21, and Louis Michael Gaebler, aged 23. They were described as principal participants in the hacking group.
According to Help Net Security, the men allegedly inserted malicious code into open-source software, enabling them to compromise organizations worldwide. BleepingComputer detailed that the attacks involved stealing credentials and sensitive data from victims. The malware campaign reportedly netted over 500,000 login credentials, according to Security Affairs.
Australian police conducted searches in several Perth suburbs as part of their investigation, as reported by The Record by Recorded Future. The operation was extensive and also involved cooperation with international law enforcement agencies, including the FBI, The Register noted.
The group's activities included the use of the Shai-Hulud worm, a piece of malware that spread through open-source repositories. TechCrunch highlighted that the affected targets included major tech companies like OpenAI and Mercor. The arrests came after months of what Cyberscoop described as "software supply-chain chaos" linked to TeamPCP's operations.
Where it stands
As of August 28, 2026, the two men face multiple charges related to hacking, credential theft, and money laundering. Australian authorities have not yet detailed all the charges, but outlets agree the case is one of the most significant recent cybercrime crackdowns in the country.
Investigations continue, with law enforcement focusing on the full scope of TeamPCP's activities and potential further arrests. The story has raised alarm about the security of open-source software and the global risks posed by supply chain attacks.
What to watch
The next steps include court proceedings for the two accused men and possible further revelations about TeamPCP's reach and collaborators. Authorities may also disclose more about how the group operated and whether additional members or victims will be identified.


