Australian Police Arrest Two Suspected TeamPCP Hackers Linked to Major Cyberattacks

Australian police arrested two people accused of hacking campaigns targeting open-source projects, tech companies, and sensitive data using TeamPCP.

Aug 28, 2026 - 17:46
 1
Australian Police Arrest Two Suspected TeamPCP Hackers Linked to Major Cyberattacks
IMAGE CREDITS: AUSTRALIAN FEDERAL POLICE

Australian authorities have arrested two people accused of being members of TeamPCP, a cybercrime group linked to a series of high-profile attacks targeting software supply chains, open-source projects, and technology companies.

The Australian Federal Police said the two men were charged with multiple offences involving hacking, money laundering, and other cybercrime activities. The arrests followed a joint investigation involving Australian and U.S. authorities.

Investigators allege the group compromised open-source software projects and modified code to distribute malicious tools designed to steal credentials and sensitive information. Authorities said the stolen data was then used to expand attacks and pressure victims for ransom payments.

TeamPCP accused of large-scale supply chain attacks

TeamPCP has been linked to supply chain attacks, in which attackers compromise widely used software tools to reach many organisations at once. These attacks can affect companies that rely on trusted open-source projects without realising the software has been altered.

Authorities said the group targeted developer tools and software used across the technology industry. Investigators alleged that the hackers stole more than half a million credentials during their campaigns, allowing further access into cloud services and company systems.

One of the attacks involved the popular vulnerability-scanning tool Trivy, which was compromised as part of a supply chain campaign targeting organisations that relied on the software. Ars Technica reported on the incident and its impact on users of the security tool.

Investigations linked hackers to major technology targets

The group has also been accused of targeting companies and platforms connected to major technology services. Investigators said the campaigns affected organisations including AI-related companies and projects connected to developer infrastructure.

Authorities said their investigation began in April 2026 after receiving information from multiple cybersecurity companies. During the arrests, officials seized devices, electronics, and a large amount of allegedly stolen data.

Australian officials said they plan to notify victims affected by the attacks as the investigation continues.

Cybersecurity journalist Brian Krebs separately reported that one of the arrested individuals was allegedly linked to the hacker identity Ellis, who was described as a former TeamPCP leader. KrebsOnSecurity reported that the alleged identity was uncovered through information shared during previous interactions with the hacker.

Authorities continue investigating TeamPCP activity

The arrests represent a major disruption effort against a group accused of targeting the software supply chain, a key area of concern for cybersecurity teams because a single compromised project can expose thousands of users and organisations.

The Australian investigation remains ongoing, and authorities have not disclosed whether additional arrests or international legal actions will follow.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Angry Angry 0
Sad Sad 0
Wow Wow 0
Shivangi Yadav Shivangi Yadav’s current bio says she reports on technology-focused developments “in India”, but the same profile publishes stories about U.S. NHTSA investigations, Hugging Face, global AI startups and other international topics.