Australia arrests alleged TeamPCP hackers behind supply-chain attacks

Australian authorities have dealt a significant blow to the notorious TeamPCP hacking group, arresting and charging two young men accused of being part of the collective. The alleged hackers are linked to a string of high-profile supply-chain attacks that compromised over a thousand organizations worldwide, resulting in the theft of half a million credentials and the exfiltration of at least 300GB of data.

TeamPCP’s modus operandi involves injecting malicious code into open-source software hosted on repositories such as GitHub. Developers then unwittingly incorporate this tainted code into their own applications, which are subsequently used by government, academic, and private-sector organizations. Rather than a cohesive group, TeamPCP appears to be a loose-knit collective of threat actors who frequent the same hacking forums, Discord servers, and Telegram channels.

The investigation, led by the Australian Federal Police (AFP), began in April 2026 after receiving key information from cybersecurity firms. The two men, aged 21 and 23, were arrested on August 26 in the western Australian cities of Cottesloe and Mandurah. During the law enforcement action, investigators seized electronic devices and other evidence for forensic analysis.

The alleged hackers are accused of receiving cryptocurrency payments for their involvement in TeamPCP operations. Police also claim that one of the suspects had dealings with at least $100,000 in criminal proceeds and failed to comply with an order requiring access to electronic data. The charges carry maximum penalties of 3 to 20 years’ imprisonment per charge.

The global impact of TeamPCP’s attacks is staggering, with estimates suggesting hundreds of millions of dollars in remediation costs. The compromise of trusted software components has had a significant global impact, as noted by the AFP. Further arrests or charges have not been ruled out at this stage, as authorities examine seized evidence.

This case serves as a stark reminder of the importance of securing supply chains and open-source repositories. It also highlights the need for developers to be vigilant when incorporating external code into their applications. As cybersecurity professionals, we must remain proactive in identifying and mitigating potential vulnerabilities before they can be exploited by malicious actors.

In light of this incident, it’s essential for organizations to implement robust security measures, including regular software updates, vulnerability assessments, and employee education on cyber threats. By doing so, we can reduce the risk of supply-chain attacks and prevent the theft of sensitive data.


Source: Bleeping Computer — 2026-08-27