
Australian authorities charged Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, with 14 offences following a joint investigation into the alleged TeamPCP cybercrime syndicate. According to reports from ABC, both defendants appeared before Perth Magistrates Court on August 27 after the Australian Federal Police filed charges on August 26. The operation involved the AFP, the FBI and the Western Australia Police Force, with authorities executing warrants at properties in Cottesloe, Hamilton Hill and Mandurah. The Hacker News reports that these arrests mark the first law enforcement action against the group responsible for the longest-running software supply chain attack spree ever documented.
Investigators allege the TeamPCP group compromised more than 1,000 organizations and obtained over 500,000 credentials through their malicious activities. As reported by the AFP, the syndicate allegedly stole at least 300 gigabytes of data from downstream software customers. The joint investigation began in April after several cybersecurity companies supplied intelligence about malicious software distributed through an open-source repository. The AFP estimated that responding organizations face hundreds of millions of dollars in remediation costs, though this figure reflects an official estimate rather than confirmed financial losses. Krebs on Security published a detailed investigation on August 27 identifying the group's structure, including its Cybercats Matrix server and key members, providing crucial insights into the operation's infrastructure.
According to the AFP's official release, investigators allege TeamPCP inserted malicious code into legitimate software components used by other developers. Once incorporated into downstream systems, the modified code allegedly gave the group unauthorized access to organizations across government, academia and the private sector. The AFP noted that software supply-chain attacks can spread beyond the organization hosting the original compromised code, allowing one modification to reach many unrelated systems. The infected software enabled alleged theft of credentials, authentication materials and other sensitive information, though authorities have not published a complete list of affected organizations or software packages.
The U.S. Department of Justice separately unsealed a federal indictment against Thomson, charging him with conspiracy to violate the Computer Fraud and Abuse Act and obtaining information from a protected computer. According to the Justice Department, the American charges concern alleged TeamPCP attacks during spring 2026. Thomson faces one Australian charge of dealing with money or property worth at least 100,000 Australian dollars that authorities allege represented criminal proceeds, carrying a maximum prison sentence of 20 years. Police allege the two men were principal participants in the operation and received cryptocurrency payments, though the value of those payments remains under investigation.
The AFP stated that investigators are examining a large volume of seized data and electronic devices, which may help identify additional participants, victims and financial transfers. As reported by the AFP, police have not ruled out further arrests or charges. The investigation's next phase will involve digital forensics and examination of cryptocurrency payment records, with prosecutors needing to separately prove each defendant's identity, role, intent and connection to the alleged activity. The case produced no verified cryptocurrency market reaction, as it concerns alleged use of digital assets for payments rather than blockchain vulnerabilities.