Skip to content
Software Supply Chain Security

TeamPCP Hackers: Australia Arrests and Charges

TeamPCP supply chain

Australian authorities have arrested two men in Perth they suspect are linked to TeamPCP hackers. The investigation centers on alleged cybercrime activity that reportedly targeted software and developer environments, with consequences measured in the hundreds of millions of dollars.

The suspects are Ruben Ian Thomson (21) and Louis Michael Gaebler (23). According to police, both men face criminal charges connected to a cybercrime syndicate believed to have caused major financial losses.

Arrests in Perth and the nature of the charges

Thomson and Gaebler were arrested and charged by Australian authorities. The case involves multiple alleged offenses, including computer hacking-related conduct and money laundering allegations tied to the alleged criminal scheme.

Thomson has been charged with five types of offenses connected to computer hacking and money laundering. If convicted, he could face between 3 and 20 years in prison for each charge.

Gaebler has been charged with computer hacking offenses. For the most serious counts, prosecutors are seeking a maximum sentence of 5 years.

How the alleged TeamPCP approach worked

Investigators describe the suspected group’s methods as a blend of supply-chain compromise and targeting of development security tooling. The alleged strategy reportedly relied on breaking into or abusing elements that software teams trust—so the attackers could reach credential material inside normal development workflows.

Authorities say TeamPCP hackers compromised major software supply chains and developer security tools, including:

  • Aqua Security’s Trivy
  • Checkmarx’s KICS
  • PyPI’s LiteLLM

The goal, as described by police, was to siphon more than 500,000 corporate credentials from compromised CI/CD pipelines.

Turning CI/CD pipelines into data-harvesting networks

A key part of the allegation is that the group hijacked automated build workflows and used popular package registries to change how organizations’ software pipelines functioned in practice. Instead of producing only builds and deployments, the pipelines were allegedly used as harvesting infrastructure.

In this scenario, attackers could funnel stolen information—such as cloud access keys and infrastructure secrets—to other criminal operations. Police allege that this data supported extortion and ransomware groups.

Worm deployment and large-scale spread

Investigators also point to malware capability in the allegation. The suspected group allegedly deployed the Mini Shai-Hulud worm—and police believe it may have included the original Shai-Hulud—to automate credential theft while spreading across package registries at scale.

By focusing on distribution ecosystems like package registries, the alleged worm behavior would help drive repeated harvesting opportunities across many organizations, without requiring the attackers to manually compromise each target.

Data exfiltration from thousands of organizations

According to Australian police, the alleged activity led to at least 300 GB of data being exfiltrated from more than 1,000 organizations worldwide.

That scale suggests the campaign was designed for broad reach rather than a small number of isolated incidents. It also highlights why CI/CD compromise and credential theft remain major concerns for security teams that manage software delivery systems.

Evidence seized and ongoing investigation

Police have seized devices belonging to Thomson and Gaebler. Investigators are working to determine how much money the suspects may have earned from the alleged activity.

The Australian Federal Police said that a large volume of seized data is being examined using forensic methods, and the investigation is ongoing. They also indicated that additional arrests and charges have not been ruled out.

Why this case matters for developers and security teams

Cases involving TeamPCP hackers underscore a broader lesson: attackers increasingly target the tools and processes that developers rely on daily. When supply-chain elements or pipeline components are compromised, the blast radius can extend across organizations and regions.

For teams responsible for securing CI/CD environments, the allegations in this case reinforce the importance of credential hygiene, strong access controls, and continuous monitoring for unusual behavior in automated workflows.

Even though this is a criminal case and not a confirmed technical postmortem, it provides a clear map of what investigators believe went wrong: compromised tooling, pipeline abuse, credential harvesting, and downstream support for extortion and ransomware.

What happens next

At this stage, the men are charged and the investigation continues. For observers, the most important near-term updates will likely involve forensic analysis of seized devices and any additional charges that emerge as investigators connect the alleged activity to other incidents.

If police uncover more evidence, the case could expand beyond these two arrests. For now, authorities have emphasized that the examination of seized data is ongoing and further legal steps remain possible.

The situation also serves as a reminder that supply-chain and credential attacks are not theoretical. When TeamPCP hackers methods are used against development ecosystems, the result can be massive data loss and significant financial impact—exactly the kind of harm this case alleges.

Source: https://www.securityweek.com/australia-arrests-2-alleged-teampcp-hackers/