Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Refract AI Intelligence Digest

BLUF

Two alleged members of the TeamPCP cybercrime syndicate were arrested in Australia for orchestrating widespread software supply chain attacks.

NEWS

The Australian Federal Police detained two suspects, aged 21 and 23 from Western Australia, linked to a sophisticated group creating malicious open-source software. TeamPCP is blamed for the longest-running spree of supply chain compromises targeting thousands of organizations worldwide.

Why I Care

This highlights the persistent threat of supply chain vulnerabilities and open-source poisoning affecting global enterprises, demonstrating that law enforcement can disrupt even long-standing cybercrime operations.

Next Steps

Security teams should audit third-party dependencies and open-source libraries immediately, while software vendors must enhance supply chain verification protocols to prevent future compromises.

Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a "sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses." The AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old suspect's real identity in June, and has been communicating with him ever since. This story includes interviews with TeamPCP's self-described spokesperson, and examines clues left behind by the TeamPCP leader that likely led to his undoing.
Back to Blog Listing

Source: Krebs on Security ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.