Australia Arrests Two Alleged TeamPCP Hackers in Cybercrime Case
Australian law enforcement has detained two individuals linked to the cybercriminal collective TeamPCP, charging them with involvement in a global cybercrime operation that resulted in substantial financial harm.
Arrests and Charges
The suspects, Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, were taken into custody in Perth. They face multiple allegations tied to their purported participation in a criminal network responsible for generating hundreds of millions in damages.
Suspects and Allegations
Thomson is charged with five distinct offenses related to cyber intrusion and financial fraud, with potential sentences ranging from three to 20 years per charge. Gaebler is accused of cybercrime, with the most severe counts carrying a maximum penalty of five years in prison.
TeamPCP’s Methods
TeamPCP exploited vulnerabilities in software supply chains and developer tools, targeting platforms such as Aqua Security’s Trivy, Checkmarx’s KICS, and PyPI’s LiteLLM. The group intercepted over 500,000 corporate credentials by compromising continuous integration/continuous deployment (CI/CD) pipelines.
Data Exfiltration
By manipulating automated build processes and widely used package repositories, the actors transformed corporate software development workflows into mechanisms for data extraction. Stolen cloud access keys and infrastructure secrets were reportedly funneled to ransomware and extortion groups.
Investigation and Seizures
The threat actor utilized the Mini Shai-Hulud worm, alongside the original Shai-Hulud variant, to automate the theft of credentials and propagate across package registries on a large scale. Australian authorities reported that the group exfiltrated at least 300 gigabytes of data from over 1,000 organizations globally.
Authorities’ Statement
Investigators have seized digital devices linked to Thomson and Gaebler, with ongoing efforts to quantify the financial gains from their activities. A statement from the Australian Federal Police indicated that a significant volume of seized data is undergoing forensic analysis, and additional arrests remain possible as the investigation progresses.
Conclusion
The operation highlights the group’s sophisticated methods in leveraging supply chain vulnerabilities to compromise enterprise systems. Their activities underscore the risks posed by malicious actors targeting critical infrastructure and development ecosystems. Law enforcement agencies continue to monitor the case, with further developments expected as the probe advances.
