Australia Charges Two Men as TeamPCP's Principal Participants After Supply-Chain Spree
Summary
The Australian Federal Police (AFP) charged two Perth-based men โ identified by ABC as Ruben Ian Thomson, 21 (Cottesloe) and Louis Michael Gaebler, 23 (Mandurah) โ with 14 combined offences over their alleged role as "principal participants" of the TeamPCP cybercrime group. TeamPCP is responsible for one of the year's most damaging hacking campaigns, a supply-chain spree that has compromised widely used open-source and enterprise developer tools.
What TeamPCP has done
TeamPCP has operated since March, often targeting open-source developer tools including TanStack, Trivy and LiteLLM, and riding downstream trust into thousands of organisations. Confirmed victims include the European Commission and GitHub. FBI assistant director Brett Leatherman alleged the pair and their syndicate "potentially compromised more than a thousand organisations worldwide", while Australian investigators estimate more than 500,000 credentials exposed and at least 300 GB of data stolen. If convicted on every count the two could face a combined 82 years in prison.
Australian context
The arrests are a deliberate display of the Australia-United States law-enforcement pipeline: the AFP ran a cross-jurisdictional operation with the WA Police Force and the FBI. It also builds on the same week's Treasury sanctions and the QScan/QTRouter disruption, underscoring that Australian agencies are not just consumers of Five Eyes takedowns but co-producers. The charges across large-scale data intrusion, identity crime and cryptocurrency money-laundering reinforce the pattern that supply-chain actors such as TeamPCP ultimately surface as identity and financial crime prosecutions.
AU/NZ relevance
The TeamPCP case is the standout AU story of the cycle and the most relevant single event for Australian and New Zealand defenders. On one hand it is a tangible AU law-enforcement success; on the other it strikes directly at an AU/NZ community that heavily depends on open-source developer tools of the exact kind TeamPCP poisoned. Australian and New Zealand software teams should verify they are not running tampered versions of TanStack, Trivy or LiteLLM, and treat supply-chain integrity of open-source dependencies as a live risk.