FBI and AFP arrest alleged TeamPCP masterminds in Perth over supply chain attacks

Two men aged 21 and 23 accused of compromising over 1,000 organisations globally

edit
By LineZotpaper
Published
Read Time2 min
The Australian Federal Police, with assistance from the FBI, have arrested two men in Perth believed to be the masterminds behind TeamPCP, a cybercrime syndicate responsible for supply chain attacks that compromised more than 1,000 organisations, stole over 500,000 credentials, and exfiltrated at least 300 gigabytes of data. The arrests, made on Wednesday, follow investigations that began in April 2026 after multiple cyber threat assessment companies alerted authorities to malicious code inserted into open-source repositories.

According to the AFP, the two men, aged 21 and 23, were ‘principal participants in the activities of the cybercrime syndicate and received payments in cryptocurrency for their roles in the illegal activity’. An FBI Facebook post identified one of the arrested men as Ruben Thomson, described as ‘the alleged leader of the cybercriminal group TeamPCP.’ Australian media named the second man as 23-year-old Louis Michael Gaebler.

TeamPCP is known for prominent supply chain attacks, including an incident targeting the open-source scanner Trivy and the Shai-Hulud worm, which attacked npm packages and sought credentials for major public clouds and services like GitHub. Researchers had detected some of these activities before April; in March, The Register reported that researchers spotted the Trivy supply chain attack.

The AFP estimates the financial impact includes global remediation costs ‘in the hundreds of millions of dollars.’ A large volume of data from seized electronic devices is under forensic examination, and the AFP stated that further arrests and charges have not been ruled out. Searches were conducted at three properties in Perth suburbs, with the two men arrested at different locations.

§

Analysis

Why This Matters

  • The arrests disrupt one of the most active cybercrime syndicates targeting the software supply chain, directly affecting thousands of organisations that unknowingly integrated compromised code.
  • The case highlights the increasing collaboration between international law enforcement — here, the FBI and AFP — to track and dismantle cybercrime operations that exploit open-source ecosystems.
  • With seized data still under analysis, the investigation could lead to further arrests, exposing the broader network behind TeamPCP and deterring similar attacks.

Background

TeamPCP gained notoriety for supply chain attacks that inserted malicious code into publicly available software, exploiting the trust developers place in open-source repositories. Their methods included the Shai-Hulud worm, designed to proliferate across npm packages and exfiltrate credentials to cloud platforms. Supply chain attacks have become a growing cybersecurity threat, as a single compromised component can cascade through many downstream users.

Key Perspectives

Australian Federal Police: The AFP views the arrests as a significant blow to a syndicate that caused hundreds of millions in global losses, calling the operation ongoing and leaving the door open for more charges. FBI: The US agency publicly named Ruben Thomson as the alleged leader, signalling its investment in cross-border cybercrime investigations and the sharing of intelligence with Australian authorities. Cybersecurity researchers: Researchers who initially detected the Trivy and Shai-Hulud attacks provided crucial early warnings, illustrating the value of independent threat intelligence in identifying stealthy supply chain compromises.

What to Watch

  • Further analysis of seized devices may reveal identities of additional accomplices and victims.
  • The AFP’s ongoing investigation could lead to charges against other members of the syndicate.
  • Open-source maintainers and security tools may see renewed focus on vetting dependencies to prevent similar attacks.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.