Australian law enforcement on Thursday lodged criminal charges against two men accused of taking part in a coordinated effort to tamper with widely used open-source software tools, a campaign investigators say affected thousands of companies around the world.
The Australian Federal Police (AFP) said the pair face a total of 14 charges tied to their alleged participation in TeamPCP, a hacking collective that reportedly inserted malicious code into commonly deployed software components to gain access to corporate systems. Some affected organisations were later targeted for extortion, according to a July advisory issued by the U.S. Federal Bureau of Investigation (FBI).
While the AFP did not publicly identify the suspects, the Australian Broadcasting Corporation named them as Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23. In initial court appearances, representation and comment were limited: the lawyer who handled Thomson's first appearance, Nick Scerri, directed questions to Thomson's current attorney, Paul Holmes, who declined to comment. James Gatti, the lawyer for Gaebler, also declined to comment.
Investigators say the malicious modifications to open-source projects potentially impacted in excess of 1,000 organisations around the world. Police estimates indicate the campaign enabled the theft of more than 500,000 credentials and the removal of over 300 gigabytes of data.
The AFP said it opened a parallel investigation with the FBI in April after receiving information from several unnamed cybersecurity threat assessment firms. In a statement included in the AFP release, FBI Cyber Division Assistant Director Brett Leatherman said the bureau was "proud to work with the Australian Federal Police and the Western Australia Police Force to impose cost on criminal actors and combat the growing threat of software supply-chain attacks." The FBI declined to offer additional comment.
Late on Thursday, the U.S. Attorney's Office for the Northern District of California announced it had filed an indictment in the United States against Thomson. The charges listed in the U.S. indictment include conspiracy to commit violations of the Computer Fraud and Abuse Act and obtaining information from a protected computer.
Industry analysts have described TeamPCP as a significant threat actor. Austin Larsen, a principal threat analyst with Google's Threat Intelligence Group, characterized TeamPCP on LinkedIn as "one of the most impactful threat actors of 2026," describing it as a peer community of skilled individuals oriented around a common center of gravity rather than a single unified group.
Context and implications
The allegations highlight vulnerabilities in software supply chains when widely used open-source components are targeted. The cross-jurisdictional nature of the investigation - with Australian and U.S. authorities coordinating and relying on intelligence from private cybersecurity firms - underscores the global dimensions of such incidents and the complexity of attributing and prosecuting supply-chain compromises.