Australian law enforcement revealed on Thursday that two men have been charged in connection with an alleged cybercriminal network that introduced malicious code into widely used open-source software tools. The suspects are accused of roles in TeamPCP, a group police say embedded harmful code into popular developer tools to breach business systems.
Authorities say the scheme had broad impact. According to a police statement, the inserted code potentially compromised more than 1,000 organizations around the world and enabled the theft of in excess of 500,000 credentials and more than 300 gigabytes of data. The statement also said some of the affected businesses were subsequently subjected to extortion, citing a July FBI advisory.
The two Australian men face a combined total of 14 charges tied to their alleged participation in the collective. Police did not publicly name the men in the initial announcement. The Australian Broadcasting Corporation identified them as Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23.
Nick Scerri, identified as a lawyer for Thomson, did not immediately respond to a request for comment outside of normal business hours. A lawyer for Gaebler could not be immediately identified.
Police said they began a parallel inquiry with the U.S. Federal Bureau of Investigation in April, following information from several unnamed cybersecurity threat assessment firms. The collaboration between Australian investigators and the FBI was described in the police statement as part of efforts to pursue those responsible and to address the growing risk from attacks on the software supply chain.
"We are proud to work with the Australian Federal Police and the Western Australia Police Force to impose cost on criminal actors and combat the growing threat of software supply-chain attacks," FBI Cyber Division Assistant Director Brett Leatherman said in the police statement.
The FBI declined further comment beyond the police statement. Separately, Austin Larsen, a principal threat analyst with the Google Threat Intelligence Group, posted on LinkedIn calling TeamPCP "one of the most impactful threat actors of 2026." Larsen further characterized TeamPCP as a "peer community of individually skilled actors with one clear center of gravity," rather than a single, unified organization.
Authorities emphasized that information supporting the case came from multiple industry sources and cross-jurisdictional cooperation. Details released by police sketch a campaign that relied on poisoning open-source supply chains to gain access to corporate environments and to harvest credentials and data, with some victims later subject to extortion demands, as noted in the July advisory referenced by police.
Summary
- Two Australian men have been charged in connection with alleged TeamPCP activity that placed malicious code into open-source software.
- Police report potential compromise of over 1,000 organizations globally, with theft of more than 500,000 credentials and over 300 gigabytes of data.
- Investigators coordinated with the FBI beginning in April after receiving information from multiple unnamed cybersecurity assessment firms.