World August 27, 2026 04:54 PM

Two Australians Charged Over Alleged Widespread Tampering of Open-Source Tools

Authorities say malicious code placed in popular software packages compromised thousands of organizations and enabled large-scale credential and data theft

By Avery Klein
Share
Twitter Reddit Facebook LinkedIn

Australian authorities announced charges against two men accused of involvement in TeamPCP, an alleged hacking collective that injected malicious code into widely used open-source tools. Police say the activity potentially affected more than 1,000 organizations worldwide, leading to the theft of over 500,000 credentials and more than 300 gigabytes of data, and that some targeted businesses were later extorted.

Two Australians Charged Over Alleged Widespread Tampering of Open-Source Tools
Summarize with
ChatGPT Perplexity Claude Grok Gemini

Key Points

  • Charges filed against two Australian men accused of involvement in TeamPCP, facing a combined 14 counts.
  • Police say malicious code potentially affected more than 1,000 organizations worldwide and enabled theft of over 500,000 credentials and more than 300 gigabytes of data.
  • Investigation involved parallel work with the FBI starting in April and relied on information from multiple unnamed cybersecurity threat assessment companies; some compromised businesses were later extorted.

Australian law enforcement revealed on Thursday that two men have been charged in connection with an alleged cybercriminal network that introduced malicious code into widely used open-source software tools. The suspects are accused of roles in TeamPCP, a group police say embedded harmful code into popular developer tools to breach business systems.

Authorities say the scheme had broad impact. According to a police statement, the inserted code potentially compromised more than 1,000 organizations around the world and enabled the theft of in excess of 500,000 credentials and more than 300 gigabytes of data. The statement also said some of the affected businesses were subsequently subjected to extortion, citing a July FBI advisory.

The two Australian men face a combined total of 14 charges tied to their alleged participation in the collective. Police did not publicly name the men in the initial announcement. The Australian Broadcasting Corporation identified them as Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23.

Nick Scerri, identified as a lawyer for Thomson, did not immediately respond to a request for comment outside of normal business hours. A lawyer for Gaebler could not be immediately identified.

Police said they began a parallel inquiry with the U.S. Federal Bureau of Investigation in April, following information from several unnamed cybersecurity threat assessment firms. The collaboration between Australian investigators and the FBI was described in the police statement as part of efforts to pursue those responsible and to address the growing risk from attacks on the software supply chain.

"We are proud to work with the Australian Federal Police and the Western Australia Police Force to impose cost on criminal actors and combat the growing threat of software supply-chain attacks," FBI Cyber Division Assistant Director Brett Leatherman said in the police statement.

The FBI declined further comment beyond the police statement. Separately, Austin Larsen, a principal threat analyst with the Google Threat Intelligence Group, posted on LinkedIn calling TeamPCP "one of the most impactful threat actors of 2026." Larsen further characterized TeamPCP as a "peer community of individually skilled actors with one clear center of gravity," rather than a single, unified organization.

Authorities emphasized that information supporting the case came from multiple industry sources and cross-jurisdictional cooperation. Details released by police sketch a campaign that relied on poisoning open-source supply chains to gain access to corporate environments and to harvest credentials and data, with some victims later subject to extortion demands, as noted in the July advisory referenced by police.


Summary

  • Two Australian men have been charged in connection with alleged TeamPCP activity that placed malicious code into open-source software.
  • Police report potential compromise of over 1,000 organizations globally, with theft of more than 500,000 credentials and over 300 gigabytes of data.
  • Investigators coordinated with the FBI beginning in April after receiving information from multiple unnamed cybersecurity assessment firms.

Risks

  • Continued vulnerability in software supply chains could expose businesses across sectors to credential theft and data loss - this primarily affects the software and cybersecurity sectors and firms that rely on open-source tools.
  • Uncertainty around the full scope of affected organizations and the long-term impact on compromised credentials and data - this presents risks to corporate security postures and market confidence in affected companies.
  • Potential for further criminal activity from loosely organized groups described as a peer community of skilled actors - law enforcement and corporate defenders may face challenges attributing actions and scaling defenses, affecting cybersecurity services and enterprise IT spending.

More from World

UEFA Seeks U.S. Court Permission to Obtain FIFA Records for Planned Swiss Criminal Case Aug 27, 2026 Norwegian King Harald’s Condition Declared 'Very Serious' as Family and Officials Rally at Hospital Aug 27, 2026 North Korea Condemns U.S. Missile Sale to South Korea, Promises Immediate Response Aug 27, 2026 Australia says 34 citizens among those missing after Nepal floods as information remains scarce Aug 27, 2026 U.S. Commission Calls for Targeted Sanctions Over Visit by RSS Leader Aug 26, 2026