Observed Signal · Aug 27, 2026 · Law Enforcement Action · Source: techcrunch · Impact: 4/5 · Sentiment: Positive
Australian arrests alleged TeamPCP hackers in supply‑chain attacks
Australian Federal Police arrested two people in Perth accused of membership in TeamPCP, a hacking group blamed for widespread software supply‑chain attacks. The suspects face more than a dozen charges including hacking and money laundering; authorities say the group tampered with popular open‑source projects to deploy malicious code that stole credentials and data for extortion. The FBI estimates the intrusions impacted more than 1,000 organizations and that over half a million credentials were stolen. Investigations began in April 2026 after tips from cybersecurity firms. Independent reporter Brian Krebs has identified one alleged suspect as Ruben Thomson (handle “Ellis”), who told Krebs he led TeamPCP until March 2026. Australian officials said they seized devices and stolen data and plan to notify victims; extradition by the US Department of Justice is not yet clear.
Arrests target a prolific supply‑chain hacking group accused of compromising open‑source developer tools and stealing >500,000 credentials, a systemic risk that affected major tech firms (OpenAI, GitHub) and could impact cloud security and downstream vendors across the tech and advertising stack.
Track Mercor Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Two people were arrested in Perth and charged with more than a dozen hacking, money‑laundering, and cybercrime offenses, according to the Australian Federal Police.
- Authorities allege TeamPCP compromised and tampered with popular open‑source projects to install malicious code that stole credentials and data for extortion.
- The FBI’s cyber division chief said the alleged hackers are accused of breaching more than 1,000 organizations.
- Authorities stated the hackers stole more than half a million credentials used to further attacks into other companies.
- Independent journalist Brian Krebs reported one arrested suspect as Ruben Thomson (alias “Ellis”), who claimed to have led TeamPCP until March 2026.
Connected Companies & Entities
4 Entities mapped“The hackers were blamed for a cyberattack on the popular vulnerability scanner tool Trivy, which affected any company that relied on it, inc...”
“The hackers are also suspected of breaching the European Commission’s cloud infrastructure, as well as targeting other open source projects ...”
“The hackers are also suspected of breaching the European Commission’s cloud infrastructure, as well as targeting other open source projects ...”
“Australian police have arrested two people in Perth accused of being members of TeamPCP, a prolific hacking group blamed for high-profile ha...”
Ontology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Rival hackers evict TeamPCP, deploy worm 'PCPJack'
An unknown hacking group, tracked by SentinelOne as “PCPJack,” has been compromising systems previously breached by the cybercrime group TeamPCP. According to a SentinelOne report, the attackers break into TeamPCP‑compromised environments, remove TeamPCP’s tooling, evict its operators, then deploy self‑propagating code that steals credentials and exfiltrates data. The group appears focused on cloud infrastructure and also scans the public internet for exposed services such as Docker and MongoDB. SentinelOne researcher Alex Delamotte said the motives appear financial — stolen credentials are monetized via resale, initial‑access brokering, or direct extortion — and proposed theories including disgruntled ex‑TeamPCP members, rival operators, or imitators modeling TeamPCP’s tools. The campaign is notable for targeting previously compromised environments and using phishing domains (including password‑manager themed sites) and fake help‑desk pages as part of its activity.
Team‑PCP steals 3,800 internal GitHub repositories
The hacker group Team‑PCP accessed approximately 3,800 internal GitHub repositories between May 18 and May 19, 2026, and is attempting to sell the stolen data. GitHub confirmed the incident on X and said no customer data was affected. According to GitHub, attackers used a compromised employee device that had a malicious Visual Studio Code extension installed; the impacted endpoint was isolated and incident response measures were taken. Team‑PCP, previously linked to a March 2026 supply‑chain attack and said to collaborate with the Ransomware‑as‑a‑Service operator Vect, is offering the GitHub data for sale and reportedly coordinated with the LAPSUS$ group in later negotiations.
CERT-EU Blames TeamPCP for European Commission Data Breach
CERT-EU reported that a cybercriminal group known as TeamPCP breached an Amazon Web Services account used by the European Commission, stealing roughly 92 GB of compressed data from the Commission's Europa.eu cloud infrastructure. The stolen material — later posted online by the hacking group ShinyHunters — included names, email addresses and the contents of emails; CERT-EU said at least 29 other EU entities and dozens of internal Commission clients may be affected. The agency traced the intrusion to March 19 after attackers acquired a secret AWS API key following a supply-chain compromise of the open-source security tool Trivy. CERT-EU is contacting affected organizations and continues analyzing the published data.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
