Australian police have arrested two people in Perth accused of being members of TeamPCP, a prolific hacking group blamed for high-profile hacks against big tech giants in recent months. The two have been charged with more than a dozen hacking, money laundering, and other cybercrime offenses and are expected in court later on Thursday.
According to a statement by the Australian Federal Police, the two men are accused of widespread breaches involving the compromise and tampering of popular open-source projects. The hackers aimed to infect a large number of computers to steal credentials and data, then extort victims into paying a ransom.
The FBI’s cyber division chief Brett Leatherman was quoted as saying that the two alleged members of TeamPCP are accused of hacking into more than a thousand organizations as part of their attacks.
It’s unclear whether the Justice Department plans to seek extradition, and a spokesperson for the FBI did not immediately comment when contacted by TechCrunch.
TeamPCP is a prolific cybercriminal gang known for several widespread hacking campaigns targeting the software supply chain, in which the hackers would break in and maliciously modify a popular open-source software tool used by potentially thousands of companies.
Once installed on a company’s or developer’s systems, the malicious code steals their private keys and other sensitive credentials used to access cloud storage systems and, oftentimes, customer data. The authorities said the hackers stole more than half a million credentials to further their attacks into other companies.
The hackers were blamed for a cyberattack on the popular vulnerability scanner tool Trivy, which affected any company that relied on it, including LiteLLM, AI recruiting startup Mercor, and others. The hackers are also suspected of breaching the European Commission’s cloud infrastructure, as well as targeting other open source projects and developer apps that allowed access to tech giants like GitHub and OpenAI.

The Australian officials said their investigations began in April 2026 after receiving information from multiple cybersecurity companies.
Police have not named the men who were arrested, but independent cybersecurity journalist Brian Krebs exclusively reported that one of the now-arrested alleged hackers is Ruben Thomson, who goes by the hacker handle Ellis. Krebs reported Thursday that he was in contact with Ellis over the past several months, and the hacker told Krebs that he was the leader of TeamPCP until March 2026.
Krebs said Ellis made mistakes that allowed the journalist to learn the alleged hacker’s real identity.
During a press conference on Wednesday announcing the arrests, Australian officials said they had also seized a large quantity of allegedly stolen data, as well as devices and other electronics from the hackers. The officials said they planned to notify victims of the attacks.