Australian Police Arrest Two Alleged Members of TeamPCP Hacking Group
Australian authorities have charged two men for their alleged role in the TeamPCP hacking collective, which is believed to have compromised thousands of organizations through malicious open-source software.

Australian law enforcement has arrested and charged two young men for their alleged involvement in TeamPCP, a hacking collective suspected of orchestrating a series of developer-focused supply chain attacks that may have impacted more than a thousand organizations worldwide. The Australian Federal Police and Western Australia Police, working with the FBI, said the arrests took place on August 26, 2026, in the western Australian cities of Cottesloe and Mandurah. Investigators also seized electronic devices and other evidence for forensic analysis.
The AFP said the suspects, aged 21 and 23, are accused of participating in TeamPCP operations, which involved injecting malicious code into open-source software hosted on public repositories. Developers unknowingly incorporated the poisoned code into applications used by government, academic, and private-sector organizations. According to the AFP, the campaign may have led to the theft of half a million credentials and the exfiltration of at least 300GB of data. Remediation costs have been estimated in the hundreds of millions of dollars globally.
TeamPCP has been linked to a number of high-profile intrusions over the past year, including attacks on Trivy, LiteLLM, Telnyx, SAP, and TanStack packages, as well as breaches at the European Commission, Mistral AI, OpenAI, and GitHub. Security researchers have described the group not as a cohesive organization but as a loosely connected set of threat actors who share hacking forums, Discord servers, and Telegram channels. The investigation into the group's activities began in April 2026, after the AFP and FBI received key leads from cybersecurity firms.
The two suspects face a combined 14 charges related to possessing and supplying data for computer offenses and modifying data to facilitate serious crimes. The younger of the two is additionally charged with dealing in criminal proceeds of at least $100,000 and failing to comply with an order requiring access to electronic data. Each charge carries a maximum penalty of between three and 20 years in prison. Police allege the pair received undisclosed amounts of cryptocurrency for their part in the operations.
Following the arrests, Flare and independent journalist Brian Krebs released separate investigations that connected the alleged TeamPCP members' Telegram activity, reused aliases, and online traces to real-world identities. The AFP said further arrests or charges have not been ruled out while it reviews the seized evidence.
The case highlights the risk posed by malicious code in trusted open-source dependencies, where a small compromise can ripple across thousands of downstream users. The AFP described the alleged compromise as having "a significant global impact." The arrests represent a notable step in holding those behind such campaigns accountable.