TeamPCP Arrests Expose the Human Cost of a Devastating Software Supply-Chain Campaign + Video

Listen to this Post

Featured ImageA Major Cybercrime Investigation Reaches a New Turning Point

A cybercrime campaign that quietly moved through trusted software tools, developer environments, and corporate infrastructure has now produced a major law-enforcement breakthrough. Australian authorities have arrested two young men in Perth who are accused of playing principal roles in the notorious TeamPCP cybercrime operation, a group linked to some of the most consequential software supply-chain compromises reported in 2026.

Two Suspects Face Serious Charges

The suspects have been identified as Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23. Australian authorities charged the pair with a combined 14 offenses following searches at properties in Western Australia. Thomson is alleged by the FBI to have been the leader of TeamPCP, while Gaebler is accused of participating in the wider hacking operation.

The Investigation Spanned Borders

The arrests were the result of cooperation between the Australian Federal Police, Western Australia Police Force, and the U.S. Federal Bureau of Investigation. Authorities began a parallel investigation in April 2026 after receiving information from multiple cybersecurity companies, eventually leading investigators to the two Perth-area suspects.

A Criminal Operation Built Around Trust

What makes the TeamPCP campaign particularly disturbing is that the attackers did not necessarily need to break directly into thousands of companies one by one. Instead, investigators say they targeted trusted software components and development infrastructure that were already being used by organizations around the world.

That approach transformed legitimate software distribution channels into an enormous delivery mechanism. Once malicious code was inserted into trusted projects, downstream developers could unknowingly pull compromised components into their own environments, giving the attackers access far beyond the original targets.

The Software Supply Chain Became the Attack Surface

The campaign has been associated with compromises involving widely used development and security projects, including Aqua Security’s Trivy, Checkmarx’s KICS, and BerriAI’s LiteLLM. The U.S. Department of Justice says Thomson allegedly conspired with others to compromise trusted software supply-chain security tools and inject malicious code into them, allowing the compromise to cascade into downstream organizations.

Why This Method Was So Powerful

A traditional cyberattack often requires an attacker to identify a vulnerable organization, penetrate its defenses, establish persistence, and move through its network. A software supply-chain attack can reverse that equation.

Instead of attacking every customer individually, criminals can compromise something those customers already trust. Developers install the software because it is legitimate. Automated systems execute it because it is part of a normal build process. Security teams may therefore see ordinary development activity rather than an obvious intrusion.

The Numbers Reveal the Scale

Australian authorities say the campaign potentially affected more than 1,000 organizations worldwide, resulted in the theft of more than 500,000 credentials, and involved the exfiltration of at least 300 GB of data. Those figures illustrate why the arrests are being treated as more than an isolated cybercrime case.

Hundreds of Millions in Potential Damage

The broader financial impact is believed to reach hundreds of millions of dollars when remediation, incident response, business disruption, credential replacement, infrastructure rebuilding, and other consequences are considered. Importantly, these figures represent the alleged impact and associated costs rather than a final court determination of damages.

The Credential Theft Was the Real Prize

The

Once stolen credentials reach criminal marketplaces or other threat actors, the original breach can continue producing consequences long after the malicious software has been removed.

CI/CD Environments Created an Unusually Dangerous Opportunity

Continuous integration and continuous delivery environments are designed to automate software development. They routinely handle source code, authentication tokens, package publishing credentials, cloud permissions, deployment keys, and other sensitive secrets.

That makes them extremely attractive targets.

If an attacker manages to execute malicious code inside a trusted development workflow, the resulting access can be dramatically more valuable than access to an ordinary workstation.

The Attack Could Propagate Through Software Ecosystems

The most dangerous characteristic of the TeamPCP campaign was its ability to exploit relationships between developers, packages, repositories, build systems, and downstream customers.

One compromised component could potentially reach thousands of development environments.

The result is a multiplier effect: one successful compromise can create hundreds or thousands of secondary exposures without the attacker having to manually penetrate each victim.

Shai-Hulud Added Another Layer of Automation

TeamPCP has also been associated with Shai-Hulud-related activity, including the so-called Mini Shai-Hulud campaign. Security researchers have documented malware capable of harvesting credentials and spreading through software ecosystems, demonstrating how modern supply-chain attacks can combine malware automation with developer infrastructure abuse.

The Security Tool Paradox

There is a particularly painful irony in attacks against security-related software.

Organizations deploy security scanners, code-analysis platforms, and developer protection tools because they are trying to become safer. Yet if an attacker compromises one of those trusted tools, the security function itself can become part of the attack path.

That does not mean security tools are inherently unsafe. It demonstrates that security software must be treated as critical infrastructure and subjected to the same rigorous supply-chain controls as any other high-value component.

The Arrest Does Not Erase the Stolen Credentials

The most important point for affected organizations is that an arrest does not automatically eliminate the technical consequences of a breach.

A credential copied months ago can remain useful if it has not been rotated.

An API token can remain active.

A cloud access key can remain valid.

A package publishing credential can remain dangerous.

A source-code access token can continue to provide visibility into proprietary systems.

This is why incident response must continue even after law enforcement identifies suspected perpetrators.

The FBI Has Warned About Persistent Exposure

The FBI previously advised organizations affected by the campaign to treat compromised credentials and data as an ongoing risk and to rotate secrets associated with the relevant exposure windows. That guidance reflects a fundamental principle of modern incident response: stolen authentication material should be considered compromised until it has been replaced or otherwise invalidated.

The Arrests May Reveal More Than the Identities

The forensic examination of seized devices could become one of the most important parts of the investigation.

Authorities have reportedly seized electronic devices and large quantities of data. Investigators are now working to determine the scope of the suspects’ activities, their financial gains, communications with other criminals, and the broader infrastructure behind the campaign.

More Arrests Remain Possible

Australian authorities have explicitly said that the investigation remains active and that further arrests and charges have not been ruled out. That suggests investigators believe the two arrests may represent only part of a larger operational structure.

TeamPCP May Be Bigger Than Two Individuals

The phrase “TeamPCP” should not automatically be interpreted as meaning two people operating alone.

Threat intelligence reporting has characterized the group as a loosely organized collection of skilled actors rather than necessarily a conventional hierarchical criminal organization. Google Threat Intelligence analyst Austin Larsen described TeamPCP as a community of individually skilled actors with a central point of coordination.

The Leadership Question Is Still Important

The

That distinction matters.

An arrest means authorities believe there is sufficient basis to pursue criminal charges. It does not mean every allegation has already been proven in court.

The U.S. Case Raises the Stakes

The legal consequences extend beyond Australia. A U.S. federal grand jury indicted Thomson in connection with alleged TeamPCP attacks on the software supply chain, accusing him of conspiracy to commit Computer Fraud and Abuse Act violations and obtaining information from protected computers.

The Case Shows How International Cybercrime Has Become

A suspect can operate from Australia, target software used globally, compromise organizations in multiple countries, move stolen information through online criminal networks, and potentially monetize the resulting access through cryptocurrency.

No single national cybersecurity perimeter can contain that model.

The investigation therefore demonstrates why international law enforcement cooperation has become an essential component of cybersecurity enforcement.

The Victims May Still Be Discovering the Damage

One of the most difficult consequences of a supply-chain attack is delayed discovery.

An organization may not know that it consumed a compromised package.

It may not realize that a build process exposed a credential.

It may not immediately understand that a cloud token was stolen.

And it may only discover the problem when an unrelated account is accessed weeks or months later.

The True Victim Count Could Change

The current figure of more than 1,000 affected organizations should therefore be understood as an investigative estimate rather than necessarily the final number of victims.

As investigators examine seized evidence and affected companies conduct retrospective searches, the number could become clearer.

The Data Itself Could Become a Second Wave of Attacks

Stolen information can create consequences beyond the original intrusion.

Corporate credentials can support additional compromises.

Cloud secrets can provide access to infrastructure.

Source code can reveal vulnerabilities or internal architecture.

Employee information can enable targeted phishing.

Customer information can support identity fraud.

And cryptocurrency-related credentials can become direct financial targets.

Supply-Chain Security Must Become a Board-Level Issue

For years, software dependencies were often treated as a technical concern for developers and security teams.

That approach is becoming increasingly difficult to justify.

When a single compromised package can potentially affect thousands of organizations, software dependency management becomes a business-continuity issue.

Open-Source Software Is Not the Problem

It would be wrong to conclude that open-source software itself is the enemy.

Open-source projects power an enormous portion of modern computing because developers can inspect, improve, reuse, and collaborate on software at extraordinary speed.

The vulnerability lies in the trust relationships surrounding the software.

Organizations need stronger controls around how dependencies are verified, built, signed, updated, monitored, and deployed.

The Lesson for Developers

Developers should treat dependencies as executable trust decisions.

A package update is not simply a version change.

It is a decision to execute code produced somewhere else.

That means package provenance, maintainer security, release integrity, dependency pinning, software bills of materials, and automated monitoring all deserve greater attention.

The Lesson for Security Teams

Security teams need visibility into developer environments that historically received less scrutiny than production networks.

CI/CD runners, package registries, Git repositories, build servers, artifact repositories, and deployment systems should be monitored as aggressively as traditional endpoints and servers.

The Lesson for Cloud Teams

Cloud credentials stolen from a development pipeline can be more valuable than a compromised employee password.

A single secret may provide access to storage, compute infrastructure, databases, internal services, or deployment systems.

Least-privilege permissions therefore become particularly important for build environments.

The Lesson for Executives

Executives should understand that software supply-chain security is not simply about preventing malware.

It is about protecting the entire digital production process.

If an attacker can influence the code entering an organization, they may be able to bypass multiple downstream security controls because the organization itself is executing the compromised software.

The Bigger Cybersecurity Trend

TeamPCP is part of a broader evolution in cybercrime.

Attackers increasingly look for infrastructure that already has trust.

Instead of breaking through the front door, they may compromise a vendor.

Instead of stealing one

Instead of attacking one company, they may attack the technology connecting many companies.

Trust Has Become a Valuable Attack Surface

Modern cybersecurity has traditionally focused heavily on protecting systems from unauthorized access.

Supply-chain attacks add another question:

What happens when authorized systems are tricked into executing unauthorized code?

That question is much harder because the activity may initially look legitimate.

Why Detection Is So Difficult

A malicious package may arrive through a normal repository.

A compromised build may be triggered automatically.

A stolen credential may be used through a legitimate API.

A malicious deployment may originate from an authorized CI/CD runner.

This creates a dangerous environment in which the attacker can hide behind the normal behavior of the development ecosystem.

Deep Analysis: How the Attack Chain Worked

Command 1: Compromise a Trusted Component

The first strategic objective in a supply-chain campaign is to gain control of something downstream organizations already trust.

Instead of targeting thousands of companies individually, an attacker looks for a common dependency or development tool with a large user base.

Command 2: Insert Malicious Code

Once the attacker gains the necessary control, malicious code can be inserted into a legitimate project, package, build process, or release mechanism.

The downstream user may have no obvious reason to suspect anything because the software originated from a trusted source.

Command 3: Let Automation Spread the Exposure

Modern development systems automatically install dependencies, execute tests, build applications, publish artifacts, and deploy infrastructure.

Automation therefore becomes an attacker multiplier.

Command 4: Harvest High-Value Credentials

The next objective is often credential theft.

The attacker can search for environment variables, configuration files, authentication tokens, cloud credentials, package publishing keys, source-control credentials, and other secrets accessible to the compromised environment.

Command 5: Move Beyond the Original Victim

Once credentials are stolen, the campaign can move beyond the original software project.

The attacker may use one credential to reach another system, another organization, or another development environment.

Command 6: Monetize the Access

Stolen credentials and data can be monetized in several ways.

They may be sold, used for extortion, passed to ransomware groups, leveraged for additional intrusion, or exploited to steal money or digital assets.

Command 7: Maintain the Criminal Ecosystem

This is where modern cybercrime becomes increasingly collaborative.

One group may specialize in initial access.

Another may specialize in credential theft.

Another may conduct extortion.

Another may operate ransomware infrastructure.

The resulting ecosystem allows attackers to specialize while still benefiting from each other’s capabilities.

Why the 500,000 Credentials Matter

The reported theft of more than 500,000 credentials is perhaps more significant than the raw volume of stolen data.

Credentials provide access.

Data can reveal information, but authentication material can open doors.

That distinction explains why credential rotation remains one of the most important defensive measures for organizations connected to the campaign.

Why 300 GB of Data Matters

Three hundred gigabytes is not merely a large number on a press release.

It potentially represents millions of individual records, configuration files, credentials, source-code fragments, documents, logs, and other information depending on the composition of the dataset.

The forensic analysis of that material could help authorities reconstruct the group’s operations and identify additional victims.

Why the Software Supply Chain Is So Attractive

The economics are simple from an

Compromise one upstream project and potentially reach thousands of downstream environments.

That is a much more efficient strategy than manually compromising thousands of companies.

It is the digital equivalent of finding one pressure point that connects an entire network.

Why Security Tools Are Especially Sensitive

A compromised security scanner can have access to source code, build environments, credentials, or internal infrastructure that ordinary applications never see.

The more deeply integrated a tool is into an organization’s development lifecycle, the more important its integrity becomes.

Security software should therefore be treated as privileged infrastructure.

Why Arrests Matter Even Before Convictions

The arrests will not instantly repair the affected software ecosystems.

They will not automatically invalidate every stolen credential.

They will not erase stolen data.

But they can disrupt the people allegedly coordinating the operation, provide investigators with valuable evidence, and potentially expose additional members of the criminal network.

The Forensic Phase Could Become the Most Important Phase

Investigators now have an opportunity to study devices, communications, cryptocurrency transactions, stolen datasets, infrastructure credentials, and operational records.

That evidence could help establish how the attacks were organized and how the stolen information moved through the criminal ecosystem.

The Cybersecurity Industry Is Watching Closely

The case will likely receive significant attention from software security teams because it demonstrates how an attack against a comparatively small number of trusted projects can create a global cascade.

It also provides investigators and defenders with an opportunity to study an active example of how supply-chain compromises are operationalized.

The Most Important Warning for Organizations

Organizations should not interpret the arrests as the end of the TeamPCP threat.

The more important question is whether they were exposed.

If a company used affected software during an exposure window, it should assume that potentially accessible secrets require investigation and, where appropriate, rotation.

The Long-Term Lesson

The TeamPCP case demonstrates that cybersecurity is increasingly about protecting trust relationships.

A company can build strong endpoint defenses and still be exposed through a compromised dependency.

It can deploy excellent identity protection and still suffer damage if machine credentials are stolen from a build system.

It can have sophisticated network monitoring and still miss malicious behavior that arrives through trusted software.

What Undercode Say:

TeamPCP Represents the New Face of Supply-Chain Crime

The TeamPCP case is significant because it demonstrates how cybercriminals can turn the software ecosystem itself into an attack platform.

The Attack Was Bigger Than a Traditional Breach

This was not simply a matter of stealing information from one company.

The alleged campaign targeted software that other organizations trusted, allowing the compromise to spread through existing relationships.

Trust Became the Weapon

The most powerful component of the operation was arguably not the malware itself.

It was the trust developers placed in legitimate software.

Automation Multiplied the Damage

Modern CI/CD environments can perform thousands of actions without human intervention.

That efficiency is extremely valuable to legitimate organizations and equally valuable to attackers who manage to compromise the process.

Credentials Were the Strategic Target

The reported theft of more than 500,000 credentials demonstrates the enormous value of authentication secrets.

Attackers do not necessarily need to steal everything when they can steal the keys that unlock other systems.

The Cloud Makes Secrets More Valuable

A stolen cloud credential can potentially provide access to infrastructure far beyond the machine on which it was originally discovered.

This makes cloud-secret protection a critical component of supply-chain defense.

CI/CD Systems Need Zero-Trust Thinking

Build systems should not automatically receive broad access simply because they are part of the development process.

Every credential and permission should have a defined purpose and limited scope.

Package Registries Are Critical Infrastructure

Package repositories are no longer merely places where developers download libraries.

They are part of the global software production system.

Software Provenance Is Becoming Essential

Organizations need stronger confidence that the software they consume is exactly what its publisher intended to release.

Signed artifacts, provenance information, reproducible builds, and integrity monitoring can all contribute to that confidence.

Dependency Management Can No Longer Be Passive

Automatically accepting every update creates unnecessary risk.

Organizations need visibility into what changed, who released it, and whether the update behaves as expected.

Security Tools Need Supply-Chain Protection Too

The compromise of security-oriented software demonstrates that defensive products can become high-value attack targets.

More Organizations Need Secrets Hygiene

Long-lived credentials create long-lived risk.

Short-lived credentials, automated rotation, and narrowly scoped permissions can significantly reduce the value of stolen secrets.

Incident Response Must Extend Into Development

Traditional incident response often focuses on endpoints, servers, email, and networks.

Modern response plans must also investigate repositories, build systems, package managers, CI/CD runners, and developer credentials.

Stolen Data Can Outlive the Attack

Even if malware is removed, stolen information may continue circulating among criminals.

The attack therefore has a long tail.

Arrests Are Only One Part of the Solution

Law enforcement can disrupt individuals and seize evidence, but organizations must still remediate their environments.

Attribution Requires Caution

Authorities have identified Thomson as the alleged leader, but allegations must still be tested through the legal process.

The Investigation Could Expand

Because investigators are examining seized devices and data, additional victims, infrastructure, or suspects could potentially emerge.

International Cooperation Is Essential

The alleged activity crossed national borders, making cooperation between Australian and U.S. authorities particularly important.

Cybercrime Has Become Increasingly Specialized

Modern criminal groups can divide responsibilities among initial access, malware development, credential theft, extortion, and laundering.

Ransomware Groups Benefit From Stolen Access

Credentials harvested from supply-chain attacks can become valuable inputs for other criminal operations.

The Damage Is Not Measured Only in Data

Operational disruption, investigation costs, credential resets, customer notification, legal exposure, and lost trust can all become part of the financial impact.

One Package Can Become a Global Problem

The central supply-chain lesson is simple: the blast radius of a compromised dependency can be enormous.

Developers Need Better Visibility

Developers should know which external components their organizations rely upon and what privileges those components receive.

Security Teams Need Dependency Intelligence

It is increasingly important to understand not just internal assets, but also the software relationships connecting those assets to the outside world.

Executives Need to Understand the Risk

Supply-chain security should be discussed alongside business continuity, cloud security, identity management, and third-party risk.

Open Source Must Become More Resilient

The answer is not to abandon open-source software.

The answer is to strengthen the security infrastructure surrounding it.

The Industry Needs Better Defaults

Secure defaults can reduce the number of opportunities attackers have to abuse development infrastructure.

Credential Rotation Should Be Automatic

If a credential is exposed, organizations should ideally be able to revoke and replace it quickly without relying on manual intervention.

Build Environments Deserve Strong Isolation

A compromised build process should not automatically provide unrestricted access to an organization’s entire infrastructure.

The Future Will Bring More Supply-Chain Attacks

As software ecosystems become more interconnected, attackers will continue looking for high-leverage points.

AI Development Adds Another Layer

The growing use of AI packages, model gateways, developer tools, and automated infrastructure creates additional software relationships that attackers may attempt to exploit.

The LiteLLM Connection Is Particularly Notable

The alleged compromise involving LiteLLM illustrates that AI infrastructure is becoming part of the broader software supply-chain battlefield.

Security Must Follow the Entire Lifecycle

Protection cannot stop at installation.

Organizations need controls during development, testing, deployment, updating, and retirement.

The Biggest Lesson Is About Trust

The TeamPCP campaign demonstrates that the most dangerous code is not always code that looks malicious.

Sometimes the most dangerous code is code that looks completely legitimate.

The Arrests Send a Warning to Other Criminals

The coordinated investigation shows that international cybercrime investigations can eventually identify individuals operating behind online aliases and technical infrastructure.

The Investigation Is Far From Finished

Authorities are still examining evidence, meaning the full scope of the campaign may not yet be known.

Organizations Should Act Before the Next Headline

Companies connected to affected software should not wait for another arrest or breach report before reviewing their credentials, dependencies, and build environments.

TeamPCP Is a Warning for the Entire Industry

The ultimate lesson is uncomfortable but clear: modern organizations are only as secure as the software and trust relationships they allow into their environments.

✅ Confirmed: Australian authorities arrested Ruben Ian Thomson and Louis Michael Gaebler in Perth and charged them with a combined 14 offenses connected to the alleged TeamPCP cybercrime operation.

✅ Confirmed: Authorities say the campaign compromised more than 1,000 organizations, exposed more than 500,000 credentials, and involved at least 300 GB of exfiltrated data.

❌ Needs qualification: Claims that Thomson is definitively the leader, that the suspects personally caused every reported TeamPCP incident, or that the full financial damage has already been established should be treated as allegations while the criminal proceedings and forensic investigation continue. The FBI describes Thomson as the alleged leader, while authorities say the investigation remains ongoing.

Prediction

(+1) The arrests are likely to accelerate the dismantling of TeamPCP’s infrastructure. Seized devices and data could provide investigators with information about additional operators, cryptocurrency transactions, victim organizations, and criminal partners.

(+1) The cybersecurity industry will place even greater emphasis on software supply-chain security. The scale of the alleged campaign provides another powerful argument for stronger package integrity, provenance, dependency monitoring, and CI/CD security.

(+1) Organizations will increasingly adopt automated credential rotation. The reported theft of hundreds of thousands of credentials demonstrates why exposed secrets cannot be treated as a minor incident.

(+1) International cybercrime cooperation will become more important. The Australian investigation, supported by the FBI, illustrates how cross-border collaboration can connect online activity to real-world suspects.

(-1) The arrests will not immediately eliminate the underlying risk. Stolen credentials and data may already have been copied, traded, or reused by other criminal actors.

(-1) Additional victims could emerge. The forensic examination of seized evidence and continued investigation may reveal that the campaign reached more systems than currently understood.

(-1) Supply-chain attacks are unlikely to disappear. The economics remain attractive: compromising one trusted software component can potentially provide access to a huge downstream population.

Final Perspective

The TeamPCP arrests mark an important moment in the fight against modern cybercrime, but they should not be mistaken for the conclusion of the story.

The most important legacy of this case may not be the identities of the people arrested. It may be the realization that the modern software supply chain has become one of the most valuable attack surfaces on the internet.

When a developer installs a package, when a CI/CD pipeline pulls a dependency, or when a security tool executes inside a corporate environment, an invisible trust decision is being made.

TeamPCP allegedly learned how to exploit that trust at extraordinary scale.

The arrests now give investigators a chance to understand how that operation worked, where the stolen information went, and who else may have benefited.

For defenders, however, the lesson is already clear.

Trust every dependency carefully. Rotate every exposed secret. Monitor every privileged build system. And assume that a compromise upstream can become a crisis downstream.

The next major supply-chain attack may not announce itself as malware.

It may arrive as an ordinary software update.

▶️ Related Video (84% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: www.securityweek.com
Extra Source Hub (Possible Sources for article):
https://www.github.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube