Two young Australian men have been arrested and charged over alleged links to TeamPCP, the hacking group behind a wave of software supply chain attacks that caused havoc in the open-source coding community throughout 2026.
The men, both from Western Australia, were charged following a joint investigation between the Australian Federal Police and the Western Australia Police Force, in collaboration with the US Federal Bureau of Investigation.
You’re out of free articles for this month
Authorities allege the pair were involved in “large-scale cybercrime” including identity theft, data intrusion, and money laundering.
“These men are allegedly members of the cybercriminal group TeamPCP, whose malicious code potentially compromised more than a thousand organisations worldwide,” FBI Cyber Division Assistant Director Brett Leatherman said in an August 27 statement.
“We are proud to work with the Australian Federal Police and the Western Australia Police Force to impose cost on criminal actors and combat the growing threat of software supply-chain attacks.”
The arrests follow an investigation which began in April, when multiple “cyber threat assessment companies” began sharing details of a campaign inserting malicious code into online repositories with the AFP and FBI. This code was then used to infect organisations in government, academia and the private sector, leading to the harvesting of sensitive data.
The law enforcement agencies estimate the campaign potentially compromised more than 1,000 organisations and led to the theft of more than 300 gigabytes of data and more than 500,000 credentials.
“The alleged compromise of a small number of trusted software components had a significant global impact,” the AFP said in a statement.
“To date, the financial impact includes global remediation costs estimated to be hundreds of millions of dollars.”
Search warrants were executed at properties in Cottesloe, Hamilton Hill and Mandurah, where several electronic devices were seized. Police also said they were in the process of forensically examining a “large volume of data” seized during the investigation. Further arrests remain a possibility.
AFP Commander Graeme Marshall said the arrests represented the “force multiplier” of international cooperation.
“Cybercrime syndicates are becoming increasingly organised and often operate like professional businesses, but our investigators are relentless in tracking down criminals who attempt to exploit digital anonymity to attack our community,” Commander Marshall said.
“In this matter, the information provided to authorities by a number of threat assessment companies proved crucial for investigators.
“The AFP’s partnerships extend to private companies as well and industry bodies are part of the solutions to cybercrime.
“Early reporting and sustained cooperation between organisations and law enforcement play a critical role in supporting cybercrime investigations, protecting affected individuals, and mitigating the broader impact of cybercrime across the Australian community.”
The 21-year-old Cottesloe man was charged with:
- One count of possessed data with the intent to commit a computer offence, contrary to section 478.3(1) of the Criminal Code (Cth). The maximum penalty for this offence is three years’ imprisonment;
- Four counts of unauthorised modification of data with intention to commit a serious offence, contrary to sections 477.1 and 372.1 of the Criminal Code (Cth). The maximum penalty for this offence is five years’ imprisonment;
- One count of supplying data with intent to commit a computer offence, contrary to sub-section 478.4(1) of the Criminal Code (Cth). The maximum penalty for this offence is three years’ imprisonment;
- One count of fail to comply with a 3LA order, contrary to section 3LA of the Crimes Act 1914 (Cth). The maximum penalty for this offence is 10 years’ imprisonment; and
- One count of dealing with proceeds of crime, money or property worth $100,000 or more, contrary to section 400.4(1) of the Criminal Code (Cth). The maximum penalty for this offence is 20 years’ imprisonment;
The 23-year-old Mandurah man was charged with:
- One count of possessed data with the intent to commit a computer offence, contrary to section 478.3(1) of the Criminal Code (Cth). The maximum penalty for this offence is three years’ imprisonment;
- Four counts of unauthorised modification of data with intention to commit a serious offence, contrary to sections 477.1 and 372.1 of the Criminal Code (Cth). The maximum penalty for this offence is five years’ imprisonment; and
- One count of supplying data with intent to commit a computer offence, contrary to sub-section 478.4(1) of the Criminal Code (Cth). The maximum penalty for this offence is three years’ imprisonment.
WAPF Acting Commander Peter Foley said the arrests were a significant event for law enforcement in Western Australia.
“It shows the prevalence of cybercrime in our community and that cybercriminals live amongst us,” Acting Commander Foley said.
“The Western Australia Police Force encourages businesses and individuals to report cybercrimes, no matter the size.
“It is important for police to understand what offences are occurring, have the ability to engage and support victims of crime, be provided with the opportunity to seize and analyse digital evidence from virtual crime scenes.
“This allows investigators to identify cybercriminals and cybercrime syndicates, locate and deal with them.
“This joint investigation shows cybercrime knows no boundaries and that state, national and international law enforcement partners will respond in a collaborative and coordinated manner.
“Businesses and individuals are reminded to ensure that they have up-to-date cyber security measures in place for their computing infrastructure and devices.”
Click Here For The Original Source.
