Australian authorities have arrested and charged two men, aged 21 and 23, accused. Of belonging to TeamPCP, a hacking collective responsible for a wave of software supply-chain attacks. That compromised over 1,000 organizations worldwide and stole an estimated 500,000 credentials and 300GB of data. This guide covers Australia arrests alleged TeamPCP hackers behind supply-chain attacks in detail. This guide covers Australia arrests alleged TeamPCP hackers behind supply-chain attacks in detail. This guide covers Australia arrests alleged TeamPCP hackers behind supply-chain attacks in detail.
Australia arrests alleged TeamPCP hackers behind supply-chain attacks: What Is TeamPCP and How Did They Operate?
TeamPCP is not a traditional hierarchical group. But a loose-knit collective of threat actors who coordinate through hacking forums, Discord servers. And Telegram channels. According to the Australian Federal Police (AFP), the group injected malicious code into. Open-source software packages hosted on public repositories. Developers unknowingly incorporated these compromised components into applications used by government agencies, academic institutions. And private-sector companies globally. High-profile victims include Trivy, LiteLLM, Telnyx, SAP, TanStack, the European Commission, Mistral AI, OpenAI, and GitHub.

How Were the Suspects Identified and Arrested?
The investigation began in April 2026 after the AFP and FBI received intelligence from cybersecurity firms. On August 26, 2026, officers arrested the two men in Cottesloe and Mandurah. Western Australia, seizing electronic devices for forensic analysis. Police allege the suspects received cryptocurrency payments for their role in TeamPCP operations. Following the arrests, independent investigations by cybersecurity firm Flare and journalist Brian Krebs. Linked alleged TeamPCP members to real-world identities through reused aliases, Telegram activity. And other online traces.


What Charges Do the Suspects Face?
The two men face a combined 14 charges. Including possessing and supplying data for computer offenses and modifying data to facilitate serious crimes. The younger suspect also faces charges for allegedly dealing with at least $100,000. In criminal proceeds and failing to comply. With an order requiring access to electronic data. Maximum penalties range from 3 to 20 years' imprisonment per charge. The AFP has not ruled out further arrests as forensic analysis of seized evidence continues.
Why This Matters for Software Supply-Chain Security
The TeamPCP case underscores the systemic risk posed by malicious code injection into trusted open-source dependencies. A single compromised package can cascade across thousands of downstream applications, giving attackers valid credentials. That bypass traditional perimeter defenses. The AFP estimates global remediation costs in the hundreds of millions of dollars. This incident reinforces the need for software bill of materials (SBOM) adoption, dependency scanning. And runtime verification of open-source components in production environments.
What's Next for the Investigation and Industry Response
Forensic analysis of seized devices may uncover additional collaborators, infrastructure, and victim data. The AFP and FBI continue to coordinate with international partners. For developers and security teams, the case is a reminder to enforce signed. Commits, monitor dependency changes. And implement credential rotation policies. Expect increased regulatory scrutiny on software supply-chain transparency following this and similar incidents.
Key Points
Two men arrested in Western Australia on August 26, 2026, charged with 14. Offenses linked to TeamPCP supply-chain attacks
Attacks compromised over 1,000 organizations, stole 500,000 credentials and 300GB of data, with. Remediation costs in hundreds of millions
TeamPCP operated as a loose collective via forums, Discord. And Telegram, injecting malicious code into open-source packages
Investigation began April 2026 after tips from cybersecurity firms. Flare and Brian Krebs later linked aliases to real identities
AFP has not ruled out further arrests as forensic analysis of seized devices continues
The Bottom Line
The TeamPCP arrests demonstrate that law enforcement can penetrate decentralized cybercrime networks. But the scale of compromise highlights how vulnerable the software supply chain remains. To credential theft via poisoned open-source dependencies.
Related Resources
For more context, check our related article on Android Car Head Units Infected in First Documented Malware Supply-Chain Attack.