Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
Two men charged in Australia for alleged role in TeamPCP cybercrime group, which compromised open-source security scanners and AI gateway.
Intelligence analysis by Qwen 2.5 (3B)

Two men in Australia have been charged for their alleged involvement in the TeamPCP cybercrime group, which compromised open-source security scanners and AI gateway.
Two men in Australia were caught for stealing passwords from open-source projects and putting bad software in them. This let the bad guys get into lots of computers and steal lots of passwords. The police found out who did it and the men got in big trouble.
Analysis
{"heading_1":"The TeamPCP Cybercrime Group","subheading_1":"Background and Infrastructure","content_1":"The TeamPCP group is believed to have been active since at least 2020, with evidence linking it to other groups like TA-NATALSTATUS and IronErn. The group used stolen credentials to compromise open-source projects and AI gateways, with the compromised data potentially affecting over 1,000 organizations.","subheading_2":"Compromised Projects and Data","content_2":"The compromised projects included Trivy, Checkmarx KICS, and LiteLLM. The group used stolen credentials to push backdoored versions of these projects, which were then used to exfiltrate data. The compromised data included more than 500,000 credentials and at least 300 gigabytes of data.","subheading_3":"Forensic Analysis and Evidence","content_3":"The Australian Federal Police (AFP) executed search warrants at properties in Cottesloe, Hamilton Hill, and Mandurah, seizing electronic devices for forensic analysis. The forensic evidence helped identify the two men as principal participants in the TeamPCP group.","subheading_4":"Legal Proceedings and Penalties","content_4":"The two men, Louis Michael Gaebler and Ruben Ian Thomson, were charged with various offenses, including possessing data with intent to commit a computer offense, unauthorized modification of data, and dealing with proceeds of crime. The section 3LA count carries a maximum penalty of 10 years' imprisonment, and the proceeds of crime count carries a maximum of 20 years."}
Key points
- Two men in Australia were charged for their alleged involvement in the TeamPCP cybercrime group.
- The group compromised open-source security scanners and AI gateways, potentially affecting over 1,000 organizations.
- The forensic evidence helped identify the two men as principal participants in the TeamPCP group.
- The two men were charged with various offenses, including possessing data with intent to commit a computer offense, unauthorized modification of data, and dealing with proceeds of crime.
The charges against the TeamPCP group may help prevent similar attacks in the future by making it harder for hackers to steal passwords and put bad software in open-source projects.
The charges may not have a big impact on preventing future attacks, as the group may have already compromised many more projects and stolen more passwords.


