Australia arrests alleged TeamPCP hackers behind supply-chain attacks
Australian authorities arrested two men, aged 21 and 23, linked to the TeamPCP hacking group, accused of widespread supply-chain attacks that compromised over a thousand organizations globally and stole half a million credentials.
Intelligence analysis by Gemini 2.5 Flash

TeamPCP is known for injecting malicious code into open-source software and developer platforms, which was then unknowingly incorporated into applications used by government, academic, and private sectors. The group, believed to be a loose-knit collective, caused hundreds of millions of dollars in remediation costs worldwide.
Imagine someone secretly putting a tiny, bad instruction into a popular building block that many people use to build their computer programs. When others use that block, the bad instruction helps the secret person steal their digital keys and information. Police in Australia caught two young men who they say were doing just that, causing big problems for many companies around the world.
Analysis
TeamPCP's Modus Operandi
TeamPCP, identified as a hacking group, specialized in developer supply chain attacks by injecting malicious code into open-source software repositories. This method allowed them to compromise software components that developers would then unknowingly integrate into their own applications.
The malicious code served to steal credentials, authentication secrets, and source code from systems across government, academic, and private-sector organizations. The group's activities were not attributed to a single, cohesive unit but rather a loose-knit collective of threat actors who communicated and operated through various hacking forums, Discord servers, and Telegram channels.
Global Impact and Costs
The scale of TeamPCP's operations was extensive, with malicious code potentially compromising over a thousand organizations worldwide. This widespread compromise led to the theft of an estimated half a million credentials and the exfiltration of at least 300GB of data, indicating a significant breach of sensitive information.
The financial repercussions of these attacks are substantial, with global remediation costs estimated to be in the hundreds of millions of dollars. This figure reflects the extensive effort and resources required by affected organizations to identify, contain, and recover from the breaches, highlighting the economic burden of such sophisticated cybercriminal activities.
The Australian Federal Police
The investigation into TeamPCP began in April 2026, following key information received by the Australian Federal Police (AFP) and the FBI from cybersecurity firms. This collaborative international effort culminated in the arrests of two men, aged 21 and 23, in the Western Australian cities of Cottesloe and Mandurah on August 26, 2026.
During the arrests, law enforcement seized electronic devices and other evidence for forensic analysis, which is expected to provide further insights into the group's operations. The suspects face a combined 14 charges, including possessing and supplying data for computer offenses and modifying data to facilitate serious crimes, with potential penalties ranging from 3 to 20 years' imprisonment per charge. The AFP has not ruled out further arrests or charges as the investigation continues.
Key points
- Australian authorities arrested two men, aged 21 and 23, linked to the TeamPCP hacking group.
- TeamPCP is accused of widespread supply-chain attacks by injecting malicious code into open-source software.
- Attacks potentially compromised over a thousand organizations globally, stealing half a million credentials and 300GB of data.
- Global remediation costs are estimated to be hundreds of millions of dollars.
- The suspects face multiple charges with maximum penalties of 3 to 20 years' imprisonment per charge.
The arrests demonstrate the increasing capability of international law enforcement to track and apprehend cybercriminals operating across borders, potentially deterring other groups from engaging in similar large-scale supply-chain attacks. This successful operation could lead to a deeper understanding of such groups' tactics, improving future defensive strategies.
Given that TeamPCP is described as a "loose-knit collective," the arrests of two individuals may not fully dismantle the entire group, allowing other members to continue their malicious activities. The global scale of the compromise also highlights persistent vulnerabilities in software supply chains, suggesting that similar attacks could still occur.



