• Login
teqpost
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy
No Result
View All Result
teqpost
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy
No Result
View All Result
teqpost
No Result
View All Result

Home / Security / Two men charged in Australia over TeamPCP supply chain hacks

Two men charged in Australia over TeamPCP supply chain hacks

byLotfi Ben Taleb
August 28, 2026
in Security
Reading Time: 2 mins read
Close-up of a person's wrists bound behind their back in steel handcuffs
Share on Facebook
Share on Twitter

The Australian Federal Police has charged two Western Australian men over their alleged roles in the TeamPCP hacking group, the syndicate blamed for a string of open-source supply chain attacks that began in late 2025.

Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, appeared in Perth Magistrates Court on 27 August facing a combined 14 offences. In a statement, the AFP described the pair as part of “a sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.” The AFP statement did not name either man; that came from court records once the case reached Perth.

Inside the TeamPCP hacking group’s alleged campaign

TeamPCP first surfaced in late 2025, embedding malicious code into hundreds of open-source packages and then extorting the businesses that depended on them. Its most damaging campaign landed in March 2026, when the group compromised the open-source security scanners Trivy and Checkmarx KICS, along with the AI gateway LiteLLM. All three are tools engineering and security teams use specifically to catch malicious code before it reaches production, which made the compromise more than an ordinary poisoned package: it hit the layer meant to prevent exactly this kind of attack.

A cross-border case

SecurityWeek reported that Australian and US authorities worked together to identify and charge the pair, and that both face many years in prison if convicted. That cooperation reflects how supply chain attacks tend to play out: the poisoned code, the victims and the people running the operation are rarely in the same country, so a single national police force is seldom enough to build a case. It is also the latest in a run of cross-border enforcement actions against hacking operations, following moves like the DOJ’s seizure of domains linked to Chinese state-sponsored hackers.

How the identification came together

Krebs on Security had already identified Thomson by name back in June, two months before the arrests, and had been in contact with him since. Krebs traced a series of missteps the alleged TeamPCP leader left behind, including a GitHub account, since archived, that ties back to the identity Krebs had already reported. Krebs also interviewed someone describing themselves as TeamPCP’s spokesperson, a separate thread from the account that reportedly exposed the leader.

What to watch

Neither Gaebler nor Thomson has entered a plea, and the AFP has not said whether it believes anyone else was involved in the March compromise of Trivy, Checkmarx KICS and LiteLLM. The spokesperson Krebs interviewed was speaking independently of the two men now charged, which leaves open whether more of TeamPCP is still operating while the Perth case proceeds.

Previous Post

GTA 6 Extended Look runtime confirmed, filmed on base PS5

Next Post

GeForce NOW adds DLSS 4.5 controls, five new games at Gamescom

Related Posts

Tangled colored network patch cables running into a server rack panel
Security

Citrix confirms two NetScaler zero-days under active attack

September 28, 2026
Rows of blue-lit server hard drive caddies in a data center rack
Security

ShinyHunters bypass WAFs to exploit Oracle PeopleSoft flaw

September 27, 2026
Rendered illustration of a data center corridor lined with server racks showing blue status lights
Security

WSO2 and Adobe Commerce flaws land on CISA’s exploited list

September 26, 2026
0 0 votes
Article Rating
Subscribe
Notify of
0 Comments

Popular News

Three Samsung phone backs side by side, green with many cameras, purple and cream with three cameras

Galaxy S27 renders show a design split from the Ultra

October 1, 2026
Close-up of an iPhone's glass back and dual rear camera lenses lit from above

iPhone Duo 3D model lets you open the hinge before launch

September 20, 2026
A Radeon graphics card installed in a PC case, lit by green and blue ambient light

Modders get DLSS 5 running on AMD’s RDNA 4 GPUs

September 7, 2026
Close-up of a GeForce RTX graphics card installed in a PC case with a blurred power cable bundle

DLSS 5 mods expose RTX 5090’s power connector limit

September 27, 2026
Next Post
Close-up of a black GeForce GTX graphics card with cooling fan and heatsink fins

GeForce NOW adds DLSS 4.5 controls, five new games at Gamescom

Technology for enthusiasts and gamers. Hardware, gaming and the software in between, with the spec sheets read properly and the marketing taken back out.

Categories

Categories

  • AI
  • Gadgets
  • Gaming
  • Hardware
  • Policy
  • Security
  • Software
Site Links
  • Latest
  • About
  • Contact
About
  • How We Work
  • Privacy Policy

© 2026 teqpost. All rights reserved.

  • Privacy Policy
  • Contact

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy

© 2026 JNews - Premium WordPress news & magazine theme by Jegtheme.

wpDiscuz
0
0
Would love your thoughts, please comment.x
()
x
| Reply