Australian Authorities Dismantle ‘TeamPCP’ Cybercrime Syndicate Behind Global Software Supply Chain Attacks

In a significant blow to the global cybercrime landscape, Australian law enforcement has apprehended two men suspected of being key figures in "TeamPCP," a prolific data extortion and hacking group blamed for orchestrating the most persistent and damaging software supply chain attacks in recent history. The arrests mark the culmination of a high-stakes international investigation involving the Australian Federal Police (AFP), the FBI, and the Western Australia Police Force, bringing an end to a spree of malicious activity that targeted thousands of global businesses.

In an official statement released today, the AFP confirmed that two men from Western Australia, aged 21 and 23, were taken into custody. Authorities described the pair as members of a "sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses." While the AFP did not disclose the names of the defendants in its initial release, subsequent reports from the Australian Broadcasting Corporation (ABC) identified the suspects as 23-year-old Michael Gaebler and 21-year-old Ruben Ian Thomson, both residents of the Perth area.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

The investigation into TeamPCP has been a focal point for security researchers since the group first emerged in late 2025. By embedding malicious code into hundreds of open-source software tools, the group successfully extorted victims and compromised corporate cloud environments on a massive scale. Their primary weapon was a self-propagating worm dubbed "Shai-Hulud," which allowed the group to inject malicious payloads into software maintained by developers whose credentials had been harvested via phishing attacks or credential stuffing on platforms like GitHub and NPM.

The Anatomy of a Supply Chain Heist

The operational success of TeamPCP was rooted in a cyclical exploitation model. Journalist Andy Greenberg, writing for Wired earlier this year, explained that the group’s core tactic involved a recursive cycle of developer exploitation. By gaining access to a network where a commonly used open-source tool was being developed, the hackers would plant malware within that tool. This infected software would then be distributed to other developers, who would inadvertently incorporate the tainted code into their own projects, including tools intended for further distribution. This cycle allowed TeamPCP to steadily expand its reach, stealing credentials and eventually publishing malicious versions of legitimate development tools.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

The group’s ambition extended beyond simple theft. In May, TeamPCP openly published the source code for the third iteration of the Shai-Hulud worm and launched a recruitment contest. They offered a $1,000 prize in Monero (XMR) to whichever participant could conduct the most extensive supply chain operation using their code. The contest rules, which scored participants based on the number of downloads their compromised packages received, were designed to incentivize attacks on the most widely used code libraries.

Security firm Dataminr noted that the competition was essentially a talent identification program, with TeamPCP offering to purchase any high-value access harvested by participants. The prize money was described by the group as a "participation trophy," signaling that those who delivered significant compromises stood to gain far more lucrative payouts.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

The reach of these operations was extensive. In March, TeamPCP executed a targeted strike against AI infrastructure by compromising LiteLLM, an open-source gateway connecting users to over 100 large language models. A subsequent analysis by CloudSEK revealed that this single breach resulted in the theft of cloud service keys and sensitive secrets from more than 2,500 organizations, including many of the world’s leading technology companies. By May, the group claimed credit for compromising at least 3,800 code repositories at GitHub after a single developer fell victim to a malicious code extension.

Meet the "Cybercats"

Industry experts emphasize that TeamPCP is less of a traditional, hierarchical criminal organization and more of a loose amalgamation of threat actors from various gangs who occasionally collaborated. Austin Larsen, a principal threat analyst with the Google Threat Intelligence Group, described the entity not as a structured crew, but as a "peer community of individually-skilled actors, with one clear center of gravity."

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

That center of gravity appears to have been George Prepakis, who operated under the handle @kernelstub on X (formerly Twitter). Prepakis facilitated the creation of a Matrix chat server dubbed "Cybercats," which served as the daily hub for TeamPCP and other associated cybercrime entities to coordinate operations. Members of the Cybercats chat were often linked to specific criminal handles, many of whom would taunt victims on social media before their attacks were even acknowledged by the press.

Other notable figures within the "Cybercats" circle included the handle "Boxturtle," an associate of TeamPCP known for selling data stolen from major automotive manufacturers like BMW, Audi, Honda, Mercedes-Benz, Volvo, and Toyota. Another administrator, "SeesawSec," has been linked to the group Fulcrumsec, which claimed responsibility for extortion attacks against major corporate entities such as Novo Nordisk, LexisNexis, and Avnet.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

The investigation into these individuals revealed a trail of digital breadcrumbs. The user "pcpcasper," identified as Michael Gaebler, was a vocal member of the Neo-Nazi political group known as the National Socialist Network. His online activity, including videos of his pet cat, provided investigators with geographic indicators that ultimately helped narrow his location to Western Australia.

The Rise and Fall of the TeamPCP Leader

The leader of the operation, Ruben Thomson, operated under several aliases including "Ellis," "BulkDMT," and "Express." His path to notoriety was marked by a blend of technical capability and severe personal instability. Before the group’s downfall, Thomson had been remarkably open about his life and activities during interviews, revealing a history of drug addiction and homelessness.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Thomson’s downfall, however, was largely self-inflicted through a series of significant operational security (OPSEC) failures. Despite his role in sophisticated attacks, he frequently reused credentials, left digital footprints linking his personal identity to his criminal handles, and even registered legitimate Australian business entities—such as "OPSEC Express"—using names directly tied to his cybercrime activity. In a final ironic turn, Thomson registered on the bug-bounty platform HackerOne using the username "Deadcatx3," an alias already flagged by multiple security firms as being linked to TeamPCP.

During an interview via Signal, Thomson acknowledged his activities, claiming he had stopped leading TeamPCP in March 2026. He expressed a mix of detachment and resignation regarding his future, noting that he felt he needed help that a prison environment could not provide. His posts to the "Cybercats" server often documented his ongoing struggles with substance abuse, including the use of dissociative anesthetics and psychedelics.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Legacy and Industry Impact

The apprehension of Thomson and Gaebler has prompted reflection among security professionals regarding the changing nature of modern cyber threats. Charlie Eriksen, a security researcher at Aikido Security, noted that TeamPCP represents a new breed of threat actor that defies traditional categorization—they are neither state-sponsored nor strictly ideological, but rather a chaotic mix of motives including profit, notoriety, and disruption.

Eriksen argues that the group’s success was aided significantly by the proliferation of AI and large language models, which have compressed the time between identifying an exploit and operationalizing it. This allows threat actors to scale their operations without necessarily developing the long-term discipline or operational security traditionally required. While this lack of discipline often leads to mistakes, it does not diminish the potential for widespread damage.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Ultimately, TeamPCP’s legacy may be the forced evolution of software supply chain security. The group’s persistent attacks on GitHub and other platforms humiliated major tech providers into action, resulting in the implementation of "cooldown" periods for dependency updates—a safeguard that industry experts had been demanding for years.

"They managed to wake up Microsoft to the fact that they had become negligent," Eriksen observed. "They humiliated them into action."

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

As of late August 2026, Ruben Thomson and Michael Gaebler remain in custody. According to reports from the Perth Magistrates Court, Thomson was denied bail, and both men are expected to remain behind bars until their next court appearance, scheduled for September 18. Their arrest brings a definitive end to one of the most disruptive chapters in recent open-source supply chain security history, leaving behind a wake of corporate reforms and a stark reminder of the vulnerabilities inherent in the modern digital ecosystem.

Share:

Dwi Wanna writes for Tech Maze.

Leave a comment