Two Australians Charged in Global TeamPCP Supply-Chain Cyberattack
Two Western Australian men, aged 21 and 23, have been charged with 14 offenses related to a sophisticated supply-chain attack allegedly orchestrated by the cybercriminal group TeamPCP. The Australian Federal Police (AFP), in collaboration with the Western Australia Police Force (WAPF) and the FBI, arrested the suspects on 26 August 2026 following search warrants executed in Perth, Cottesloe, Hamilton Hill, and Mandurah.
Authorities allege the men were key figures in a syndicate that inserted malicious code into open-source software repositories, which was then unknowingly integrated into systems by developers worldwide. The compromised components spread across government, academic, and private-sector organizations, leading to the theft of over 500,000 credentials and the exfiltration of at least 300GB of data. The attack potentially impacted more than 1,000 organizations globally, with remediation costs estimated in the hundreds of millions of dollars.
The investigation began in April 2026 after cybersecurity firms flagged the campaign. The suspects are accused of data intrusion, identity crime, and cryptocurrency-based money laundering, with seized devices still under forensic analysis. The 21-year-old from Cottesloe faces eight charges, including unauthorized data modification and dealing in proceeds of crime, while the 23-year-old from Mandurah faces six similar offenses. Both are scheduled to appear in Perth Magistrates Court on 27 August 2026.
FBI Cyber Division Assistant Director Brett E. Leatherman stated the arrests impose significant costs on those behind software supply-chain attacks. AFP Commander Graeme Marshall noted that cybercrime syndicates increasingly operate like professional enterprises, emphasizing the role of industry intelligence in disrupting such threats. The investigation remains ongoing, with further arrests not ruled out.
Source: https://cybersecuritynews.com/two-australians-teampcp-supply-chain/
ReversingLabs cybersecurity rating report: https://www.rankiteo.com/company/reversinglabs
Government of Western Australia cybersecurity rating report: https://www.rankiteo.com/company/wagovernment
"id": "REVWAG1788058567",
"linkid": "reversinglabs, wagovernment",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'More than 1,000 organizations',
'industry': ['Government',
'Academia',
'Private Sector'],
'location': 'Global',
'type': 'Government, academic, and private-sector '
'organizations'}],
'attack_vector': 'Malicious code in open-source software repositories',
'data_breach': {'data_exfiltration': 'Yes (300GB of data)',
'number_of_records_exposed': 'Over 500,000 credentials',
'personally_identifiable_information': 'Likely (credentials)',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Credentials', 'Sensitive data']},
'date_detected': '2026-04',
'date_publicly_disclosed': '2026-08-26',
'description': 'Two Western Australian men, aged 21 and 23, have been charged '
'with 14 offenses related to a sophisticated supply-chain '
'attack allegedly orchestrated by the cybercriminal group '
'TeamPCP. The attack involved inserting malicious code into '
'open-source software repositories, which was then unknowingly '
'integrated into systems by developers worldwide, leading to '
'the theft of over 500,000 credentials and the exfiltration of '
'at least 300GB of data.',
'impact': {'data_compromised': 'Over 500,000 credentials, at least 300GB of '
'data',
'financial_loss': 'Hundreds of millions of dollars (estimated '
'remediation costs)',
'identity_theft_risk': 'High',
'systems_affected': 'Government, academic, and private-sector '
'organizations globally'},
'initial_access_broker': {'entry_point': 'Open-source software repositories'},
'investigation_status': 'Ongoing',
'motivation': 'Financial gain, data theft',
'post_incident_analysis': {'root_causes': 'Supply-chain compromise via '
'malicious code in open-source '
'software'},
'references': [{'source': 'Australian Federal Police (AFP)'},
{'source': 'FBI'}],
'regulatory_compliance': {'legal_actions': 'Charges filed (14 offenses '
'including unauthorized data '
'modification, identity crime, and '
'money laundering)'},
'response': {'law_enforcement_notified': 'Yes (AFP, WAPF, FBI)',
'third_party_assistance': 'FBI, cybersecurity firms'},
'threat_actor': 'TeamPCP',
'title': 'Two Australians Charged in Global TeamPCP Supply-Chain Cyberattack',
'type': 'Supply-Chain Attack',
'vulnerability_exploited': 'Supply-chain compromise via open-source software'}