Independent cybersecurity news, intelligence and analysis
HomeSecurity AnalysisRSS Feed
Where Cyber News Becomes Intelligence.Global cyber events transformed into clear, practical intelligence for defenders and security professionals.
Independent cybersecurity news, intelligence and analysis
Latest  •  Analysis
Threat Activity

Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks

Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks. Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree...

By CyberDeltaForce Newsroom Published Aug 27, 2026, 11:56 AM UTC

What happened

Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks. The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences over their alleged role in TeamPCP, the cybercrime group behind the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS and the AI gateway LiteLLM. Australian authorities have arrested and charged two young men accused of belonging to TeamPCP, a hacking group linked to a string of far-reaching developer supply chain attacks.

Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos. Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a "sophisticated cybercrime syndicat.

Two Alleged 'TeamPCP' Hackers Arrested in Australia. Australia arrests alleged TeamPCP hackers behind supply-chain attacks. Private researchers traced one suspect through leaked passwords and a decade-old gaming profile.

Australia Arrests 2 Alleged TeamPCP Hackers. Australian and US authorities collaborated to identify and charge the alleged cybercriminals, who face many years in prison. Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, appeared in Perth Magistrates Court on August 27,.

Editorial note: this News Brief follows the available evidence and adds length only when additional facts or useful context are available. Where public reporting does not establish a specific victim sequence, CyberDeltaForce does not present one as fact.

CONFIRMED FACTS

What the reporting and advisory establish

The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences over their alleged role in TeamPCP, the cybercrime group behind the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS and the AI gateway LiteLLM.

Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, appeared in Perth Magistrates Court on August 27,

In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a "sophisticated cybercrime syndicat

Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks

Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a "sophisticated cybercrime syndicat

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Australian authorities have arrested and charged two young men accused of belonging to TeamPCP, a hacking group linked to a string of far-reaching developer supply chain attacks.

Australian and US authorities collaborated to identify and charge the alleged cybercriminals, who face many years in prison.

CYBERDELTAFORCE INTELLIGENCE

What this means for your environment

Move from the published facts to the technical path, exposure conditions and defensive decisions that matter in a real environment.

TECHNICAL SEQUENCE

Attack & Exploitation Path

The sequence below reconstructs the intrusion from the stages supported by public reporting. Undisclosed transitions remain explicitly marked rather than inferred.

Confirmed / reportedRequired conditionSecurity assessmentNot publicly disclosed
1
trust pathConfirmed / reported

a software, supplier, dependency or update relationship is part of the access path.

2
identity accessConfirmed / reported

stolen credentials, sessions, tokens or another trusted identity are involved.

3
impactConfirmed / reported

ransomware, encryption or extortion is part of the incident.

Trusted pathTrivy, Checkmarx KICS, LiteLLM
Where to lookDeveloper workstations, CI/CD pipelines, containers and build automation
Main concernA compromised upstream component entering a trusted workflow

Why this matters to you

This is relevant beyond the organizations named in the headline because a compromised software supply chain can transfer risk to every downstream team that trusted the affected component. The key question is whether Trivy, Checkmarx KICS, LiteLLM entered your build, scanning or deployment path and what privileges it could reach there.

RELATE IT TO YOUR ENVIRONMENT

Does this deserve attention in my environment?

Check the conditions below against your use of Trivy, Checkmarx KICS, LiteLLM.

Local only — your selections are not sent to CyberDeltaForce.
YOUR CURRENT VIEWNot assessed yet

Select the conditions that are true in your environment. Leaving a condition unselected does not mean you are safe — it only means you have not marked it as applicable.

What to check now
  • Identify where Trivy, Checkmarx KICS, LiteLLM appears in developer workstations, CI/CD pipelines, containers and automation.
  • Verify package, image and release provenance against trusted vendor or project guidance; do not rely only on a package name or latest tag.
  • Review CI/CD, registry, source-control and cloud logs for unusual access or secret use associated with affected build paths.
  • Rotate exposed build or deployment credentials if your investigation finds a compromised artifact or unauthorized use.

Sources & References

Original reporting and technical references are kept here for readers who want to verify the facts. Publisher names stay out of the reading flow above.

The Hacker NewsAug 27, 2026, 11:56 AM UTC
KrebsOnSecurityAug 27, 2026, 11:04 AM UTC
BleepingComputerAug 27, 2026, 1:31 PM UTC
SecurityWeekAug 27, 2026, 12:48 PM UTC
CyberScoopAug 27, 2026, 2:31 PM UTC
CyberDeltaForce publication standards