The Rise and Fall of TeamPCP: How a Reckless Collective Rewrote the Rules of Supply Chain Cybercrime

In a landmark operation that marks a turning point for global software security, Australian authorities have successfully dismantled the core leadership of TeamPCP, a decentralized but prolific cybercrime syndicate responsible for the most sustained and destructive software supply chain attack spree in history.

The Australian Federal Police (AFP) confirmed this week that two men, aged 21 and 23, were arrested in Western Australia following a joint investigation involving the FBI and local authorities. While the police withheld the defendants’ identities in their initial statement, subsequent reports and forensic investigations have identified the primary orchestrator as Ruben Ian Thomson, a 21-year-old resident of the affluent Perth suburb of Cottesloe. His associate, 23-year-old Michael Gaebler, was also taken into custody. Both now face a staggering 14 charges related to systemic cyber-extortion and malicious software development.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

TeamPCP’s reign, which began in late 2025, functioned less like a traditional criminal enterprise and more like a volatile, drug-fueled "peer community" of hackers. By exploiting the inherent trust in open-source ecosystems, the group turned the very tools used to build modern software into weapons of mass disruption.


A Chronology of Chaos: The Shai-Hulud Era

TeamPCP’s entry into the cybercriminal landscape was marked by the deployment of Shai-Hulud, a self-propagating worm designed to infiltrate the supply chains of popular coding platforms. Unlike traditional ransomware, which often targets individual endpoints, Shai-Hulud targeted the "upstream" source.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

By phishing the credentials of developers on GitHub and NPM, the group embedded malicious code into hundreds of open-source packages. When downstream developers updated their software, they unwittingly pulled the malware into their own production environments. This "cyclical exploitation" allowed the group to compromise an ever-expanding web of corporate networks, harvesting cloud service keys and sensitive secrets from thousands of global businesses.

Key Milestones in the Campaign:

  • March 2026: TeamPCP strikes a critical blow to AI infrastructure by compromising LiteLLM, an open-source gateway. Security firm CloudSEK reported that this single breach exposed cloud secrets belonging to over 2,500 organizations, including major technology conglomerates.
  • May 2026: The group claims responsibility for compromising 3,800 GitHub repositories after a developer inadvertently installed a compromised code extension.
  • Mid-2026: The group pivots to a "gamified" recruitment strategy. They launched a competition offering $1,000 in Monero (XMR) to participants who could conduct the largest supply chain operations using Shai-Hulud’s code. This contest functioned as a talent-scouting mechanism, allowing TeamPCP to acquire high-value access harvested by lower-level participants.

The "Cybercats" and the Anatomy of a Syndicate

Security analysts from Google Threat Intelligence Group describe TeamPCP as a "center of gravity" for a loose federation of actors known as the Cybercats. This group utilized the Matrix chat platform to coordinate, boast about conquests, and share stolen data.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

The group’s internal culture was a blend of technical brilliance and catastrophic operational security (OPSEC) failures. Among the administrators was "Boxturtle" (@xpl0itrsturtle), a broker who peddled data stolen from automotive giants like BMW, Audi, and Toyota. Another, "SeesawSec," fronted the group Fulcrumsec, which targeted pharmaceutical titan Novo Nordisk and LexisNexis.

The downfall of the group was largely driven by its own hubris. The leader, Ruben Thomson, operated under several aliases—including EllisD25, BulkDMT, and Deadcatx3—frequently linking his criminal identities to his real-world persona through reused passwords, email addresses, and even public business registrations.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Forensic investigations revealed that Thomson had registered Australian companies under names like "OPSEC Express," a profound irony given that he repeatedly used his criminal handles as business names. Furthermore, his attempt to engage with the legitimate security research community on HackerOne under his alias Deadcatx3 provided authorities with the "smoking gun" needed to link the criminal actor to the physical individual in Western Australia.


Official Responses and the Arrest

The arrest of Thomson and Gaebler was the culmination of months of digital surveillance. For much of 2026, the group was under the watchful eye of both private security firms and international law enforcement.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

In an interview conducted via Signal shortly before his arrest, Thomson (referred to by his handle "Ellis") admitted to his role, though he claimed to have stepped back from leadership in March 2026. His narrative was one of personal struggle, characterized by cycles of addiction and a feeling of alienation from the traditional job market. "I am nowhere close to a skill level where I am comfortable," he told reporters, "this would take maybe half a decade of further experience."

The AFP confirmed the arrests on August 27, 2026. According to court records, Thomson was denied bail, while Gaebler’s counsel did not contest his remand. Both are slated for a secondary court appearance on September 18, where they will face the reality of their digital transgressions.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Implications for Global Supply Chain Security

While TeamPCP caused millions in damages, security experts argue that their legacy may paradoxically be the strengthening of the digital ecosystem. Charlie Eriksen, a security researcher at Aikido Security, labeled Shai-Hulud the "best thing to happen to supply chain security."

The group’s relentless attacks forced Microsoft and other platform providers to implement long-overdue safeguards. In late July 2026, GitHub introduced a mandatory three-day "cooldown" for Dependabot updates. This mechanism forces a delay between the release of an update and its automated deployment, providing a window for security researchers to identify malicious injections before they propagate.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

The "AI Compression" Factor

A critical takeaway from the TeamPCP era is the role of Artificial Intelligence in lowering the barrier to entry for cybercrime. Eriksen notes that historically, an attacker needed deep research, coding skills, and infrastructure expertise to launch a supply chain campaign. "LLMs have compressed that gap significantly," he stated.

The result is a new class of "accidental" cyber-terrorists: actors who are technically proficient enough to cause systemic damage but lack the operational discipline of state-sponsored groups. They are often noisier, more prone to mistakes, and more likely to leave behind "digital breadcrumbs" that lead to their front doors.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Conclusion: A Cautionary Tale

The story of TeamPCP is a quintessential 21st-century tragedy of the internet age. It features a group of individuals with the raw intellectual capability to have been elite software architects, who instead chose to channel their skills into a cycle of destruction, ego-driven exploitation, and substance abuse.

The case serves as a stark warning to the open-source community: the model of "implicit trust" that built the modern web is no longer sufficient. As the dust settles in Perth and the legal proceedings begin, the global software industry must grapple with the fact that the next "TeamPCP" may already be forming in the shadows of an encrypted chat room. The infrastructure is now more secure, but the threat, fueled by the accelerating capabilities of AI and the volatile nature of underground digital subcultures, remains as persistent as ever.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

For Ruben Thomson and Michael Gaebler, the "game" has ended. For the rest of the world, the task of hardening the supply chain against the next wave of "Cybercats" is only just beginning.