deniz.in

Markets

Weather

Loading weather

· via TechCrunch

Two Arrested in Perth Over TeamPCP Supply Chain Hacks That Reached OpenAI and Mercor

Australian Federal Police have arrested two Perth men accused of belonging to TeamPCP, the group behind supply chain attacks on open-source tools that hit OpenAI, Mercor, Trivy and others.

Two Arrested in Perth Over TeamPCP Supply Chain Hacks That Reached OpenAI and Mercor

Two men have been arrested in Perth and charged in connection with TeamPCP, a hacking group blamed for a string of high-profile breaches against major technology companies in recent months. According to TechCrunch, the pair face more than a dozen charges spanning hacking, money laundering and other cybercrime offences, and were expected to appear in court later on Thursday.

How the campaigns worked

TeamPCP specialised in software supply chain attacks. As TechCrunch describes it, the group would break into and maliciously modify a popular open-source tool used by potentially thousands of companies, so that anyone who installed the tampered version pulled hostile code onto their own systems.

The goal, according to the Australian Federal Police (AFP), was to infect large numbers of computers, harvest credentials and data, and then pressure victims into paying a ransom. Once running on a company's or developer's systems, the code grabbed private keys and other sensitive credentials used to reach cloud storage, along with customer data in many cases. The authorities said the hackers amassed more than half a million stolen credentials, which they used to push further into other companies.

The scale of the breaches

The FBI's cyber division chief, Brett Leatherman, was quoted saying the two alleged TeamPCP members are accused of hacking into more than a thousand organisations. TechCrunch notes that it remains unclear whether the US Justice Department will seek extradition, and that the FBI declined to comment when approached.

The group's known victims include Trivy, a widely used open-source vulnerability scanner. That compromise affected every organisation depending on the tool, among them LiteLLM, the AI recruiting startup Mercor and others. TeamPCP is also suspected of breaching the European Commission's cloud infrastructure, and of targeting additional open-source projects and developer applications that provided pathways into services such as GitHub and OpenAI.

An unmasking by a journalist

The police have not named the arrested men, but independent cybersecurity journalist Brian Krebs reported that one of them is Ruben Thomson, who used the hacker handle Ellis. According to Krebs, he had been in contact with Ellis over several months, and the hacker told him he had led TeamPCP until March 2026. Krebs said Ellis made mistakes that ultimately allowed the journalist to work out his real identity.

The AFP said its investigation began in April 2026 after receiving information from multiple cybersecurity companies. At a press conference on Wednesday, officials said they had seized a large quantity of allegedly stolen data along with devices and other electronics, and that they intend to notify the victims of the attacks.

Why it matters

TeamPCP's campaigns are a case study in why open-source supply chains are such an attractive target: a single tampered tool can reach thousands of downstream organisations at once, and the harvested credentials then open doors into cloud providers and services such as GitHub and OpenAI. The arrests also show that coordinated work between agencies like the AFP and FBI, seeded by private-sector tip-offs, can eventually catch up with such groups. But the damage is not automatically undone. With more than half a million credentials stolen and an unknown quantity of data now seized, affected organisations will only be able to respond properly once they are notified, which the police say they plan to do.

  • #security
  • #supply-chain
  • #open-source
  • #hacking
  • #australia

Related posts