Authorities in Australia have arrested two men believed to be key members of TeamPCP, a prolific cybercrime and data extortion group held responsible for orchestrating the longest-running and most disruptive software supply chain attack campaign in history.
In an official statement released today, the Australian Federal Police (AFP) announced that two men from Western Australia, aged 21 and 23, were taken into custody following a joint operation involving the AFP, the Federal Bureau of Investigation (FBI), and the Western Australia Police Force (WAPF). The suspects are accused of being part of a sophisticated cybercrime syndicate that allegedly created malicious open-source software to target and exploit thousands of global businesses.
While the AFP did not publicly name the defendants in its initial release, investigative journalist Brian Krebs of KrebsOnSecurity independently identified the 21-year-old suspect months prior, maintaining communications with him since June. This reporting includes direct interviews with TeamPCP’s self-described spokesperson and examines the digital footprints and security oversights left behind by the group’s leadership that ultimately paved the way for their identification and apprehension.

TeamPCP first burst onto the global cybercrime landscape in late 2025, deploying malicious code into hundreds of popular open-source software tools and systematically extorting victims for financial gain. The group made international headlines by compromising corporate cloud environments using a self-propagating worm dubbed Shai-Hulud. This worm autonomously injected malicious payloads into open-source programs maintained by developers whose credentials at public code repositories, such as GitHub or NPM, had been phished or otherwise stolen.
Writing for Wired, journalist Andy Greenberg detailed TeamPCP’s core methodology as a cyclical exploitation loop targeting software developers. "The hackers gain access to a network where an open source tool commonly used by coders is being developed," Greenberg explained in May. "The hackers plant malware in the tool that ends up on other software developers’ machines, including some who are writing other tools intended to be used by coders. The malware allows TeamPCP’s hackers to steal credentials that let them publish malicious versions of those software development tools, too. The cycle repeats, and TeamPCP’s collection of breached networks grows."
In addition to this cyclical exploitation, TeamPCP engaged in a form of cyclical recruitment. In May, the source code for the third iteration of the Shai-Hulud worm was published online, and the group quickly launched a contest offering $1,000 in Monero cryptocurrency to whichever participant could execute the largest supply chain operation using the provided code. Contestants were scored based on the weekly and monthly download counts of the packages they compromised, directly incentivizing them to target the most widely used code libraries.

Security firm Dataminr noted the true function of the contest in a deep-dive analysis. "TeamPCP has stated the competition is a recruiting opportunity and they intend to purchase all meaningful access harvested from participants’ campaigns," Dataminr wrote. "The $1,000 XMR prize is a recruitment floor and has been dismissed by the actor as ‘just like participation trophy,’ adding ‘if you find something good you will be paid way more,’ confirming the contest’s true function as talent identification and malicious access acquisition at scale."
The group’s operational reach extended deep into artificial intelligence infrastructure. In March, TeamPCP executed a supply chain attack targeting LiteLLM, an open-source AI gateway connecting users to more than 100 different large language models. A subsequent analysis by security firm CloudSEK revealed that the LiteLLM compromise harvested cloud service keys and sensitive credentials from more than 2,500 organizations, including numerous prominent global technology companies. By May, TeamPCP claimed responsibility for compromising at least 3,800 code repositories at Microsoft-owned GitHub after a developer inadvertently installed a compromised code extension.
Meet the Cybercats
Security experts emphasize that TeamPCP operates less like a traditional hierarchical criminal crew and more as an amalgamated peer community of threat actors drawn from various cybercriminal backgrounds who occasionally collaborate to achieve shared objectives.

"It is not a structured criminal crew with a single operator," said Austin Larsen, a principal threat analyst with the Google Threat Intelligence Group. "It is a peer community of individually-skilled actors, with one clear center of gravity."
That center of gravity has been identified as George Prepakis, an accomplished security researcher and self-described exploit developer who operates the X (formerly Twitter) profile @kernelstub. Earlier this year, Prepakis posted a public invite link to a Matrix chat server he established, dubbed "Cybercats." TeamPCP members and figures associated with other cybercrime entities utilized this server for daily operational communications over several months.
Administrators within the Cybercats chat frequently used their public social media handles during communications. The administrator listed prominently in chat rosters as "Boxturtle" corresponds to the X handle @xploitrsturtle, which is linked to a data breach broker active on Breachforums and Darkforums. This broker has been responsible for selling data stolen from high-profile automotive manufacturers—including the BMW Group, Audi, Honda, Mercedes-Benz, Volvo, and Toyota—as well as data allegedly lifted from Snapchat and SportRadar.

Another Cybercats administrator, "SeesawSec," represents the persona behind Fulcrumsec, a cybercrime operation that recently claimed credit for extortion attacks targeting pharmaceutical giant Novo Nordisk, data broker LexisNexis, and Fortune 500 electronic component distributor Avnet. A third administrator, using the handle "@pcpcasper," discussed TeamPCP attacks on X while maintaining an extensive message history on Telegram. Media and investigative sources revealed that @pcpcasper frequently shared media confirming his presence in Western Australia and was one of the two men arrested by the AFP.
The chat roster also featured an administrator known as "T," short for the now-suspended X profile @pcpcats, operated by the self-described TeamPCP spokesperson who was also taken into custody. As group members frequently noted in chats, T/@pcpcats struggled with extended absences, which he attributed to heavy substance use that left him incapacitated for days at a time.
Who Is the TeamPCP Leader?
The Cybercats member operating as @pcpcats utilized several aliases across underground cybercrime forums, including EllisD25/LSD on Darkforums, BulkDMT on Breachstars, and Express on Breachforums. These accounts shared consistent Tox IDs and Session IDs across forum postings. BulkDMT was also known as the operator of "DMT Host," a virtual private server (VPS) hosting service advertised on English-language forums.

According to cyber intelligence firm Intel 471, the alias Express registered on Breachforums using the email address [email protected] and operated across a two-month period in 2025 using internet protocol addresses located in South Africa. Around the same time, the Telegram alter ego Persy_PCP discussed splitting time between countries and referenced local political tensions in South Africa, aligning with Google’s threat intelligence findings that traced some of TeamPCP’s residential and mobile internet connections to the region.
Further technical attribution by identity threat protection firm SpyCloud traced the [email protected] address to an account named ChristmasSnow on the defunct forum Raidforums in 2022, with access logs pointing to internet service providers in Perth, Australia. Passive DNS records analyzed via DomainTools linked these Perth IP addresses to a private family file server operated by a household with the surname Thomson.
Open-source intelligence and public records revealed that the household included Dr. Ian Thomson, a dentist in the Perth beachside suburb of Cottesloe who originally graduated from the University of Witwatersrand in Johannesburg, South Africa. Public records and breach intelligence databases connected Ian Thomson’s sons, Joshua and Ruben Thomson, to various online profiles and corporate registrations in Western Australia.

Ruben Thomson, utilizing email addresses such as [email protected], maintained an extensive history on cybercrime forums dating back to 2018 under handles such as Yolosolo17, Sheep420, and DingoFlour. On freelance platforms like Upwork and through registered business entities in Australia—including Secure Computing Solutions, Tensor Industries, and OPSEC Express—Thomson described himself as a full-stack web developer and Linux specialist fluent in Python and PHP.
Operational security failures ultimately undermined the group’s anonymity. In June 2025, someone registering under the name Ruben Thomson joined the HackerOne bug bounty platform using the handle Deadcatx3—an alias previously flagged by multiple cybersecurity firms as a primary identifier for TeamPCP.
Interview with Ellis
In early July 2026, KrebsOnSecurity conducted an interview via Signal with the TeamPCP leader, who operated under the name Ellis. He was remarkably candid regarding his activities, motivations, and ongoing personal struggles.

Ellis claimed he stepped away from active cybercrime operations for TeamPCP in March 2026, shortly before the LiteLLM supply chain attacks, leaving other individuals to guide the syndicate. He explained that his entry into the group occurred while he was attempting to recover from substance abuse and seeking a distraction.
"One year ago I needed help monetizing some GitHub credentials, I was two months sober and needed a distraction and something to keep busy as well as people to speak to," Ellis said. "I had largely disconnected from my old circle, they had become very toxic and I needed to get away from the substances. Previously I had done some mass exploitation campaigns and grew up doing malware development and capture the flag contests."
Ellis stated that his total financial return from TeamPCP activities amounted to approximately $20,000, emphasizing that his primary drivers were technical engagement and community connection rather than financial enrichment. "Blackhatting is fun," he remarked. "There are actual rewards and incentives to learn and you grow with your team. Without qualifications, no employer will even take the time to hear you out."

Expressing resignation about the inevitability of law enforcement action, Ellis noted that he had considered turning himself in while attempting to resolve personal matters. Group chat logs recovered from Matrix and Telegram reflected ongoing struggles with sobriety and references to hallucinogenic substances in the weeks leading up to his arrest.
The two suspects were taken into custody on Wednesday morning by the Australian Federal Police. According to reports from the Australian Broadcasting Corporation (ABC News), 21-year-old Ruben Ian Thomson was denied bail following an appearance in the Perth Magistrates Court, while legal representation for 23-year-old Michael Gaebler did not seek bail. Both men remain remanded in custody pending their next scheduled court appearance.
Security researchers note that TeamPCP represents a distinct shift in the threat landscape. Charlie Eriksen, a security researcher at Aikido Security who monitored the group’s campaigns, observed that TeamPCP blurred the traditional boundaries between state-sponsored espionage, financially motivated cybercrime, and ideological disruption. Eriksen added that the integration of large language models has compressed the technical learning curve for emerging threat actors, allowing individuals to operate at significant scale without necessarily cultivating the operational discipline traditionally required.

Nevertheless, Eriksen credited TeamPCP’s disruptive Shai-Hulud campaign with achieving a vital breakthrough in supply chain security. The widespread exploitation forced major hosting platforms like GitHub to implement structural safeguards, including mandatory three-day cooldown periods for automated package dependency updates designed to intercept malicious code before propagation.
"They managed to wake up Microsoft to the fact that they had become negligent in terms of security," Eriksen said. "By compromising GitHub and stealing their source code, they humiliated Microsoft into action, making them finally act on what we had been asking them to do and take seriously for a while now."
Leave a Reply