Skip to content
CYBERSECURITY & DATA PRIVACY

Australian Federal Police Arrest Alleged Leaders of Prolific "TeamPCP" Cybercrime Syndicate

Authorities in Australia have arrested two men believed to be core members of TeamPCP, a prolific cybercrime and data extortion group held responsible for orchestrating what security experts describe as the longest-running and most damaging software supply chain attack campaign in history.

In a joint statement released today, the Australian Federal Police (AFP)—acting in coordination with the Federal Bureau of Investigation (FBI) and the Western Australia Police Force (WAPF)—announced the arrests of two men from Western Australia, aged 21 and 23. The suspects were taken into custody in connection with what law enforcement termed a sophisticated cybercrime syndicate that allegedly created malicious open-source software to target and exploit thousands of global businesses.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

While the AFP did not publicly name the defendants in its initial release, independent investigative reporting by KrebsOnSecurity identified the 21-year-old suspect as Ruben Thomson, whose real identity was uncovered earlier this year, leading to months of communication with the researcher. The second suspect, 23-year-old Michael Gaebler, was identified following subsequent local news reports.

TeamPCP vaulted into the global cybercrime spotlight in late 2025, deploying malicious code across hundreds of open-source software tools and systematically extorting corporate victims for financial gain. The group made international headlines by compromising corporate cloud environments via a self-propagating worm dubbed "Shai-Hulud." This worm surreptitiously injected malicious payloads into open-source programs maintained by developers whose credentials at major public code repositories, such as GitHub and NPM, had been stolen or phished.

Writing for Wired, journalist Andy Greenberg described TeamPCP’s core operational tactic as a cyclical exploitation loop targeting software developers. The hackers initially gain unauthorized access to networks where common open-source tools are actively developed. They then plant malware within those tools, which inevitably propagates to the machines of other software developers—including those building secondary tools for the broader developer community. The malware steals valuable credentials, allowing the group to publish malicious versions of subsequent development tools, thereby widening the breach radius and continuously expanding their collection of compromised networks.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

In addition to cyclical exploitation, TeamPCP practiced a form of cyclical recruitment. In May, the group published the source code for the third iteration of the Shai-Hulud worm online and launched an illicit contest offering $1,000 in Monero cryptocurrency to the participant who could execute the largest supply chain operation using the provided code. Contestants were scored based on the weekly and monthly download numbers of the packages they successfully compromised, directly incentivizing them to target the most popular and widely used code libraries.

Security firm Dataminr noted that TeamPCP framed the competition primarily as a recruitment initiative, stating an intent to purchase all meaningful corporate access harvested by participants. The baseline cryptocurrency prize was dismissed by the group’s leaders as a mere participation trophy, with organizers promising vastly greater payouts for high-value corporate infiltration, thereby operationalizing talent identification and mass access acquisition.

The syndicate’s reach extended deep into critical enterprise infrastructure. In March, TeamPCP executed a high-profile supply chain attack targeting artificial intelligence infrastructure by compromising LiteLLM, an open-source AI gateway used to connect users to more than 100 different large language models. An analysis by security firm CloudSEK revealed that the LiteLLM breach successfully harvested cloud service keys and other sensitive corporate secrets from more than 2,500 organizations, including many of the world’s leading technology enterprises. By May, TeamPCP claimed responsibility for compromising at least 3,800 code repositories on GitHub after a developer installed a compromised code extension.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Meet the Cybercats

Security analysts emphasize that TeamPCP operated less as a traditional, highly structured cybercriminal crew and more as an interconnected peer community of threat actors drawn from multiple criminal gangs who occasionally collaborated to achieve shared objectives. Austin Larsen, a principal threat analyst with the Google Threat Intelligence Group, noted that the collective lacked a single corporate-style operator, instead functioning as a decentralized community centered around a gravitational hub.

That center of gravity was identified as George Prepakis, an accomplished security researcher and self-described exploit developer operating under the handle @kernelstub on Twitter/X. Earlier in the year, Prepakis published a public invite link to a Matrix chat server he created and named "Cybercats," which TeamPCP and various associated cybercrime entities used for daily communication over a span of several months.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Administrators and members of the Cybercats chat frequently used handles corresponding to known cybercrime figures and data breach brokers. Among them was a user known as "Boxturtle," linked to the Breachforums and Darkforums handle @xpl0itrs, who brokered data stolen from major automobile manufacturers—including BMW, Audi, Honda, Mercedes-Benz, Volvo, and Toyota—as well as data allegedly lifted from Snapchat and SportRadar. Another administrator, "SeesawSec," aligned with the Fulcrumsec extortion group, which claimed responsibility for attacks against pharmaceutical giant Novo Nordisk, data broker LexisNexis, and Fortune 500 electronic component distributor Avnet.

Another prominent figure in the chat, operating as @pcpcasper, maintained a heavy presence on Telegram, where shared media tied the user to the National Socialist Network, a neo-Nazi organization based in Australia. Sources close to the investigation indicated that @pcpcasper was one of the two individuals arrested during the police raid, a claim supported by online posts made by Prepakis.

The roster also featured an administrator known simply as "T," short for the now-banned Twitter/X profile @pcpcats, operated by the self-described TeamPCP spokesperson who was also taken into custody. Communications within the Matrix server frequently noted this individual’s erratic participation, often attributed to prolonged battles with narcotics and hallucinogens that kept him awake for days before crashing.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Who Is the TeamPCP Leader?

The individual operating behind the alias @pcpcats utilized several monikers across illicit cybercrime forums, including EllisD25 and LSD on Darkforums, BulkDMT on Breachstars, and Express on Breachforums. These accounts were conclusively linked by shared instant messaging contact handles, including Tox and Session IDs. BulkDMT also operated "DMT Host," a virtual private server hosting service advertised across English-language cybercrime communities.

According to intelligence firm Intel 471, the account holder registered on Breachforums using an email address linked to multiple Internet addresses located in South Africa. In mid-2025, the user claimed to be selling access to 14 gigabytes of data stolen from South Africa’s State Information Technology Agency. Flashpoint records further documented the threat actor complaining about social conditions in South Africa, aligning with Google telemetry tracing TeamPCP’s residential and mobile IP connections to the region during active campaigns.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Concurrently, identity threat protection firm SpyCloud traced the foundational email address to a 2022 Raidforums account named ChristmasSnow, which primarily accessed platforms using internet service providers located in Perth, Australia. Passive DNS records maintained by DomainTools mapped those Perth IP addresses to a private file server utilized by the Thomson family. Open-source intelligence and corporate registry records confirmed that the address belonged to Ian Thomson, a Cottesloe dentist, and his sons, including Ruben Thomson.

Digital breadcrumbs linked Ruben Thomson to numerous online handles, virtual infrastructure, and business entities in Western Australia. Investigators discovered that Thomson had incorporated several companies since 2024, including Secure Computing Solutions, Tensor Industries, and OPSEC Express—the latter bearing an ironic nod to operational security principles, given that "Express" was one of his primary cybercrime forum monikers. Further compromising his anonymity, Thomson registered on the HackerOne bug bounty platform under the username Deadcatx3, an alias previously flagged by multiple security firms as a core identifier for TeamPCP.

Interview with Ellis

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

In early July, following the discovery of his real-world identity, the TeamPCP leader—who requested to be referred to as Ellis—granted an interview via Signal, offering candid insights into his background and motivations. Ellis claimed he stepped away from active cybercrime operations for TeamPCP in March 2026, shortly before the LiteLLM attacks, leaving leadership to other members of the collective.

Reflecting on his entry into the syndicate, Ellis stated that he had recently completed a sobriety program and was seeking a distraction after years of instability and homelessness. "Blackhatting is fun," he remarked, noting that illicit networks provided tangible incentives to learn complex technical skills that formal educational pathways and traditional employers failed to offer him without prior credentials.

Ellis estimated that he earned roughly $20,000 total from his activities with TeamPCP, insisting that financial enrichment was never his primary driver. While expressing gratitude for the camaraderie within the group, he harbored few illusions regarding his future, acknowledging that his ongoing struggles with substance abuse and the inevitability of law enforcement intervention had placed him in an untenable position.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

The two suspects appeared before the Perth Magistrates Court following their arrests. Charlie Eriksen, a security researcher at Aikido Security who closely monitored TeamPCP, observed that the group represents a new paradigm of threat actors who defy traditional classifications—neither state-sponsored nor strictly financially motivated, but driven by an unpredictable mixture of disruption, ideology, and technical curiosity.

Eriksen noted that the lowering technical barrier to entry, catalyzed by the integration of artificial intelligence and large language models, has enabled individuals to scale sophisticated operations without developing the operational discipline traditionally required by professional criminal syndicates. This combination of high capability and lax operational security frequently results in noisy attacks that leave extensive digital footprints, ultimately leading to their undoing.

Nevertheless, Eriksen highlighted that TeamPCP’s aggressive campaign inadvertently triggered profound improvements in global software supply chain security. By exposing systemic vulnerabilities in prominent coding platforms, the syndicate’s actions compelled organizations like Microsoft and repository maintainers to implement essential safeguards, such as mandatory three-day cooldown periods for dependency updates designed to intercept malicious code before it reaches production environments.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Australian authorities confirmed that Ruben Ian Thomson was denied bail, while legal representation for Michael Gaebler did not request bail during their initial court appearance. Both men remain in custody pending their next scheduled court date.

Leave a Reply

Your email address will not be published. Required fields are marked *