TeamPCP Arrests: 500K Credentials Stolen From 1,000+ Orgs
Two alleged TeamPCP members face up to 20 years in prison after a supply-chain campaign that stole 500,000 credentials and 300GB from over 1,000 organizations via Trivy, KICS, and LiteLLM. The case underscores how compromised CI/CD pipelines became a data-harvesting network for extortion groups.
Beat this week
Last 7 days · Threat Intelligence
Impact 6.3/10 (+0.1 vs prior). Counts are stories in our record, not a market forecast.
Open the change reportCoverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 83 percentage points.
This story sits in Threat Intelligence — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.
Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.
Cybersecurity briefing
Key takeaways
- Two alleged TeamPCP members face up to 20 years in prison after a supply-chain campaign that stole 500,000 credentials and 300GB from over 1,000 organizations via Trivy, KICS, and LiteLLM.
- The case underscores how compromised CI/CD pipelines became a data-harvesting network for extortion groups.
- SecurityWeek
- BleepingComputer
In this briefing
Mentioned
Key Intelligence
Key Facts
- 1Australian Federal Police arrested Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, in Cottesloe and Mandurah, Western Australia, on August 26, 2026.
- 2TeamPCP compromised major developer tooling and registries including Aqua Security's Trivy, Checkmarx's KICS, PyPI's LiteLLM, Telnyx, SAP, and TanStack packages.
- 3The campaign exfiltrated at least 300 GB of data from more than 1,000 organizations worldwide and siphoned over 500,000 corporate credentials from CI/CD pipelines.
- 4Global remediation costs are estimated in the hundreds of millions of dollars, according to the Australian Federal Police.
- 5Thomson faces five categories of computer hacking and money laundering offenses, each carrying 3 to 20 years in prison; Gaebler faces hacking charges with a maximum penalty of 5 years.
- 6TeamPCP deployed the Mini Shai-Hulud worm, and likely the original Shai-Hulud, to automate credential theft and self-propagation across package registries.
Who's Affected
Analysis
For cybersecurity teams, the TeamPCP arrests are less about two hackers and more about the systemic failure of trusted developer tooling. The attackers weaponized tools your developers use daily—Trivy, KICS, and LiteLLM—to pivot from a single compromised package into half a million stolen credentials and 300GB of exfiltrated data. If your organization pulled any of these dependencies into production, the window for forensic review is now.
The coordinated arrest of two alleged TeamPCP operatives in Western Australia on August 26, 2026, marks one of the most significant law enforcement actions against software supply chain attackers. Australian Federal Police, working with the FBI and Western Australia Police, charged Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, in connection with a campaign that the AFP says compromised more than 1,000 organizations, stole half a million credentials, and exfiltrated at least 300 GB of data. The two men were taken into custody in Cottesloe and Mandurah after an investigation that began in April 2026. Thomson faces five categories of computer hacking and money laundering offenses, each carrying three to 20 years in prison, while Gaebler faces computer hacking charges with a maximum penalty of five years. These arrests are not just a criminal prosecution; they represent an attempt to disrupt a supply chain model that has quietly become one of the most effective ways to harvest enterprise secrets at scale.
Given that TeamPCP has been linked to breaches at the European Commission, Mistral AI, OpenAI, and GitHub, the stolen data could include sensitive government and frontier AI source code, not just routine enterprise credentials.
TeamPCP's tradecraft has been unusually effective. The group compromised trusted developer tooling and package registries—including Aqua Security's Trivy vulnerability scanner, Checkmarx's KICS, PyPI's LiteLLM, Telnyx, SAP, and TanStack packages—injecting malicious code into builds that developers then pulled into their own applications. Because these components live inside automated CI/CD pipelines, the attackers gained access to cloud access keys, authentication secrets, and source code without ever targeting an end organization directly. That indirect approach allowed TeamPCP to turn thousands of otherwise well-defended organizations into victims, while the original compromise point was a single trusted package. BleepingComputer notes that the group is not a single cohesive unit but a loose-knit collective of threat actors who frequent shared hacking forums, Discord servers, and Telegram channels. This distinguishes TeamPCP from traditional hierarchical ransomware gangs and makes attribution and disruption more difficult.
The operational details are sobering. The group deployed the Mini Shai-Hulud worm—and likely the original Shai-Hulud—to automate credential theft and self-propagation across package registries, according to SecurityWeek. The worm's ability to spread autonomously meant each compromised package could seed further infections, dramatically expanding reach. The AFP's announcement states that the financial impact includes global remediation costs estimated in the hundreds of millions of dollars. That number is likely understated, as it captures remediation rather than the downstream consequences of extortion and ransomware enabled by stolen infrastructure secrets. TeamPCP's stolen cloud access keys were funneled to extortion and ransomware groups, creating a multiplier effect where a single supply chain compromise could cascade into multiple extortion incidents across different victim organizations.
The law enforcement response, while notable, leaves significant questions unanswered. The AFP has seized devices belonging to the two men and is conducting forensic analysis, and further arrests and charges have not been ruled out. But the decentralized, forum-based nature of the collective means that removing two alleged members may not degrade TeamPCP's overall capability. The malicious infrastructure, package tampering, and credential exfiltration may continue through other affiliates or mirrored accounts. Investigators still need to determine how much money the two men earned from their activities, and whether the data they exfiltrated has already been transferred to third parties. Given that TeamPCP has been linked to breaches at the European Commission, Mistral AI, OpenAI, and GitHub, the stolen data could include sensitive government and frontier AI source code, not just routine enterprise credentials.
What to Watch
For the wider security community, this case validates the urgency of software supply chain defense. SecurityWeek's reporting emphasizes that TeamPCP hijacked automated build workflows and popular package registries, transforming corporate software pipelines into data-harvesting networks. Defenders must assume that any third-party dependency can become an attack surface. Techniques such as Software Bill of Materials, repository verification, build provenance, and continuous monitoring of registry changes are no longer optional. The arrests also highlight the role of information sharing between cybersecurity firms and law enforcement. The investigation began with key information from private security vendors, suggesting that external telemetry—not purely government surveillance—was the trigger. That may encourage more vendors to report early signals, though the slow timeline from April to August suggests the forensic work is complex.
Looking ahead, the TeamPCP case may become a benchmark for how authorities pursue supply chain attackers. If the AFP and FBI can convert device seizures into attribution for additional members, it could signal a new deterrence model. But the more immediate test is whether disrupted infrastructure remains offline or reappears under new package names. Organizations using compromised packages—Trivy, KICS, LiteLLM, SAP, TanStack, and others—should audit their dependencies and assume any CI/CD secrets were exposed. The next few weeks of forensic disclosure will likely reveal the true scope of the compromise, and it may be substantially larger than the current 1,000-organization, 300 GB baseline.
Timeline
Timeline
Investigation begins
AFP and FBI receive key information from cybersecurity firms and open a joint investigation into TeamPCP supply-chain attacks.
Arrests in Western Australia
Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, are arrested in Cottesloe and Mandurah; electronic devices seized for forensic analysis.
Charges announced
AFP announces charges for computer hacking and money laundering, with Thomson facing up to 20 years per offense and Gaebler up to 5 years.
Source cluster
Primary reporting
- SecurityWeekAustralia Arrests 2 Alleged TeamPCP Hackers
Cite This Page
"TeamPCP Arrests: 500K Credentials Stolen From 1,000+ Orgs." Cyber Intelligence Brief, August 27, 2026. https://getcyberbrief.com/story/australia-arrests-teampcp-hackers-cyber
How we covered this story
Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled cybersecurity-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |