Industry News

Two Alleged Members of 'TeamPCP' Hacking Group Arrested in Australia

Krebs on Security · 27 Aug 2026
Key Takeaway Regularly audit and verify the open-source software components your business relies on, since supply chain attacks can compromise you indirectly through trusted third-party code.

The Australian Federal Police (AFP) has arrested two men from Western Australia, aged 21 and 23, over their alleged involvement with TeamPCP, a cybercrime group accused of building malicious open-source software packages to target businesses worldwide. The AFP described the group as a sophisticated cybercrime syndicate believed responsible for robbing thousands of organisations globally through tampered software components.

Supply chain attacks like these work by inserting malicious code into open-source libraries or packages that developers unknowingly pull into their own projects, giving attackers a foothold in systems far beyond the original target. Because open-source components are widely reused, a single compromised package can affect a huge number of downstream businesses before anyone notices.

The arrests highlight how law enforcement is increasingly able to trace and dismantle groups operating in this space, even when they attempt to hide behind pseudonyms and technical obfuscation.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from Krebs on Security. We link back to every original so you can read it yourself.