Australian Police Arrest Two Members of TeamPCP Hacking Group Behind Breaches at OpenAI, Mercor, and Others

Australian Federal Police arrested two men in Perth on August 27, 2026, accused of belonging to TeamPCP, a cybercriminal group responsible for breaches affecting more than a thousand organizations worldwide. The two face more than a dozen charges including hacking, money laundering, and other cybercrime offenses, and were expected in court later that day.

TeamPCP is known for targeting the software supply chain by infiltrating and maliciously modifying widely used open source tools. Once installed on a company’s or developer’s systems, the tampered code stole private keys and sensitive credentials used to access cloud storage and customer data. Authorities said the group stole more than half a million credentials in total.

Among the group’s known targets was Trivy, a popular vulnerability scanner. The compromise affected any organization relying on the tool, including AI recruiting startup Mercor and LiteLLM. The group is also suspected of breaching the European Commission’s cloud infrastructure and targeting open source projects that provided access to platforms including GitHub and OpenAI.

FBI cyber division chief Brett Leatherman stated that the two alleged members are accused of hacking into more than a thousand organizations. It remains unclear whether the U.S. Justice Department will seek extradition, and an FBI spokesperson did not immediately respond to comment requests.

The Australian investigation began in April 2026 following information provided by multiple cybersecurity companies. During a press conference, officials said they seized a large quantity of allegedly stolen data, along with devices and electronics. Authorities said they plan to notify victims.

Police have not publicly named the arrested men. However, cybersecurity journalist Brian Krebs reported that one is Ruben Thomson, who uses the handle Ellis and claimed to have led TeamPCP until March 2026. Krebs said Thomson made mistakes that allowed his real identity to be uncovered.

The arrests may signal increased international cooperation in pursuing cybercriminal groups that exploit open source software to compromise large numbers of organizations at scale.

Source: TechCrunch

This article was generated by AI and cites original sources.
Scroll to Top