Australian and US Authorities Charge Two Men in TeamPCP Supply Chain Cybercrime Probe

Daily Feed
Australian and US Authorities Charge Two Men in TeamPCP Supply Chain Cybercrime Probe

Australian and U.S. authorities have charged two Western Australian men in a cybercrime probe tied to an alleged software supply-chain attack that may have hit more than 1, 000 organizations.

  • Two men charged in Australia after a joint AFP, FBI, and Western Australia Police Force investigation
  • Authorities allege supply-chain malware spread through an open-source repository
  • More than 1, 000 organizations may have been affected, with over 500, 000 credentials exposed
  • Cryptocurrency payments are under scrutiny, but the money trail is still incomplete

Australian authorities charged 21-year-old Ruben Ian Thomson and 23-year-old Louis Michael Gaebler on Aug. 26, and both men appeared before Perth Magistrates Court on Aug. 27. The Australian Federal Police filed a combined 14 charges after a joint investigation involving the AFP, the FBI, and the Western Australia Police Force, in a case linked to the FBI and Australian police charge two in TeamPCP probe.

Investigators say the pair were linked to an alleged cybercrime syndicate called TeamPCP. According to police, the group used malicious software distributed through an open-source repository, then took advantage of that trust to reach downstream systems. That is the rotten logic of a supply-chain attack. Compromise one trusted package, and the fallout can spread across a lot of unrelated organizations.

Police allege the operation compromised more than 1, 000 organizations, exposed over 500, 000 credentials, and stole at least 300 gigabytes of data. Authorities also estimate remediation costs could run into the hundreds of millions of dollars. If those figures hold up, this was not some tiny breach or a lone operator in a basement. It was the kind of mess that leaves victims paying for cleanup long after the headlines move on.

The investigation began in April after cybersecurity companies provided intelligence. Warrants were later executed at properties in Cottesloe, Hamilton Hill, and Mandurah. Police have not publicly named the affected organizations, identified the open-source project allegedly used to distribute the malware, or laid out the full victim map. That matters, because in supply-chain cases the exact software component is often what shows how wide the blast radius really was.

Authorities say Thomson and Gaebler played central roles in the alleged scheme and received cryptocurrency for their involvement. That part will grab attention, naturally, but it needs to be handled without the usual crypto hysteria. Crypto may have been part of the payment flow here, but it did not cause the intrusion. Bad code, abused trust, and weak security did.

At the same time, crypto can make criminal payments easier to move across borders, especially when funds pass through exchanges or other regulated services that keep records. Investigators can often follow the trail when criminals are sloppy, and blockchain data can turn into a useful breadcrumb path instead of some magical cloak of invisibility.

Still, the AFP has not disclosed which cryptocurrencies were allegedly used, and it has not provided wallet addresses, transaction hashes, mixer details, exchange accounts, or any confirmed laundering total. No verified seizure value has been released either. So while cryptocurrency appears to be part of the case, the financial picture is still unfinished.

Thomson faces one Australian charge involving money or property worth at least 100, 000 Australian dollars that authorities allege represented criminal proceeds. That charge carries a maximum prison term of 20 years. Separately, the U.S. Department of Justice unsealed a federal indictment against him, charging conspiracy to violate the Computer Fraud and Abuse Act and obtaining information from a protected computer.

In plain English, a protected computer is a system covered under U.S. federal law, often because it is used in interstate or foreign commerce or by government and financial institutions. The U.S. indictment concerns alleged TeamPCP activity during spring 2026. Each U.S. offence carries a maximum five-year prison term, and the fine can reach $250, 000, or twice the alleged gross gain or victim loss.

Thomson remained in Australian custody when prosecutors disclosed the U.S. case. Gaebler was not named in a corresponding U.S. indictment. That split is worth watching, because cross-border cybercrime cases often move at different speeds in different jurisdictions, and prosecutors do not always charge every suspect at the same time.

The next phase will focus on digital forensics and on examining cryptocurrency payment records. That means seized devices, source code, repository access logs, chat records, and whatever financial evidence investigators can piece together. Police have also not ruled out more arrests or additional charges.

The broader lesson here is not that crypto is the villain. Criminals use whatever works: fiat, crypto, cash, intermediaries, or a grim mix of all three. The bigger problem is the one exposed by this case, modern software runs on trust, and supply-chain attacks weaponize that trust at scale. That’s a headache for security teams, a gift to attackers, and a reminder that open-source software is powerful precisely because so many systems depend on it. The same dynamic has pushed even major firms to think harder about decentralized rails and digital assets, which is why a move like Nokia Ventures into Cryptocurrency is worth watching, even if corporate enthusiasm does not magically fix security theater or bad engineering.

For the record, police have been busy elsewhere too. In related crackdowns, the AFP has moved on major crypto-linked seizures including Australian Federal Police Seize $6.4M Crypto Wallet in and Australian Federal Police Seize $4.5M in Bitcoin and Luxury, underscoring that when criminals get careless, the chain does not disappear. It points straight back at them.

Key questions and takeaways

  • What is TeamPCP alleged to be?
    Authorities describe it as an alleged cybercrime syndicate tied to supply-chain malware and credential theft. The claims are still being tested through the courts.
  • What is a supply-chain attack?
    It is an attack that compromises software used by many other systems. If one trusted component is poisoned, the damage can spread to every downstream user.
  • Did authorities say cryptocurrency caused the breach?
    No. Investigators say crypto may have been used to pay participants, but the intrusion itself appears to have come from malicious software distribution and system compromise.
  • Did police disclose wallets or seized crypto?
    No. They have not identified wallet addresses, transaction hashes, mixer use, exchange accounts, or any confirmed laundering total.
  • Why does the U.S. indictment matter?
    It shows the case stretches beyond Australia. Cross-border cybercrime often triggers parallel charges, especially when U.S. systems or victims are involved.
  • What happens next?
    Investigators will keep working through digital evidence and payment records, and more arrests or charges remain possible. The proof will come down to what the forensics can actually show.

If the allegations are confirmed, this will be another reminder that cybercrime at scale is a business model, not a prank. It feeds on weak code, sloppy operational security, and too much trust in software that too many people assume is safe by default.

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog