Australian authorities say TeamPCP is at the center of a major cybercrime investigation after two Western Australian men were charged in connection with an alleged international software supply-chain operation involving the FBI.
The Australian Federal Police (AFP) charged 21-year-old Ruben Ian Thomson and 23-year-old Louis Michael Gaebler with a combined 14 offences on Aug. 26. Both appeared before Perth Magistrates Court on Aug. 27 after authorities conducted searches at properties in Cottesloe, Hamilton Hill and Mandurah.
The scale of the alleged campaign is what makes the investigation particularly significant. Australian authorities estimate that malicious code associated with the operation potentially compromised more than 1,000 organizations worldwide, exposed more than 500,000 credentials and resulted in the theft of at least 300 gigabytes of data. The AFP also estimates that remediation costs could reach hundreds of millions of dollars.
The allegations have not been proven in court, and both defendants remain entitled to the presumption of innocence.
TeamPCP allegedly turned trusted software into an attack vector
Investigators say the alleged operation exploited one of the most dangerous weaknesses in modern cybersecurity: trust.
Rather than attacking every victim directly, TeamPCP allegedly inserted malicious code into legitimate software available through open-source repositories. Developers who downloaded or incorporated the compromised components could then unknowingly introduce the malicious code into their own environments and, potentially, the systems of their customers.
That approach can create a cascading effect. A single compromised developer tool may be used across thousands of organizations, allowing attackers to reach environments that would otherwise be difficult to penetrate individually.
The AFP said its investigation began in April after law enforcement received information from several cyber threat assessment companies about a syndicate allegedly inserting malicious code into software used by other developers. The investigation was conducted alongside the FBI and Western Australia Police Force.
The alleged victims span multiple sectors, including government, academia and private industry. According to investigators, compromised software could search downstream environments for credentials and authentication information before sending stolen data to infrastructure controlled by the attackers.
FBI Cyber Division Assistant Director Brett E. Leatherman described the alleged reach of the operation in stark terms, saying the men were allegedly members of TeamPCP, whose malicious code “potentially compromised more than a thousand organizations worldwide.”
The statement underscores why software supply-chain security has become a major priority for law-enforcement agencies and cybersecurity teams. A vulnerability in one trusted component can effectively become a gateway into an entire network of downstream users.
Cryptocurrency payments are part of the investigation
The case also has a cryptocurrency angle, although authorities have so far provided limited financial details.
Australian police allege that the two men were principal participants in the operation and received cryptocurrency payments for their roles. However, investigators have not disclosed the total value of the digital assets allegedly received, the cryptocurrencies involved or any confirmed laundering amount.
Thomson faces an Australian charge relating to dealing with money or property worth at least A$100,000 that authorities allege represented criminal proceeds. That offence carries a maximum penalty of 20 years in prison, although the charge itself does not establish the amount ultimately proven in court.
The absence of a disclosed cryptocurrency seizure figure is important. While digital assets allegedly formed part of the criminal activity under investigation, authorities have not announced a specific amount of cryptocurrency seized or claimed that a particular sum was laundered.
For investigators, blockchain records could nevertheless become an important source of evidence. Cryptocurrency transactions can leave a permanent public record, allowing investigators to trace funds through wallets and, where transactions touch identifiable services, potentially connect them to real-world individuals or organizations.
The financial investigation could therefore expand as Australian authorities examine seized electronic devices and other evidence.
U.S. charges put Thomson under a separate federal spotlight
The Australian arrests were accompanied by a separate U.S. criminal case.
The U.S. Department of Justice said a federal grand jury indicted Thomson on charges involving conspiracy to commit violations of the Computer Fraud and Abuse Act and obtaining information from a protected computer. The indictment was filed Aug. 25 and unsealed after his Australian arrest.
U.S. prosecutors allege that attacks conducted in spring 2026 involved the compromise of trusted software supply-chain tools. According to the indictment, malicious code was then used to scan downstream environments for sensitive information, exfiltrate data and maintain persistent access.
Prosecutors further allege that stolen information was used in extortion attempts, with victims allegedly being asked to pay in exchange for assurances that their data would not be publicly released.
Each of the U.S. charges carries a maximum five-year prison sentence and a fine of up to $250,000, or twice the gross gain or loss associated with the conduct. Any eventual sentence would depend on a conviction and would be determined by a federal judge.
The U.S. indictment names Thomson but does not announce a corresponding federal indictment against Gaebler.
For TeamPCP, the parallel Australian and U.S. proceedings represent a significant escalation. The case is no longer simply a cybersecurity investigation into compromised software; it has developed into a multinational criminal prosecution involving alleged data theft, extortion, unauthorized computer access and cryptocurrency payments.
Further charges could follow as digital evidence is examined
The investigation is not necessarily over.
Australian police are examining electronic devices and other evidence seized during the raids. That forensic process could reveal additional victims, financial transactions, infrastructure and individuals allegedly connected to the operation.
Authorities have also left open the possibility of further arrests and charges as investigators work through the evidence.
The case illustrates the growing importance of cooperation between governments and private cybersecurity firms. AFP officials said information supplied by threat assessment companies proved crucial to the investigation, highlighting the role of early threat intelligence in identifying complex cybercrime campaigns.
For businesses, the immediate lesson is less about cryptocurrency than software dependency. Organizations that rely on open-source packages and third-party developer tools need to scrutinize software provenance, rotate credentials exposed during compromise windows and monitor authentication activity for signs of unauthorized access.
The alleged operation also demonstrates why software supply-chain attacks can have consequences far beyond the original compromised developer.
As forensic examinations continue, TeamPCP investigators could uncover a much broader picture of how the alleged syndicate operated, how stolen credentials were monetized and where cryptocurrency payments ultimately moved.
For now, however, the central allegations remain before the courts. The Australian and U.S. cases will need to establish the defendants’ individual roles and prove the alleged offences beyond the relevant legal standards before any criminal liability is determined.