Advertisement
Advertisement
Advertisement
28 August 2026·7 min read·By Sloane Meyer

Two Alleged TeamPCP Members Arrested and Charged

Two alleged TeamPCP members arrested and charged after months of software supply-chain attacks compromising over 1,000 organizations worldwide.

Two Alleged TeamPCP Members Arrested and Charged

Two Alleged TeamPCP Members Arrested and Charged

Two men from Western Australia were arrested and charged Wednesday for their alleged roles in TeamPCP, a notorious cybercrime group that inserted malicious code into widely used open-source software, a campaign that compromised more than 1,000 organizations worldwide. Australian authorities didn't formally name them. But Australian media identified the pair as Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23. Police arrested both after searching properties, and they seized electronic devices for forensic testing in the process. That's the whole story.

Thomson faces eight charges, including four counts of unauthorized data modification, dealing in criminal proceeds worth $100,000 or more, and refusal to comply with an order to hand over device passwords. Gaebler faces six related counts. The Australian Federal Police, which worked with the Western Australia Police Force (WAPF) and the Federal Bureau of Investigation, allege both men were part of a syndicate engaged in “data intrusion, identity crime and cryptocurrency-based money laundering.” Investigators said further arrests have not been ruled out.

Months of Havoc

TeamPCP has been one of the most active cybercriminal groups in 2026. They struck in late February. Exploiting a misconfigured workflow in Trivy, Aqua Security's widely used vulnerability scanner, the group stole a service-account token, and Aqua replaced its credentials but missed some. So on March 19, they pushed a malicious Trivy release through every distribution channel at once. That's a bold move. The result: malware sat inside thousands of automated build pipelines, and we can't underestimate the fallout from that single, sweeping attack.

The European Commission and GitHub were downstream victims. Investigators estimate the campaign exposed more than 500,000 credentials, removed at least 300 gigabytes of data, and produced global cleanup costs in the hundreds of millions of dollars. Then came the worms. In May, a piece of self-replicating malware known as “mini Shai-Hulud” targeted prominent software libraries, including TanStack, UiPath, and MistralAI, embedding credential-stealing code into development tools downloaded millions of times a week, so the damage spread fast and far. Earlier this month, Oligo Security shared exclusive research with CyberScoop that dated the group’s attacks as far back as 2020. That’s a long game. But it’s not over yet.

Cat Photos and GitHub Accounts

Alongside the arrests, researchers at the Canadian threat intelligence firm Flare published research that traced Ruben Thomson’s online presence. Working from a GitHub alias, DeadCatx3, the researchers found a bug-bounty account under the name Ruben Thomson and a profile listing masscan[.]cloud, a domain that served as command server for mini Shai-Hulud. From there, a password tied to a school email address led researchers to databases of stolen credentials and a trove of accounts: a personal Google account, a TikTok profile under Thomson’s name, and a Steam gaming page showing a cat seated before several monitors.

The cat image surfaced on a TeamPCP Telegram identity. Flare assessed with high confidence that Thomson ran the group, and the firm said it confirmed those findings with law enforcement. Charlie Eriksen, lead malware researcher at Aikido Security, called the arrests a “relief,” but he warned that the actions don’t mean the threat toward open-source software suddenly vanishes. Still, it's a start. But the pressure isn't off yet, not by a long shot, because the same vulnerabilities that drew Thomson’s group remain open for anyone else to exploit.

“The conditions that produced them haven’t gone away, so there will be another TeamPCP,” he told CyberScoop in an email. “We just don’t know their name yet.”

Who Was Affected?

The scale is staggering. More than a thousand organizations worldwide found malicious code in their software supply chains, and the fallout didn't stop there, because the European Commission and GitHub both suffered downstream effects from the Trivy incident. Credential theft alone touched over 500,000 accounts. Data exfiltration hit at least 300 gigabytes. Cleanup costs have climbed into the hundreds of millions of dollars, a figure that keeps rising as organizations audit their systems for lingering backdoors, and it's far from over. So don't expect a quick fix.

Computer screen displaying code with a context menu

The real damage may not be measured in credentials or gigabytes. It’s in the trust eroded across the open-source ecosystem. Developers who pulled Trivy releases in March had no reason to suspect the tool they relied on for vulnerability scanning was itself compromised. The same goes for the libraries targeted by mini Shai-Hulud, tools downloaded millions of times weekly by developers who never imagined the code they were integrating was stealing credentials.

What Happens Next?

The two men will appear in Australian court Thursday. The charges against them carry serious weight, particularly the allegations of dealing in criminal proceeds and refusing to comply with password handover orders. The FBI’s involvement signals the international scope of the investigation.

These men are allegedly members of TeamPCP. Their malicious code potentially compromised more than a thousand organizations worldwide, according to Brett Leatherman, assistant director of the FBI’s Cyber Division. We’re proud to work with the Australian Federal Police and the Western Australia Police Force. So we impose cost on criminal actors and combat the growing threat of software supply-chain attacks. It’s a tough fight. But we can’t let up.

Investigators Not Done Yet

More arrests can't be ruled out. The investigation spanned multiple agencies across two continents, and the forensic testing of seized electronic devices may yield additional leads that could reshape the case entirely. Flare's research traced Thomson's activities with "high confidence," but the full extent of the group's operations remains under examination. And that's not the end of it.

  • Thomson: 8 charges including unauthorized data modification and dealing in criminal proceeds
  • Gaebler: 6 related charges
  • Both men arrested after property searches and device seizures
  • Further arrests not ruled out by investigators

The Lesson for Open Source

Eriksen’s warning cuts to the heart of the matter. The arrests are a win for law enforcement, but they don’t address the underlying vulnerabilities that made TeamPCP’s campaign possible. Misconfigured workflows, missed credential rotations, and trust in automated build pipelines created the conditions for this chaos. Those conditions persist.

The TeamPCP members arrested this week may face justice, but the infrastructure that enabled their attacks remains largely unchanged. It's still there, waiting. Open-source maintainers still run projects with limited resources, and organizations still rely on automated tools without fully auditing their security posture, so the same gaps persist in plain sight. The next group, whatever their name, will find the same doors open. They don't even need to knock.

For now, the focus is on the two men in Australian custody and their day in court. That's the immediate picture. But the broader reckoning with software supply-chain security will take much longer, because as Eriksen noted, the conditions that produced TeamPCP haven't gone away and they're still simmering beneath the surface. The arrests mark a notable step. The struggle is far from over.

Frequently Asked Questions

Who were the two alleged TeamPCP members arrested and what were their ages?

The two alleged TeamPCP members were Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, both from Western Australia. They were arrested and charged Wednesday for their alleged roles in the cybercrime group.

What specific charges does Ruben Thomson face?

Ruben Thomson faces eight charges, including four counts of unauthorized data modification, dealing in criminal proceeds worth $100,000 or more, and refusal to comply with an order to hand over device passwords. These charges were detailed in the article.

How did TeamPCP compromise more than 1,000 organizations?

TeamPCP exploited a misconfigured workflow in Trivy, a widely used vulnerability scanner, and stole a service-account token. They then pushed a malicious Trivy release through all distribution channels, which inserted malware into thousands of automated build pipelines, leading to the compromise of over 1,000 organizations worldwide.

What was the extent of the damage caused by the TeamPCP campaign?

The campaign exposed more than 500,000 credentials, removed at least 300 gigabytes of data, and produced global cleanup costs in the hundreds of millions of dollars. Additionally, the European Commission and GitHub were affected as downstream victims.

What did researchers at Flare discover about Thomson's online activities?

Researchers at Flare traced Thomson's online presence through a GitHub alias, DeadCatx3, and found a domain that served as a command server for mini Shai-Hulud. They also found databases of stolen credentials and various accounts, including a Steam page with a cat image that appeared on a TeamPCP Telegram identity, leading them to assess with high confidence that Thomson ran the group.

Sloane Meyer
Written by
Cybersecurity Editor

Sloane Meyer covers cybersecurity, privacy and the threats facing individuals and organisations online. She explains how attacks happen and what can be done to stay protected.

💬 Comments (0)

Sign in to leave a comment.

No comments yet. Be the first!

Advertisement