"We cuffed ’em!"
AFP arrests in Perth suburbs
The Australian Federal Police (AFP) announced that two men aged 21 and 23 were arrested on Wednesday in separate locations in the suburbs of Perth. The AFP said the pair “were principal participants in the activities of the cybercrime syndicate and received payments in cryptocurrency for their roles in the illegal activity.” Authorities searched a third nearby property, seized electronic devices and other items, and wrote that “a large volume of data seized is being forensically examined and the investigation remains ongoing.” The AFP added that “Further arrests and charges have not been ruled out.”
FBI identification and the named suspects
The FBI assisted the AFP in the investigation. An FBI Facebook post named one of the arrested men as Ruben Thomson and described him as “the alleged leader of the cybercriminal group TeamPCP.” Australian media named the second man as 23-year-old Louis Michael Gaebler. The public notices from the two agencies frame the operation as a joint, cross-border law enforcement effort that culminated in the pair’s detention and the seizure of digital evidence.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleTeamPCP’s supply-chain techniques: injected malicious code, Trivy and the Shai‑Hulud worm
AFP investigators say the syndicate “allegedly inserted malicious code into software available on an open-source repository, which was then unwittingly used by other developers.” Researchers detected some of those activities prior to April: in March, observers spotted a supply-chain attack on the open-source scanner Trivy. Another intrusion attributed to TeamPCP is the Shai‑Hulud worm, which targets npm packages, attempts to infect them, searches for credentials to major public clouds or services like GitHub, and if it “burrowed into its targets” would either try to replicate to continue its attacks or wipe the environment.
AFP estimates: scope of compromise and projected costs
In its public statement the AFP estimated TeamPCP’s supply-chain operations “potentially compromised more than 1000 organisations globally, enabling the theft of more than 500,000 credentials, and the exfiltration of at least 300 gigabytes of data.” The agency also wrote that “the financial impact includes global remediation costs estimated to be hundreds of millions of dollars.” Those figures provide the government’s current working estimate of scale and economic harm while the seized data are being forensically examined.
How technologists, policymakers, and affected enterprises are likely to respond
- Technologists and security teams will be focused on identifying any instances where malicious code from open-source repositories entered their build or deployment pipelines, scanning for indicators tied to the Trivy compromise or the patterns described for the Shai‑Hulud worm, and rotating credentials where exposure is suspected.
- Policymakers and regulators will note the cross-border cooperation between Australian authorities and the FBI and may use the AFP’s cost estimates and the transnational scope—“more than 1000 organisations globally”—to inform regulatory scrutiny, reporting requirements, or international law-enforcement coordination.
- Affected enterprises and procurement leaders will confront the operational impact implied by the AFP’s numbers: credential theft (over 500,000 credentials alleged), data exfiltration (at least 300 gigabytes), and potential remediation bills in the “hundreds of millions of dollars” range, all while awaiting forensic results from seized devices.
The AFP’s announcement closes with two concrete facts that frame the next phase of the story: a large volume of seized data is under forensic examination, and additional arrests and charges have not been ruled out. Those points underscore that the detentions in Perth, while significant, may be an interim milestone rather than the final word on TeamPCP’s reach, the identities of other participants, or the ultimate tally of affected organisations and costs.
Source: The Register — Australian cops cuff alleged TeamPCP masterminds




