Authorities in Australia have arrested two men believed to be core members of TeamPCP, a prolific cybercrime and data extortion group held responsible for orchestrating the longest-running and most disruptive software supply chain attack spree in history.
In an official statement released today, the Australian Federal Police (AFP) announced that two men from Western Australia, aged 21 and 23, were taken into custody following a joint operation involving the AFP, the Federal Bureau of Investigation (FBI), and the Western Australia Police Force (WAPF). The suspects are connected to what authorities described as a sophisticated cybercrime syndicate that allegedly created malicious open-source software to target and rob thousands of global businesses.

While the AFP did not publicly name the defendants in its initial release, investigative reporting by Brian Krebs revealed the 21-year-old suspect’s real identity as Ruben Ian Thomson in June, culminating in months of communication. ABC News in Australia later confirmed Thomson and 23-year-old Michael Gaebler were the two individuals arrested in Perth. Thomson was denied bail, while Gaebler’s attorney did not request bail; both men are being held in custody until their next court appearance scheduled for September 18.
TeamPCP first vaulted onto the global cybercrime scene in late 2025, embedding malicious code into hundreds of open-source software tools and systematically extorting victims for financial gain. Members of the collective made international headlines by compromising corporate cloud environments utilizing a self-propagating worm dubbed Shai-Hulud. The worm inserted malicious payloads into open-source programs maintained by developers whose credentials at public code repositories, such as GitHub and NPM, had been phished or otherwise stolen.
Writing for Wired, journalist Andy Greenberg described TeamPCP’s core methodology as a cyclical exploitation scheme targeting software developers. The hackers gained access to networks where popular open-source tools were actively developed, planted malware within those tools, and allowed the compromised software to end up on the machines of other developers—including those writing additional tools for coders. This enabled TeamPCP to steal credentials, publish malicious versions of subsequent software tools, and continuously expand their collection of breached corporate networks.

TeamPCP also engaged in a form of cyclical recruitment. In May, the source code for the third iteration of Shai-Hulud was published online, and the group launched a contest offering $1,000 in Monero cryptocurrency to the participant who could conduct the largest supply chain operation using the worm’s code. Contestants were scored based on the weekly and monthly download counts of their compromised packages, directly incentivizing them to target the most popular code libraries.
Security firm Dataminr noted that the $1,000 prize served merely as a recruitment floor. The group dismissed the initial payout as a participation trophy, confirming that participants who found meaningful access would be paid significantly more. The contest functioned primarily as a large-scale talent identification and malicious access acquisition initiative.
The syndicate’s reach extended into artificial intelligence infrastructure in March, when TeamPCP executed a supply chain attack targeting LiteLLM, an open-source AI gateway connecting users to more than 100 different large language models. An analysis by security firm CloudSEK revealed that the attack harvested cloud service keys and sensitive credentials from more than 2,500 organizations, including major technology enterprises worldwide. By May, TeamPCP claimed credit for compromising at least 3,800 code repositories on Microsoft-owned GitHub after a developer installed a compromised browser or code extension.

Meet the Cybercats
Security experts emphasize that TeamPCP operates less like a traditional hierarchical hacker group and more as an amalgamation of threat actors from multiple criminal factions collaborating toward shared objectives. Austin Larsen, a principal threat analyst with the Google Threat Intelligence Group, noted that the collective is not a structured crew with a single operator, but rather a peer community of skilled individuals with a distinct center of gravity.
That center of gravity has been identified as George Prepakis, a security researcher and self-described exploit developer operating under the handle @kernelstub on Twitter/X. Earlier in the year, Prepakis posted an invite link to a Matrix chat server named "Cybercats," which TeamPCP and allied cybercrime entities used for daily communication over a period of months.

Administrators and participants in the Cybercats chat used handles associated with separate criminal groups that occasionally collaborated on supply chain and data ransom attacks. Among them was "Boxturtle," linked to data breach broker handle @xpl0itrsturtle on Breachforums and Darkforums, who sold data stolen from major automotive manufacturers including BMW, Audi, Honda, Mercedes-Benz, Volvo, and Toyota, alongside data allegedly sourced from Snapchat and SportRadar.
Another administrator, "SeesawSec," was tied to the cybercrime group Fulcrumsec, which claimed responsibility for data extortion attacks against pharmaceutical giant Novo Nordisk, data broker LexisNexis, and Fortune 500 electronic components distributor Avnet. A third figure, operating under @pcpcasper, utilized Telegram channels that linked them directly to the National Socialist Network, an Australian neo-Nazi organization. Sources confirmed that @pcpcasper was one of the two men arrested in Perth.
The roster also featured an administrator known simply as "T," short for the banned Twitter/X profile @pcpcats, operated by the self-described TeamPCP spokesperson who was also arrested. As investigations progressed, members of the chat often noted T’s extended absences, which he attributed to intensive drug use and exhaustion.

Who is the TeamPCP Leader?
The Cybercats member @pcpcats utilized multiple aliases across cybercrime forums, including EllisD25/LSD on Darkforums, BulkDMT on Breachstars, and Express on Breachforums. These accounts shared consistent instant messaging contact handles across posts. BulkDMT was also known as DMT Host, a virtual private service peddled on English-language cybercrime communities.
According to intelligence firm Intel 471, the Express account registered on Breachforums using an email address mapped to internet addresses in South Africa, where the user frequently discussed local political and social issues. Public reporting from Cyberscoop previously indicated that Google had traced TeamPCP residential and mobile internet connections to South Africa during several attacks.

Simultaneously, identity threat protection firm SpyCloud traced the same email address to an account named ChristmasSnow on Raidforums in 2022, which was predominantly accessed via internet service providers in Perth, Australia. Passive DNS records maintained by DomainTools linked those Perth internet addresses to a residential file server operated by a family named Thomson. Open-source intelligence and public records connected the household to Ian Thomson, a dentist in the Perth suburb of Cottesloe, and his sons, including Ruben Thomson.
Historical breach records and forum registrations revealed that Ruben Thomson used aliases including Yolosolo17, Sheep420, and Yakuza.cc, alongside email addresses tied to web development, proxy services, and scam profiles. Ruben Thomson had incorporated multiple businesses in Australia since 2024, including Secure Computing Solutions, Tensor Industries, and OPSEC Express—a striking operational security failure given that "OPSEC" refers to the practice of concealing one’s real-life identity online.
Further exposure came when Ruben Thomson registered on HackerOne in June 2025 using the username Deadcatx3, an alias previously flagged by multiple security firms as a key identifier for TeamPCP.

Interview with Ellis
In July 2026, KrebsOnSecurity interviewed the TeamPCP leader, who spoke openly via Signal about his involvement and personal struggles under the name Ellis. Ellis claimed he stopped participating in cybercrime for TeamPCP in March 2026, just prior to the LiteLLM attacks, and that leadership had shifted to other individuals.
Ellis recounted that he had recently completed a sobriety program when he reconnected with old malware development peers. Having experienced periods of homelessness and instability, he noted that blackhat hacking provided intellectual rewards and community that standard employment opportunities failed to offer him due to his lack of formal qualifications. He estimated earning roughly $20,000 through his activities with TeamPCP, maintaining that personal enrichment was never his primary motivation.

Despite expressing gratitude for the camaraderie within the group, Ellis showed little remorse for the syndicate’s disruptive campaigns, though he acknowledged that his ongoing struggles with substance use remained a constant challenge.
Security researchers have highlighted TeamPCP as an evolution in modern cyber threats. Charlie Eriksen, a security researcher at Aikido Security, noted that the group defies traditional classifications as state-sponsored actors, organized criminal syndicates, or ideological groups, blending financial motivation with disruption and notoriety. Eriksen observed that the proliferation of large language models has significantly compressed the knowledge gap required to execute complex attacks, enabling threat actors to operate at scale without necessarily exercising professional discipline or considering the collateral consequences.
TeamPCP’s campaign ultimately served as a catalyst for defensive reform. In response to the Shai-Hulud worm and widespread open-source poisoning, GitHub introduced a mandatory three-day cooldown mechanism for Dependabot updates in late July, allowing security maintainers adequate time to vet newly released packages. Similar safeguards were subsequently adopted across other major programming ecosystems. Eriksen remarked that TeamPCP achieved in a matter of months what the supply chain security community had advocated for years, effectively forcing major technology platforms to elevate their defensive postures.

Australian federal authorities confirmed that the two arrested men face a combined total of 14 cybercrime offenses. Following their initial appearance in the Perth Magistrates Court, both defendants remain remanded in custody ahead of their next scheduled court date on September 18.