Australia Charges Two Men in TeamPCP Software Supply Chain Attack Case

The Australian Federal Police and Western Australia Police Force charged two men as part of an investigation into the TeamPCP campaign. U.S. authorities also unsealed an indictment against Ruben Ian Thomson.

TeamPCP charges have been filed by Australian and U.S. authorities in an alleged campaign targeting the software supply chain. The Australian Federal Police (AFP) and Western Australia Police Force charged two men in Western Australia, aged 21 and 23, with a combined 14 offenses. The U.S. Department of Justice also unsealed a federal indictment against 21-year-old Ruben Ian Thomson on August 27.

In the United States, Thomson faces charges of conspiracy and unauthorized access to information from protected computers in connection with the campaign known as TeamPCP. According to U.S. authorities, he was arrested in Australia. However, the available announcements do not indicate whether the United States will seek his extradition.

What authorities attribute to TeamPCP

The AFP said the investigation concerns the alleged insertion of malicious code into open-source software. Dependencies compromised in this way could then distribute malicious code to other users of those tools.

Investigators also describe the alleged collection of credentials and data, as well as the acceptance of cryptocurrency payments. According to an AFP estimate, the malicious code may have affected more than 1,000 organizations, led to the theft of more than 500,000 credentials, and resulted in the exfiltration of at least 300 GB of data.

These figures are investigators’ estimates, not independently audited final totals. Likewise, the charges do not yet establish guilt or the specific role of either defendant in all of the alleged intrusions.

Why attacks on open-source dependencies matter

The case concerns the software supply chain—when an attack targets not just one organization, but a tool or library used by other developers and companies. Compromising a trusted development dependency can affect a larger number of downstream users.

The arrests therefore do not, by themselves, eliminate the risk associated with credentials or data stolen earlier. The AFP describes the alleged real-world distribution of malicious code, not merely a theoretical attack. At the same time, the available materials do not indicate a single new patch applicable to all potentially affected environments.

Organizations that used the affected tools should, according to the available information, review their dependencies, rotate potentially exposed secrets and credentials, and check for unusual access. The specific compromised packages, systems, and remediation steps must, however, be determined based on their own environments and further announcements from vendors or investigators.

Uncertainty around affected organizations and next steps

Secondary reports have mentioned OpenAI and Mercor in connection with the supply chain incidents. However, neither the AFP nor the U.S. indictment named them in their published announcements. It is therefore not officially confirmed that these organizations were directly compromised.

The investigation in Australia is ongoing. Authorities are analyzing seized data and devices using forensic procedures and have not ruled out further charges or arrests. Key developments to watch include proceedings before the Perth Magistrates Court, any U.S. decision on a request for Thomson’s extradition, and future technical announcements that may identify the affected software packages and systems more precisely.

Thomson is presumed innocent in the U.S. proceedings unless and until proven guilty. The charges against both men will likewise have to be tested in court.

Sources

Verified and updated: 08/28/2026 09:28

Sharing