Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) announced the arrests of two men from Western Australia, aged 21 and 23, in connection with a “sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.” While the AFP did not disclose the defendants’ identities, KrebsOnSecurity has learned the 21-year-old suspect’s real identity and has been in communication with him since June. This report features interviews with TeamPCP’s self-proclaimed spokesperson and examines clues left by the group’s leader that likely contributed to his apprehension.
TeamPCP emerged on the cybercrime scene in late 2025, embedding malicious code into numerous open-source software tools and extorting victims for financial gain. The group gained notoriety for compromising corporate cloud environments using a self-propagating worm called Shai-Hulud. This worm injected malicious code into open-source programs maintained by developers whose credentials at public code repositories like GitHub or NPM had been compromised through phishing or theft. Journalist Andy Greenberg, writing for Wired, characterized TeamPCP’s primary tactic as a cyclical exploitation of software developers. Greenberg explained, "The hackers gain access to a network where an open source tool commonly used by coders is being developed. The hackers plant malware in the tool that ends up on other software developers’ machines, including some who are writing other tools intended to be used by coders. The malware allows TeamPCP’s hackers to steal credentials that let them publish malicious versions of those software development tools, too. The cycle repeats, and TeamPCP’s collection of breached networks grows."

TeamPCP also engaged in a form of cyclical recruitment. In May, the source code for the third iteration of Shai-Hulud was released online, followed by a contest offering $1,000 in virtual currency to participants who could execute the largest supply chain operation using the worm’s code. According to the contest rules, participants were scored based on the weekly and monthly downloads of the packages they compromised, directly incentivizing them to target widely used code libraries. The security firm Dataminr noted, "TeamPCP has stated the competition is a recruiting opportunity and they intend to purchase all meaningful access harvested from participants’ campaigns. The $1,000 XMR (Monero) prize is a recruitment floor and has been dismissed by the actor as ‘just like participation trophy,’ adding ‘if you find something good you will be paid way more,’ confirming the contest’s true function as talent identification and malicious access acquisition at scale."
In March, TeamPCP executed a supply chain attack targeting AI infrastructure by compromising the code for LiteLLM, an open-source AI gateway connecting users to over 100 large language models. A recent analysis by CloudSEK revealed that TeamPCP’s attack on LiteLLM harvested cloud service keys and other secrets from more than 2,500 organizations, including many leading global technology companies. In May, TeamPCP claimed responsibility for compromising at least 3,800 code repositories on Microsoft-owned GitHub, following a GitHub developer’s installation of a code extension compromised by TeamPCP’s malware.

Security experts suggest that TeamPCP is less a cohesive hacker group and more an amalgamation of threat actors from various cybercriminal gangs who collaborate on shared objectives. Austin Larsen, a principal threat analyst with the Google Threat Intelligence Group, stated, "It is not a structured criminal crew with a single operator. It is a peer community of individually-skilled actors, with one clear center of gravity." This central figure is George Prepakis, an accomplished security researcher and exploit developer operating under the Twitter/X handle @kernelstub. Earlier this year, @kernelstub shared a public invite link to a Matrix chat server he created, named "Cybercats," which has served as a communication hub for TeamPCP and other cybercrime entities for several months.
Within the Cybercats chat, administrators like "Boxturtle" (@xpl0itrsturtle2) are closely associated with TeamPCP. Boxturtle is a data breach broker active on Breachforums and Darkforums, selling data stolen from recent breaches at major automobile manufacturers such as BMW Group, Audi, Honda, Mercedes-Benz, Volvo, and Toyota, as well as alleged data from Snapchat and SportRadar. Another Cybercats administrator, "SeesawSec," is the alias for the operator of Fulcrumsec, a group that claimed responsibility for data extortion attacks against Novo Nordisk, LexisNexis, and Avnet.

The Cybercats administrator "@pcpcasper" has also used a similar name on X to discuss TeamPCP’s attacks and victims. Messages and shared videos from @pcpcasper on Telegram indicate active participation in the National Socialist Network, a neo-Nazi organization based in Australia. Videos shared by @pcpcasper, reportedly showing his cat, appear to place him in Western Australia. One source close to the investigation confirmed that @pcpcasper was one of the two arrested, a claim supported by @kernelstub’s online posts. The Cybercats member listed as "T," short for the banned Twitter/X profile @pcpcats, is the self-described TeamPCP spokesperson who was arrested. @pcpcats is also from Western Australia. Before his ban, @pcpcats posted infrequently, with other members inquiring about his well-being, often attributing his absences to substance use.
The Cybercats member @pcpcats has utilized multiple aliases on cybercrime forums, including EllisD25/LSD on Darkforums, BulkDMT on Breachstars, and Express on Breachforums. These accounts are linked by shared Tox ID and/or Session ID contact information. BulkDMT was also known as DMT Host, a virtual private server (VPS) hosting service advertised on Darkforums and Breachstars. According to cyber intelligence firm Intel 471, Express registered on Breachforums using the email address [email protected] and posted from four different Internet addresses in South Africa during a two-month period in 2025. On July 30, 2025, Express advertised selling access to 14 gigabytes of data stolen from South Africa’s State Information Technology Agency.

Flashpoint has recorded over a year’s worth of messages from the TeamPCP leader’s Telegram alter ego, Persy_PCP, who claimed to split his life between two countries. Persy_PCP explained, "I have these [files] as well, problem is these are in another country." He later complained, "My whole country is racist and they want people like me dead," possibly referencing white landowners in South Africa. Cyberscoop reported in June that Google traced TeamPCP’s Internet connections to South Africa, suggesting the primary operator was located there during some attacks.
BulkDMT also shared in a group chat that he was recovering from a methamphetamine addiction, stating, "My life is kinda fucked rn [right now], but that’s fine and there isn’t really a point in pouring so much emotional energy into that fact, my parents had money but I unfortunately got really addicted to some things so I don’t get to benefit from that. As long as I continue to survive, stay sober, and move closer towards my goals that’s enough drive and meaning." The identity threat protection company SpyCloud found that [email protected] was used to register an account named ChristmasSnow on Raidforums in 2022, with nearly all access originating from Internet addresses in Perth, Australia.

KrebsOnSecurity analysis of passive DNS records revealed that one of these Perth IP addresses, 211.27.196.111, was used for several years as a private file server by a Perth family named Thomson. Records show persistent hosts at this address between 2022 and 2025, including ithomson.direct.quickconnect.to, kthomson0061.direct.quickconnect.to, and joshuawthomson39.myqnapcloud.com. Searching "joshuathomson39" on the breach tracking service Constella Intelligence identified an account at the freight forwarding company kwe.com created in the name of Joshua Thomson from Perth, Australia. The phone number attached to this account was used to register a Facebook profile for Josh Thomson, indicating his family includes a brother named Ruben, father Ian, and mother Cindy. This Facebook profile also stated that Josh and his family are originally from Pietermaritzburg, South Africa, but currently reside in Cottesloe, Western Australia. DomainTools searches for Ian Thomson in Australia uncovered five domains registered by the same individual, including securecomputing.au, thomson.org.au, and thomsonfamily.net.au. Ian Thomson is a dentist in Cottesloe who graduated from The University of the Witwatersrand in Johannesburg, South Africa.
Constella Intelligence found that [email protected] registered several online accounts, but Josh himself had limited connection to cybercrime forums. His brother, Ruben, however, has maintained a significant presence in these communities since at least 2018. Constella reports that [email protected] frequently reused the password "joshuathomson1," which was also used by a few other accounts, including [email protected] and [email protected]. According to Intel 471, [email protected] was used to register the user Yolosolo17 on the crime forum Altenen in 2018, with that account registered from the Perth address 110.141.230.15. On Altenen, Yolosolo17 advertised free web proxies and the domain rubenthomson.com, which at one point sold steeply discounted iPhones. DomainTools indicates rubenthomson.com was hosted at 110.141.230.15 and registered to [email protected].

SpyCloud reports that 10.141.230.15 was used by the email address [email protected] on Raidforums and [email protected] on Nulled. The same IP was also used by [email protected], [email protected], and [email protected]. SpyCloud links the sheepstealing Gmail address to accounts Sheep420, YoloSolo117, and Yakuza.cc on Raidforums, and to "Sheep Stealing" on Hackforums. Intel 471 states that [email protected] was used to register the account DingoFlour on Breachforums in October 2023 and Sheepx on Altenen.
Epieos reports that [email protected] is linked to an Airbnb account for Ruben, who described himself as a web developer educated at the University of Western Australia and living abroad. He stated, "Hey, I’m Ruben, my friends call me Ellis. I’m a Perth creative who occasionally books rooms when visiting family and for photography." Epieos also found that [email protected] registered an upwork.com profile under the name Ruben, listing his skills as setting up secure server hosting solutions and PHP full-stack web development. The profile reads, "I’m familiar with Linux, working with relational databases (SQL), I also script in Python mainly for writing social media bots."

Epieos further discovered that [email protected] is connected to a Microsoft account for Ruben Thomson and a now-defunct GitHub account called XmasSnow/XmasSnowisBack, which scammed users on forums in 2022 by claiming to sell exclusive exploits for newly released software patches. The same email address registered a Twitter/X account in 2026 called "Gone Fishing," listing its location as South Africa. This Gmail account also left business reviews on Google Maps, all located on the west coast of Australia. Pipl finds a 21-year-old Ruben Thomson in Western Australia with a phone number ending in 979, which Epieos links to a TikTok account under the name Ellis and a PayPal account in the name of Ruben Thomson.
Searches for Ruben Thomson from Cottesloe in Australian government business registries show he has incorporated or served as an official in multiple companies since 2024, including Secure Computing Solutions, Tensor Industries, and OPSEC Express. The name OPSEC Express is ironic, as "OPSEC" (operational security) refers to techniques used to obscure real-life identity online, and using a cybercrime handle in a company name is antithetical to this practice. Ruben Thomson also exhibited a significant opsec failure by registering on HackerOne, a bug bounty program, with the username Deadcatx3, a nickname flagged by multiple security firms as an alias used by TeamPCP.

In early July 2026, KrebsOnSecurity interviewed the TeamPCP leader, referred to as Ellis, via Signal. Ellis claimed he ceased cybercrime activities for TeamPCP in March 2026, prior to the LiteLLM attacks, and that another individual assumed leadership. Ellis stated he had completed sobriety programs a year earlier and was two months sober when he reconnected with malware development associates. "One year ago I needed help monetizing some [GitHub credentials], I was two months sober and needed a distraction and something to keep busy as well as people to speak to," Ellis said. "I had largely disconnected from my old circle, they had become very toxic and I needed to get away from the substances. Previously I had done some mass exploitation campaigns and grew up doing [malware development] and [capture the flag] contests." Ellis claimed to have earned approximately $20,000 for his TeamPCP activities, stating it was never about money or fame. He doubted his experiences would translate to legitimate IT employment, estimating he would need half a decade of further experience. Ellis expressed gratitude for no longer facing financial insecurity and did not show remorse for his cybercrime activities, accepting the potential consequences of arrest. He believed individuals like him needed more help than prison could provide, suggesting that financial resources for education and guidance could have altered his path.
Ellis’s posts on the Cybercats Matrix server indicated ongoing struggles with sobriety. On June 25, he informed @kernelstub of plans to "trip" with his "homie," mentioning ketamine, DMT, and 2cb. Roughly two weeks before his arrest, Ellis told KrebsOnSecurity he was prepared to surrender but needed to tie up loose ends. Less than 24 hours later, he posted an image on Telegram showing a yellowish powdered substance, likely synthetic DMT, alongside vape cartridges.

The two defendants were arrested Wednesday morning, facing a combined 14 cybercrime offenses, and were scheduled to appear in Perth Magistrates Court the same day. Charlie Eriksen, a security researcher at Aikido Security who has closely monitored TeamPCP, described them as a new breed of threat actor mixing motivations of money, disruption, attention, and ideology. Eriksen noted that large language models (LLMs) and artificial intelligence are increasingly enabling threat actors to bypass the knowledge gap required for operational campaigns, allowing them to operate at scale without traditional operational discipline. This can lead to "noisy" actors who make mistakes and leave evidence, taking risks that professional criminals would avoid, potentially making them more dangerous. Eriksen credited TeamPCP’s Shai-Hulud worm with forcing GitHub and other coding platforms to implement new security safeguards, such as a three-day "cooldown" mechanism for Dependabot, which buys time for security tools to detect and remove compromised versions. Eriksen stated that TeamPCP achieved in months what the supply chain security community had struggled to do for years, effectively forcing Microsoft to address its security negligence.
Update, 10:08 a.m. ET: ABC News in Australia confirmed that Ruben Ian Thomson of Cottesloe, aged 23, was one of the two arrested, identified as the suspect thought to be @pcpcasper, Michael Gaebler. Thomson was denied bail, and Gaebler’s attorney did not request bail for his client. Both men will remain in custody until their next court appearance on September 18.

