Australian Federal Police (AFP) have apprehended two men, aged 21 and 23, in Western Australia, who are believed to be members of the notorious cybercrime and data extortion group, TeamPCP. This group is implicated in an unprecedented spree of software supply chain attacks, reportedly the longest-running of its kind. The arrests are linked to a sophisticated operation that allegedly created malicious open-source software, defrauding thousands of businesses globally. While the AFP has not officially named the defendants, KrebsOnSecurity has identified the 21-year-old suspect and has been in communication with him. This report includes insights from TeamPCP’s self-proclaimed spokesperson and details the investigative breadcrumbs that may have led to the suspects’ capture.

TeamPCP emerged in late 2025, rapidly gaining notoriety for embedding malicious code into numerous open-source software tools, which they then leveraged for profit through data extortion. The group achieved significant attention by compromising corporate cloud environments using a self-propagating worm named "Shai-Hulud." This worm injected malicious code into open-source programs maintained by developers whose credentials at public code repositories like GitHub or NPM had been compromised through phishing or theft.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Journalist Andy Greenberg, writing for Wired, described TeamPCP’s modus operandi as a cyclical exploitation of software developers. The hackers gain access to a network where a widely used open-source tool is being developed. They then plant malware within the tool, which subsequently lands on the machines of other software developers, including those creating other coding tools. This malware enables TeamPCP hackers to steal credentials, allowing them to publish malicious versions of these development tools, perpetuating a cycle that expands their reach across breached networks.

TeamPCP also employed a strategy akin to cyclical recruitment. In May, the source code for the third iteration of Shai-Hulud was released online, followed by a TeamPCP-sponsored contest offering $1,000 in virtual currency to participants who could execute the most extensive supply chain operation using the worm’s code. The contest rules stipulated that participants would be scored based on the weekly and monthly download numbers of the packages they compromised, directly incentivizing them to target the most popular code libraries. According to the security firm Dataminr, TeamPCP explicitly stated the competition was a recruitment opportunity, with the intention of purchasing all meaningful access harvested from participants’ campaigns. The $1,000 Monero (XMR) prize was characterized as a "recruitment floor," with participants assured of significantly higher payouts for valuable discoveries, underscoring the contest’s dual purpose of talent identification and large-scale malicious access acquisition.

In March, TeamPCP executed a supply chain attack targeting AI infrastructure by compromising the code for LiteLLM, an open-source AI gateway that interfaces with over 100 large language models. A recent analysis by CloudSEK revealed that TeamPCP’s attack on LiteLLM harvested cloud service keys and other sensitive information from more than 2,500 organizations, including many leading global technology companies. In May, TeamPCP claimed responsibility for compromising at least 3,800 code repositories on Microsoft-owned GitHub, following a GitHub developer’s installation of a compromised code extension.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Security experts characterize TeamPCP not as a singular hacker group, but rather as an amalgamation of threat actors from various cybercriminal gangs who collaborate on shared objectives. Austin Larsen, a principal threat analyst with the Google Threat Intelligence Group, stated that TeamPCP is not a structured criminal crew with a single operator but a "peer community of individually-skilled actors, with one clear center of gravity."

This central figure is identified as George Prepakis, an accomplished security researcher and exploit developer operating under the Twitter/X handle @kernelstub. Prepakis created a Matrix chat server named "Cybercats," which has served as a daily communication hub for TeamPCP and several other cybercrime entities for several months. Within the Cybercats chat, administrators, including Prepakis, frequently referenced other members and ongoing discussions on their respective X accounts. Notably, some Cybercats members publicly taunted potential victims before incidents were reported in the media.

One prominent Cybercats administrator, "Boxturtle" (real name not disclosed), operating under the handle @xpl0itrsturtle2, is a close associate of TeamPCP. This individual is identified as a data breach broker active on Breachforums and Darkforums, selling data stolen from recent breaches at major automobile manufacturers like BMW Group, Audi, Honda, Mercedes-Benz, Volvo, and Toyota, as well as alleged data from Snapchat and SportRadar. Another Cybercats administrator, "SeesawSec," is the alias for the individual behind the cybercrime group Fulcrumsec, which has claimed responsibility for data extortion attacks against Novo Nordisk, LexisNexis, and Avnet.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

The Cybercats administrator "@pcpcasper" has also used a similar name on X to discuss TeamPCP’s attacks and victims. Investigations into this individual’s Telegram messages and shared videos indicate active participation in the National Socialist Network, a neo-Nazi political organization based in Australia. Videos and images shared by @pcpcasper, purportedly of their cat, have placed this user in Western Australia. A source close to the investigation confirmed that @pcpcasper was one of the two individuals arrested, a claim supported by @kernelstub’s recent online posts.

The Cybercats member roster also includes an administrator identified as "T," short for the now-banned Twitter/X profile @pcpcats, who is identified as the self-proclaimed TeamPCP spokesperson and was arrested today. T/@pcpcats is also from Western Australia. While @kernelstub tweeted an invitation to the Cybercats Matrix server, T/@pcpcats was posting infrequently, with other members expressing concern about his well-being. These absences were reportedly attributed to drug use, including hallucinogens, which caused prolonged periods of wakefulness followed by extended periods of sleep.

The Cybercats member @pcpcats has utilized multiple aliases on cybercrime forums, including EllisD25/LSD on Darkforums, BulkDMT on Breachstars, and Express on Breachforums. These identities are linked by shared Tox ID and/or Session ID instant messaging handles. BulkDMT was also known as DMT Host, a virtual private server (VPS) hosting service advertised on Darkforums and Breachstars. According to cyber intelligence firm Intel 471, Express registered on Breachforums using the email address [email protected] and posted from four different Internet addresses located in South Africa during a two-month period in 2025. On July 30, 2025, Express announced on Breachforums the sale of 14 gigabytes of data stolen from South Africa’s State Information Technology Agency.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

The threat intelligence platform Flashpoint recorded over a year’s worth of messages from the TeamPCP leader’s Telegram alter ego, Persy_PCP, who claimed to split his time between two countries. Persy_PCP explained that certain data files were located in another country and, in November 2025, complained about pervasive racism in his country, stating that "My whole country is racist and they want people like me dead," potentially referencing white landowners in South Africa who claim to be targets of a genocide campaign. This aligns with public reporting by Cyberscoop, which stated that Google traced TeamPCP’s residential and mobile internet address connections to South Africa, suggesting the primary operator was located there during some of their attacks.

BulkDMT also shared in a group chat on Breachforums about recovering from a methamphetamine addiction, expressing that his life was "kinda fucked rn" but focused on survival, sobriety, and achieving his goals. The breach tracking service SpyCloud notes that [email protected] is associated with the registration of an account named ChristmasSnow on the cybercrime community Raidforums in 2022. Almost all the internet addresses used to access this account originated from ISPs in Perth, Australia.

KrebsOnSecurity examined passive DNS records from DomainTools.com for these Perth IP addresses, revealing that one IP address, 211.27.196.111, was used for several years as a private file server by a Perth family with the surname Thomson. Records indicate that at least three hosts—ithomson.direct.quickconnect.to, kthomson0061.direct.quickconnect.to, and joshuawthomson39.myqnapcloud.com—persisted at this address between 2022 and 2025.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

A search for "joshuathomson39" on the breach tracking service Constella Intelligence uncovered an account at the freight forwarding company kwe.com registered in the name of Joshua Thomson from Perth, Australia. The open-source intelligence platform Epieos found that the phone number linked to this kwe.com account was used to register a Facebook profile for Josh Thomson, which lists his family members as brother Ruben, father Ian, and mother Cindy. This Facebook profile also indicates that Josh and his family are originally from Pietermaritzburg, South Africa, but currently reside in Cottesloe, Western Australia.

A DomainTools search for Ian Thomson and Australia revealed five domains registered by the same individual, including securecomputing.au, thomson.org.au, and thomsonfamily.net.au. Ian Thomson is a dentist in Cottesloe who graduated from the University of the Witwatersrand in Johannesburg, South Africa. Constella found that [email protected] registered several online accounts, but Josh appears to have limited involvement in cybercrime forums. His brother, Ruben, however, has a significant presence in these communities dating back to at least 2018. Constella reports that [email protected] frequently reused the password "joshuathomson1," which was also used by a few other accounts, including [email protected] and [email protected].

Intel 471 states that [email protected] was used to register the user Yolosolo17 on the crime forum Altenen in 2018, with that user account registered from the Perth address 110.141.230.15. On Altenen, Yolosolo17 advertised free web proxies and the domain rubenthomson.com, which was at one point used to sell steeply discounted iPhones. DomainTools indicates that rubenthomson.com was hosted at 110.141.230.15 and registered to [email protected].

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

SpyCloud reports that 10.141.230.15 was used by the email address [email protected] on Raidforums and [email protected] on Nulled. The same IP address was also used by [email protected], [email protected], and [email protected]. SpyCloud also shows that the sheepstealing Gmail address is linked to accounts Sheep420, YoloSolo117, and Yakuza.cc on Raidforums, and to the account "Sheep Stealing" on Hackforums. Intel 471 indicates that [email protected] was used to register the account DingoFlour on Breachforums in October 2023, as well as Sheepx on Altenen.

Epieos reports that [email protected] is linked to an Airbnb account for Ruben, who described himself as a web developer who attended the University of Western Australia and was living abroad. Ruben’s Upwork profile highlights skills in setting up secure server hosting solutions and PHP full-stack web development, including Linux, relational databases (SQL), and Python scripting for social media bots. Epieos further discovered that [email protected] is connected to a Microsoft account for Ruben Thomson and a defunct GitHub account called XmasSnow/XmasSnowisBack, which scammed users on forums in 2022 by claiming to sell exclusive exploits for newly released software patches (recalling that [email protected] was used to register the forum account ChristmasSnow).

This same sheepstealing email address registered a Twitter/X account in 2026 called "Gone Fishing," listing its location as South Africa. The Gmail account has also left numerous reviews for businesses on Google Maps across Western Australia over the past seven years. Pipl finds a 21-year-old Ruben Thomson in Western Australia with a phone number ending in 979. A lookup of this number at Epieos reveals it is connected to a TikTok account under the name Ellis and a PayPal account in the name of Ruben Thomson.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Finally, a search for Ruben Thomson from Cottesloe in Australia’s record of registered businesses shows he has incorporated or served as an official in multiple companies created since 2024, including Secure Computing Solutions, Tensor Industries, and OPSEC Express. OPSEC is an acronym for "operational security," a practice of obscuring one’s real-life identity online, making the naming of a company "OPSEC Express" particularly ironic, given that "Express" was BulkDMT’s nickname on Breachforums.

There is at least one other significant operational security failure by Ruben that links him to TeamPCP. In June 2025, someone using the name Ruben Thomson registered on HackerOne, a bug bounty program. Ruben Thomson’s chosen HackerOne username was "Deadcatx3," a nickname identified by multiple security firms as an alias used by TeamPCP.

In early July 2026, KrebsOnSecurity interviewed the TeamPCP leader, identified as Ellis, via Signal. Ellis claimed he ceased his cybercrime activities for TeamPCP in March 2026, prior to the LiteLLM compromise, and that another individual has since assumed leadership. He stated that a year prior, after completing a series of detox and sobriety programs, he was two months sober when he reconnected with friends from the malware development scene. Ellis explained that he initially needed help monetizing GitHub credentials and sought a distraction and social interaction, having disconnected from a toxic circle. He acknowledged a history of mass exploitation campaigns and malware development contests, and that a friend introduced him to chats where he posted access for sale. Prior to this, Ellis reported being homeless and residing in "very unstable places." He described blackhatting as "fun" with "actual rewards and incentives to learn" and noted that without qualifications, legitimate employers would not consider him. Ellis estimates he earned approximately $20,000 from his TeamPCP activities, asserting that his motivations were not money or fame. He doubted his skills were sufficient for a legitimate IT job without significant further experience, stating he was grateful to no longer face the choice between rent and food. Ellis expressed no remorse for his cybercrime activities, valuing the friendships and relationships formed within TeamPCP. He appeared resigned to potential arrest, stating, "If I’ve already been found out then its out of my control, I’ll make peace with that." He also suggested that individuals like him require more help than prison can offer, lamenting that access to study and guidance could have led to a different outcome.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Ellis’s posts on the Cybercats Matrix server indicate ongoing struggles with sobriety. On June 25, he informed @kernelstub about planning to "trip" with a "homie," specifying ketamine and DMT, with the possibility of adding 2C-B. Approximately two weeks before his arrest, Ellis told KrebsOnSecurity he was ready to cease his criminal activities and turn himself in, but was still tying up loose ends. Less than 24 hours later, he posted an image on Telegram showing a yellowish powdered substance and vape cartridges, likely representing synthetic DMT.

The two defendants were arrested on Wednesday morning and face a combined 14 cybercrime offenses. They are scheduled to appear in Perth Magistrates Court today. Charlie Eriksen, a security researcher at Aikido Security who has closely monitored TeamPCP’s campaigns, described them as a new breed of threat actor that defies traditional categorization, mixing motivations of money, disruption, attention, and ideology. Eriksen noted that large language models (LLMs) and artificial intelligence are increasingly bridging the knowledge gap for threat actors, enabling them to operate at scale without the traditional operational discipline. This allows for "noisy" and risk-taking behavior, potentially making them more dangerous.

Eriksen credited TeamPCP’s Shai-Hulud worm as a catalyst for improved supply chain security, forcing platforms like GitHub to implement new safeguards. In response to TeamPCP’s success in distributing poisoned software packages, GitHub introduced a three-day "cooldown" mechanism for Dependabot, its automated update tool, to allow time for security checks. Other coding ecosystems have also adopted cooldown periods. Eriksen concluded that TeamPCP achieved in months what the supply chain security community had struggled with for years, specifically by "humiliating Microsoft into action" and compelling them to address long-standing security concerns.