{"id":4382,"date":"2026-08-27T11:04:00","date_gmt":"2026-08-27T11:04:00","guid":{"rendered":"https:\/\/futurenews24.com\/index.php\/2026\/08\/27\/two-alleged-teampcp-hackers-arrested-in-australia\/"},"modified":"2026-08-29T02:59:18","modified_gmt":"2026-08-29T02:59:18","slug":"two-alleged-teampcp-hackers-arrested-in-australia","status":"publish","type":"post","link":"https:\/\/futurenews24.com\/index.php\/2026\/08\/27\/two-alleged-teampcp-hackers-arrested-in-australia\/","title":{"rendered":"Two Alleged \u2018TeamPCP\u2019 Hackers Arrested in Australia \u2013 Krebs on Safety"},"content":{"rendered":"<p><br \/>\n<\/p>\n<div>\n<p>Authorities in Australia have arrested two males believed to be members of TeamPCP, a prolific cybercrime and knowledge extortion group blamed for perpetrating the longest operating spree of software program provide chain assaults ever.<\/p>\n<p>In a press release launched at this time, the Australian Federal Police (AFP) mentioned two males from Western Australia, aged 21 and 23, had been arrested in reference to a \u201crefined cybercrime syndicate that allegedly created malicious open-source software program to rob hundreds of world companies.\u201d<\/p>\n<p>The AFP didn&#8217;t identify the defendants, however KrebsOnSecurity discovered the 21-year-old suspect\u2019s actual id in June, and has been speaking with him ever since. This story contains interviews with TeamPCP\u2019s self-described spokesperson, and examines clues left behind by the TeamPCP chief that possible led to his undoing.<\/p>\n<p>TeamPCP vaulted onto the cybercrime scene in late 2025, embedding malicious code in lots of of open supply software program instruments and extorting victims for revenue. Members of the group made headlines by compromising company cloud environments utilizing a self-propagating worm dubbed\u00a0Shai-Hulud, which added malicious code to open supply applications maintained by builders whose credentials at public code repositories like GitHub or NPM had been phished or stolen.<\/p>\n<p>Writing for Wired, journalist Andy Greenberg described TeamPCP\u2019s core tactic as a type of cyclical exploitation of software program builders.<\/p>\n<p>\u201cThe hackers achieve entry to a community the place an open supply software generally utilized by coders is being developed,\u201d Greenberg wrote in Could. \u201cThe hackers plant malware within the software that finally ends up on different software program builders\u2019 machines, together with some who&#8217;re writing different instruments supposed for use by coders. The malware permits TeamPCP\u2019s hackers to steal credentials that allow them publish malicious variations of these software program growth instruments, too. The cycle repeats, and TeamPCP\u2019s assortment of breached networks grows.\u201d<\/p>\n<p>TeamPCP additionally has practiced one thing akin to cyclical recruitment. In Could, the supply code for the third iteration of Shai-Hulud was revealed on-line, and TeamPCP quickly after launched a contest providing $1,000 in digital forex to whichever participant might conduct the most important provide chain operation utilizing the worm\u2019s code. In line with the competition guidelines, individuals had been scored primarily based on the variety of weekly and month-to-month downloads of packages they compromised \u2014 instantly incentivizing them to focus on the preferred code libraries.<\/p>\n<div id=\"attachment_74036\" style=\"width: 700px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-74036\" decoding=\"async\" class=\"size-full wp-image-74036\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/teampcp-shai-hulud.png\" alt=\"\" width=\"690\" height=\"581\"\/><\/p>\n<p id=\"caption-attachment-74036\" class=\"wp-caption-text\">A screenshot of a message from TeamPCP\u2019s Telegram account, saying the provision chain hacking contest. Picture: dataminr.com.<\/p>\n<\/div>\n<p>\u201cTeamPCP has said the competitors is a recruiting alternative they usually intend to buy all significant entry harvested from individuals\u2019 campaigns,\u201d the safety agency Dataminr wrote. \u201cThe $1,000 XMR (Monero) prize is a recruitment ground and has been dismissed by the actor as \u2018identical to participation trophy,\u2019 including \u2018when you discover one thing good you can be paid far more,\u2019 confirming the competition\u2019s true perform as expertise identification and malicious entry acquisition at scale.\u201d<\/p>\n<p>In March, TeamPCP executed a provide chain assault focusing on AI infrastructure by compromising the code for LiteLLM, an open supply AI gateway that connects customers to greater than 100 totally different massive language fashions. A current evaluation by the safety agency CloudSEK discovered TeamPCPs assault on LiteLLM harvested cloud service keys and different secrets and techniques from greater than 2,500 organizations, together with most of the world\u2019s prime expertise firms.<\/p>\n<p>In Could, TeamPCP claimed credit score for compromising not less than 3,800 code repositories on the Microsoft-owned GitHub, after a GitHub developer put in a code extension that was compromised by TeamPCP\u2019s malware.<\/p>\n<h2>MEET THE CYBERCATS<\/h2>\n<p>Safety consultants say TeamPCP is much less of a hacker group than an amalgamation of menace actors from a number of cybercriminal gangs who generally work collectively towards comparable targets.<\/p>\n<p>\u201cIt&#8217;s not a structured felony crew with a single operator,\u201d mentioned Austin Larsen, a principal menace analyst with the Google Risk Intelligence Group. \u201cIt&#8217;s a peer neighborhood of individually-skilled actors, with one clear middle of gravity.\u201d<\/p>\n<p>That middle of gravity is George Prepakis, an achieved safety researcher and self-described exploit developer who operates the Twitter\/X profile @kernelstub. Earlier this yr, @kernelstub tweeted a public invite hyperlink to a Matrix chat server he created and dubbed \u201cCybercats,\u201d and TeamPCP and a number of other different cybercrime entities have been utilizing this server to speak every day for the previous a number of months.<\/p>\n<div id=\"attachment_74165\" style=\"width: 758px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-74165\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-74165\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/matrix-tpcp-xpl0itrs.png\" alt=\"\" width=\"748\" height=\"590\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/matrix-tpcp-xpl0itrs.png 1018w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/matrix-tpcp-xpl0itrs-768x606.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/matrix-tpcp-xpl0itrs-782x617.png 782w\" sizes=\"auto, (max-width: 748px) 100vw, 748px\"\/><\/p>\n<p id=\"caption-attachment-74165\" class=\"wp-caption-text\">A screenshot of the Matrix chat server \u201cCybercats,\u201d whose members used hacker handles related to a number of distinct cybercrime teams which have sometimes collaborated on a sequence of provide chain and knowledge ransom assaults over the previous 9 months.<\/p>\n<\/div>\n<p>Kernelstub, like different directors within the Cybercats chat, has been utilizing his Twitter\/X profile identify as his deal with in these Matrix communications, continuously tweeting references to different members and to conversations going down within the Cybercats chat. In a lot of instances, the corresponding X accounts for members of the Cybercats chat taunted cybercrime victims publicly earlier than the incidents had been reported within the information media.<\/p>\n<p>The Cybercats administrator listed on the prime of the screenshot above \u2014 \u201cBoxturtle\u201d \u2014 is an in depth affiliate of TeamPCP who has been tweeting in regards to the group\u2019s conquests underneath the identify @xpl0itrsturtle. This deal with corresponds to a knowledge breach dealer lively on Breachforums and Darkforums who has been promoting knowledge stolen in a wave of current breaches at car producers, together with BMW Group, Audi, Honda, Mercedes-Benz, Volvo and Toyota, in addition to knowledge allegedly taken from Snapchat and SportRadar.<\/p>\n<div id=\"attachment_74174\" style=\"width: 760px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-74174\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-74174\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/xpl0itrs-dls.png\" alt=\"\" width=\"750\" height=\"525\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/xpl0itrs-dls.png 1119w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/xpl0itrs-dls-768x538.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/xpl0itrs-dls-782x548.png 782w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/xpl0itrs-dls-100x70.png 100w\" sizes=\"auto, (max-width: 750px) 100vw, 750px\"\/><\/p>\n<p id=\"caption-attachment-74174\" class=\"wp-caption-text\">The information leak web site for the extortion group or deal with \u201cxpl0itrs.\u201d<\/p>\n<\/div>\n<p>The Cybercats administrator \u201cSeesawSec\u201d within the screenshot above is the alias of whoever is behind the cybercrime group generally known as Fulcrumsec, which lately claimed credit score for knowledge extortion assaults in opposition to the pharmaceutical big Novo Nordisk, the info dealer LexisNexis, and Avnet, a Fortune 500 distributor of digital parts.<\/p>\n<div id=\"attachment_74175\" style=\"width: 686px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-74175\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-74175\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/fulcrumsec-dls.png\" alt=\"\" width=\"676\" height=\"858\"\/><\/p>\n<p id=\"caption-attachment-74175\" class=\"wp-caption-text\">The information leak web site of Fulcrum Safety, a.okay.a. Fulcrumsec.<\/p>\n<\/div>\n<p>The Cybercats administrator \u201c@pcpcasper\u201d additionally has been utilizing an identical identify on X to debate TeamPCP\u2019s assaults and victims. This particular person has an intensive message historical past on Telegram, the place their messages and shared movies present @pcpcasper is an lively and vocal member of the Nationwide Socialist Community, a neo-Nazi political group primarily based in Australia.<\/p>\n<p>At one level in these chats, @pcpcasper shared movies and pictures of what they claimed was their cat, and a number of other of these movies place this consumer in Western Australia. One supply near the investigation instructed KrebsOnSecurity that @pcpcasper was one of many two arrested, a declare supported by messages that @kernelstub posted on-line this morning.<\/p>\n<p>The Cybercats member roster pictured above additionally options an administrator with the username \u201cT,\u201d which is brief for the now-banned Twitter\/X profile @pcpcats, the account operated by the self-described TeamPCP spokesperson who was arrested at this time. As we\u2019ll see in a second, @pcpcats is also from Western Australia.<\/p>\n<p>By the point @kernelstub tweeted a public invite hyperlink to the Cybercats Matrix server, T\/@pcpcats was posting solely occasionally to the group chat, with different members usually inquiring as to his whereabouts and well-being. The group\u2019s collective concern associated to @pcpcats\u2019s tendency responsible his more and more prolonged absences on the usage of hallucinogens and different narcotics that saved him awake for days on finish, but additionally triggered him to crash in mattress for a number of days after the highs wore off.<span id=\"more-73635\"\/><\/p>\n<h2>WHO IS THE TEAMPCP LEADER?<\/h2>\n<p>The Cybercats member @pcpcats has used a number of nicknames on the cybercrime boards, together with EllisD25\/LSD on Darkforums, BulkDMT on Breachstars, and Categorical on Breachforums. These accounts are linked as a result of all of them marketed the identical Tox ID and\/or Session ID as instantaneous message contact handles of their cybercrime discussion board posts. BulkDMT was additionally recognized on the boards as DMT Host, which was a digital non-public server (VPS) internet hosting service that was peddled on Darkforums and Breachstars.<\/p>\n<div id=\"attachment_74040\" style=\"width: 760px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-74040\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-74040\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/dmthost.png\" alt=\"\" width=\"750\" height=\"356\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/dmthost.png 950w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/dmthost-768x365.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/dmthost-782x371.png 782w\" sizes=\"auto, (max-width: 750px) 100vw, 750px\"\/><\/p>\n<p id=\"caption-attachment-74040\" class=\"wp-caption-text\">DMT Host\/EllisD25, posting on the English-language cybercrime neighborhood DarkForums in September 2025. Picture: ke-la.com.<\/p>\n<\/div>\n<p>In line with the cyber intelligence agency Intel 471, Categorical registered on Breachforums utilizing the e-mail handle shitstickpp@gmail.com. Intel 471 finds Categorical posted on Breachforums throughout a two-month interval in 2025 utilizing 4 totally different Web addresses situated in South Africa. On July 30, 2025, Categorical introduced on Breachforums they had been promoting entry to 14 gigabytes of knowledge stolen from South Africa\u2019s State Info Know-how Company.<\/p>\n<p>The menace intelligence platform Flashpoint recorded greater than a yr\u2019s value of messages from the TeamPCP chief\u2019s alter ego on Telegram \u2014 Persy_PCP \u2014 \u00a0who claimed they break up their life residing between two international locations [full disclosure: Flashpoint is an advertiser on this blog]. \u201cI&#8217;ve these [files] as nicely, downside is these are out of the country,\u201d Persy_PCP defined to a different consumer inquiring a few stolen knowledge set in November 2025.<\/p>\n<p>Later that month, Persy_PCP complained, \u201cMy entire nation is racist they usually need individuals like me lifeless.\u201d Flashpoint information present BulkDMT shared in September 2025 that \u201cthis nation goes to fucking starve once they take the farmers land,\u201d a probable reference to white landowners in South Africa who declare to be focused by an ongoing genocide marketing campaign.<\/p>\n<p>This tracks with public reporting on TeamPCP. Cyberscoop reported in June that Google had traced TeamPCP\u2019s residential and cell Web handle connections to South Africa, \u201cindicating the first operator was situated there throughout not less than a few of its assaults.\u201d<\/p>\n<p>BulkDMT additionally shared on the group chat at Breachforums that they had been recovering from an habit to methamphetamine. \u201cMy life is kinda fucked rn [right now], however that\u2019s positive and there isn\u2019t actually a degree in pouring a lot emotional vitality into that truth, my dad and mom had cash however I sadly obtained actually hooked on some issues so I don\u2019t get to learn from that. So long as I proceed to outlive, keep sober, and transfer nearer in direction of my targets that\u2019s sufficient drive and that means.\u201d<\/p>\n<p>The id menace safety firm SpyCloud finds shitstickpp@gmail.com reveals up within the registration of an account known as ChristmasSnow on the cybercrime neighborhood Raidforums in 2022. Practically the entire Web addresses used to entry that account got here from ISPs in Perth, Australia, SpyCloud discovered.<\/p>\n<p>KrebsOnSecurity appeared up all of these Perth IP addresses in passive DNS information maintained by DomainTools.com, and located one in all them \u2014 211.27.196.111 \u2014 for a number of years was used as a personal file server by a household in Perth with the final identify of Thomson. These information present not less than three hosts \u2014 ithomson.direct.quickconnect.to (a distant Synology server), kthomson0061.direct.quickconnect.to, and joshuawthomson39.myqnapcloud.com (a QNAP community storage gadget) \u2014 persevered at that handle between 2022 and 2025.<\/p>\n<p>Looking out on \u201cjoshuathomson39\u201d within the breach monitoring service Constella Intelligence reveals an account on the freight forwarding firm kwe.com created within the identify of Joshua Thomson from Perth, Australia. The open supply intelligence platform Epieos finds the cellphone quantity hooked up to that kwe.com account was used to register a Fb profile for Josh Thomson, which says his household features a brother named Ruben, his father Ian, and his mother Cindy.<\/p>\n<p>That Fb profile additionally says Josh and his household are initially from Pietermaritzburg, in KwaZulu-Natal, South Africa, however at the moment residing in Cottesloe, a beach-side suburb of Perth. A search in DomainTools for Ian Thomson and Australia unearthed 5 domains by the identical registrant, together with securecomputing.au, thomson.org.au, and thomsonfamily.web.au. Ian Thomson is a dentist in Cottesloe, and a biography says he graduated from The College of the Witwatersrand in Johannesburg, South Africa.<\/p>\n<p>Constella finds a joshua@thomson.org.au registered a lot of accounts on-line, however Josh doesn\u2019t appear to have a lot of a connection to dodgy cybercrime boards. His brother Ruben, however, has fairly the presence on these communities, relationship again to not less than 2018. Constella experiences ruben@thomson.org.au continuously reused the password \u201cjoshuathomson1,\u201d and Constella additional finds that password was utilized by only a handful of accounts, together with yolosolo17@gmail.com and surfinup8@gmail.com.<\/p>\n<p>In line with Intel 471, surfinup8@gmail.com was used to register the consumer Yolosolo17 on the crime discussion board Altenen in 2018, and that consumer account was registered from the Perth handle 110.141.230.15. On Altenen, Yolosolo17 marketed free net proxies, in addition to the area rubenthomson.com, which was at one level used to promote steeply discounted iPhones. DomainTools says rubenthomson.com was hosted at 110.141.230.15 and registered to surfinup8@gmail.com.<\/p>\n<div id=\"attachment_73723\" style=\"width: 758px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-73723\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-73723\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/05\/rubenthomsondotcom.png\" alt=\"\" width=\"748\" height=\"483\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/05\/rubenthomsondotcom.png 1146w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/05\/rubenthomsondotcom-768x496.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/05\/rubenthomsondotcom-782x505.png 782w\" sizes=\"auto, (max-width: 748px) 100vw, 748px\"\/><\/p>\n<p id=\"caption-attachment-73723\" class=\"wp-caption-text\">A cached copy of the area rubenthomson.com from 2017 reveals a login web page beneath a banded stack of cash. Picture: archive.org.<\/p>\n<\/div>\n<p>SpyCloud experiences 10.141.230.15 was utilized by the e-mail handle sheepstealing@gmail.com on Raidforums and surfinup8@gmail.com on Nulled, and that the identical IP was utilized by the e-mail addresses ian@thomsonfamily.web.au, jasper@yakuza.cc, and rubenthomson1@gmail.com. SpyCloud additionally reveals that sheepstealing Gmail handle is tied to the accounts Sheep420, YoloSolo117 and Yakuza.cc on Raidforums, and to the account \u201cSheep Stealing\u201d on Hackforums. Intel 471 says sheepstealing@gmail.com was used to register the account DingoFlour on Breachforums in October 2023, as nicely Sheepx on Altenen.<\/p>\n<p>Epieos experiences that ruben@securecomputing.au is tied to an Airbnb account for Ruben, who described himself as a Net developer who went to highschool on the College of Western Australia and was residing exterior the nation. \u201cHey, I\u2019m Ruben, my associates name me Ellis. I\u2019m a Perth inventive who sometimes books rooms when visiting household and for images.\u201d<\/p>\n<p>Epieos additionally finds sheepstealing@gmail.com registered an upwork.com profile underneath the identify Ruben, who mentioned his major abilities are establishing safe server internet hosting options and PHP full-stack Net growth.<\/p>\n<p>\u201cI\u2019m accustomed to Linux, working with relational databases (SQL),\u201d the Upwork profile reads. \u201cI additionally script in Python primarily for writing social media bots.\u201d<\/p>\n<div id=\"attachment_74038\" style=\"width: 760px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-74038\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-74038\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/upwork-thomson.png\" alt=\"\" width=\"750\" height=\"397\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/upwork-thomson.png 1419w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/upwork-thomson-768x406.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/upwork-thomson-782x414.png 782w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/upwork-thomson-267x140.png 267w\" sizes=\"auto, (max-width: 750px) 100vw, 750px\"\/><\/p>\n<p id=\"caption-attachment-74038\" class=\"wp-caption-text\">The Upwork profile for Ruben Thomson in Cottesloe, Australia.<\/p>\n<\/div>\n<p>Epieos additional found sheepstealing@gmail.com is linked to a Microsoft account for Ruben Thomson, and to a now-defunct GitHub account known as XmasSnow\/XmasSnowisBack that scammed individuals on the boards in 2022 by claiming to promote unique exploits for recently-released software program patches (recall that shitstickpp@gmail.com was used to register a discussion board account named ChristmasSnow).<\/p>\n<p>This similar sheepstealing e-mail handle registered a Twitter\/X account in 2026 known as \u201cGone Fishing\u201d that lists its location as South Africa. That Gmail account additionally left a number of evaluations for companies listed on Google Maps over the previous seven years, however all of these institutions are situated on the west coast of Australia.<\/p>\n<div id=\"attachment_74037\" style=\"width: 760px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-74037\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-74037\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/gonefishing.png\" alt=\"\" width=\"750\" height=\"547\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/gonefishing.png 1306w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/gonefishing-768x560.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/gonefishing-782x571.png 782w\" sizes=\"auto, (max-width: 750px) 100vw, 750px\"\/><\/p>\n<p id=\"caption-attachment-74037\" class=\"wp-caption-text\">Enterprise evaluations in Western Australia left by the Google account sheepstealing at gmail.com.<\/p>\n<\/div>\n<p>The individuals search service Pipl finds a 21-year-old Ruben Thomson in Western Australia who has a cellphone quantity ending in 979. A lookup on that quantity at Epieos reveals it&#8217;s linked to a TikTok account underneath the identify Ellis, and to a PayPal account within the identify of Ruben Thomson.<\/p>\n<p>Lastly, a search on the identify Ruben Thomson from Cottesloe on the Australian authorities\u2019s report of registered companies finds he has included or served as an official in a number of firms created since 2024, together with Safe Computing Options, Tensor Industries, and one other entity mockingly named OPSEC Categorical. Recall that Categorical was BulkDMT\u2019s nickname on Breachforums.<\/p>\n<div id=\"attachment_74206\" style=\"width: 760px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-74206\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-74206\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/rthomson-companies.png\" alt=\"\" width=\"750\" height=\"449\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/rthomson-companies.png 1333w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/rthomson-companies-768x460.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/rthomson-companies-782x468.png 782w\" sizes=\"auto, (max-width: 750px) 100vw, 750px\"\/><\/p>\n<p id=\"caption-attachment-74206\" class=\"wp-caption-text\">Australian firms linked to Ruben Thomson. Picture: abr.enterprise.gov.au.<\/p>\n<\/div>\n<p>It\u2019s ironic as a result of OPSEC is brief for the time period \u201coperational safety,\u201d which refers to strategies and behaviors used to obfuscate and compartmentalize one\u2019s real-life id on-line, and utilizing your cybercrime deal with as a part of your individual firm identify could be very a lot the antithesis of that observe.<\/p>\n<p>There may be not less than one different main opsec failure by Ruben that uncovered a hyperlink to TeamPCP. In June 2025, somebody utilizing the identify Ruben Thomson registered on HackerOne, a well-liked \u201cbug bounty\u201d program that seeks to reward and acknowledge researchers who conform to work with affected software program distributors to assist repair the failings earlier than publishing about their findings. What was Ruben Thomson\u2019s chosen HackerOne username? Deadcatx3, a nickname that has been flagged by a number of safety companies as an alias utilized by TeamPCP.<\/p>\n<div id=\"attachment_74167\" style=\"width: 756px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-74167\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-74167\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/ruben-deadcatx3.png\" alt=\"\" width=\"746\" height=\"415\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/ruben-deadcatx3.png 1627w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/ruben-deadcatx3-768x427.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/ruben-deadcatx3-1536x854.png 1536w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/ruben-deadcatx3-782x435.png 782w\" sizes=\"auto, (max-width: 746px) 100vw, 746px\"\/><\/p>\n<p id=\"caption-attachment-74167\" class=\"wp-caption-text\">The HackerOne profile for \u201cRuben Thomson\u201d makes use of the nickname Deadcatx3, which a number of safety companies have concluded is an alias utilized by TeamPCP. Picture credit score: flare.io.<\/p>\n<\/div>\n<h2>INTERVIEW WITH ELLIS<\/h2>\n<p>In early July 2026, not lengthy after having found clues about Ellis\u2019s actual life id, KrebsOnSecurity interviewed the TeamPCP chief through Sign, the place he was remarkably open about his actions and private struggles [for the sake of simplicity, the TeamPCP spokesperson will be referred to from here on as Ellis].<\/p>\n<p>Ellis claims he stopped doing cybercrime for TeamPCP in March 2026 \u2014 simply earlier than the assaults that compromised LiteLLM \u2014 and that not less than one different particular person has taken over the group\u2019s management since then. Ellis shared {that a} yr earlier he had simply accomplished the newest in a sequence of detox and sobriety applications, and was two months sober when he reconnected with some previous associates from the malware growth scene.<\/p>\n<p>\u201cOne yr in the past I wanted assist monetizing some [GitHub credentials], I used to be two months sober and wanted a distraction and one thing to maintain busy in addition to individuals to talk to,\u201d Ellis mentioned. \u201cI had largely disconnected from my previous circle, they&#8217;d change into very poisonous and I wanted to get away from the substances. Beforehand I had executed some mass exploitation campaigns and grew up doing [malware development] and [capture the flag] contests. There have been some associates who had been additionally merchandising however had stopped some time, and one in all them launched me to some chats the place I posted entry on the market.\u201d<\/p>\n<p>Previous to that, Ellis mentioned, he was homeless and hopping between \u201csome very unstable locations.\u201d<\/p>\n<p>\u201cBlackhatting is enjoyable,\u201d he mentioned. \u201cThere are precise rewards and incentives to be taught and also you develop along with your crew. With out {qualifications}, no employer will even take the time to listen to you out.\u201d<\/p>\n<p>Ellis claims he\u2019s earned a grand whole of about $20,000 for his actions with TeamPCP, and that it was by no means in regards to the cash or fame for him. Requested whether or not his experiences with TeamPCP may put together him for gainful employment in a respectable IT job, Ellis mentioned he doubted it.<\/p>\n<p>\u201cI&#8217;m nowhere near a ability degree the place I&#8217;m snug, and this is able to take possibly half a decade of additional expertise,\u201d he mentioned. \u201cI not have to decide on between hire and meals for that I\u2019m grateful and so are the crew members.\u201d<\/p>\n<p>Ellis expressed no regret over his cybercrime actions, and mentioned he was grateful for the friendships and relationships constructed all through his engagement with TeamPCP. The younger hacker additionally appeared resigned to his destiny, and instructed KrebsOnSecurity that he\u2019ll settle for the implications if he\u2019s ever arrested.<\/p>\n<p>\u201cIf I\u2019ve already been discovered then its out of my management, I\u2019ll make peace with that,\u201d he mentioned. \u201cActually, I believe somebody like me wants a number of assist that jail simply can\u2019t present. If I had the funds to review totally different elements of the sector and nearer steering, this is able to have turned out in another way. However that\u2019s a pipe dream and we each know this.\u201d<\/p>\n<p>It&#8217;s clear from studying Ellis\u2019s posts to the group\u2019s Matrix server chats that his struggles with sobriety are ongoing. On Thursday, June 25, Ellis instructed @kernelstub he was about to \u201cjourney\u201d along with his \u201chomie.\u201d<\/p>\n<p>\u201cWhat variety,\u201d @kernelstub inquired.<\/p>\n<p>\u201cKetty and a few DMT,\u201d Ellis replied, referring to the dissociative anesthetic ketamine and dimethyltryptamine (DMT), a robust psychedelic compound that&#8217;s discovered naturally in some vegetation however can also be synthetically produced in underground lab environments. \u201cThere\u2019s slightly 2cb so we would throw that within the combine,\u201d he continued, referring to a different psychedelic compound by its chemical shorthand.<\/p>\n<p>Roughly two weeks earlier than his arrest, Ellis instructed KrebsOnSecurity he was prepared to go away his lifetime of crime behind and was ready to show himself in, however that within the meantime he was planning to tie up unfastened ends.<\/p>\n<p>Lower than 24 hours later, the TeamPCP chief posted a picture on Telegram displaying a yellowish powdered substance in a baggie and on a scale, presumably artificial DMT. The picture reveals the powder being weighed subsequent to a sequence of small vape cartridges, two of that are open on the desk in entrance of the photographer.<\/p>\n<div id=\"attachment_74171\" style=\"width: 759px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-74171\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-74171\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/teampcp-dmtmaybe.png\" alt=\"\" width=\"749\" height=\"412\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/teampcp-dmtmaybe.png 1449w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/teampcp-dmtmaybe-768x423.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/teampcp-dmtmaybe-782x431.png 782w\" sizes=\"auto, (max-width: 749px) 100vw, 749px\"\/><\/p>\n<p id=\"caption-attachment-74171\" class=\"wp-caption-text\">A picture posted by the TeamPCP chief to Telegram, promoting his acquisition of some sort of psychoactive substance, most definitely an artificial model of the highly effective hallucinogen generally known as DMT.<\/p>\n<\/div>\n<p>The 2 defendants had been arrested Wednesday morning. The AFP mentioned the lads face a mixed 14 cybercrime offenses and are scheduled to seem in Perth Magistrates Courtroom at this time.<\/p>\n<p>Charlie Eriksen is a safety researcher at Aikido Safety who has carefully adopted TeamPCP\u2019s cybercrime campaigns. Eriksen mentioned TeamPCP are a great instance of a brand new type of menace actor that doesn&#8217;t match neatly into the standard classes.<\/p>\n<p>\u201cThey don&#8217;t seem to be a state actor, not fairly organized cybercrime, and never purely ideological,\u201d he mentioned. \u201cTheir motivations appear to combine cash, disruption, consideration, and beliefs.\u201d<\/p>\n<p>Eriksen mentioned that traditionally there has all the time been a significant hole between studying about an assault method and with the ability to reliably flip it into an operational marketing campaign, however that giant language fashions (LLMs) and synthetic intelligence more and more are serving to menace actors to bypass that data hole.<\/p>\n<p>\u201cYou needed to perceive the analysis, adapt the code, troubleshoot it, construct infrastructure round it, after which repeat that course of throughout totally different targets,\u201d he mentioned. \u201cLLMs have compressed that hole considerably.\u201d<\/p>\n<p>In line with Eriksen, this creates an setting the place menace actors all of a sudden have the flexibility to function at important scale with out having developed the operational self-discipline that historically accompanies that degree of functionality. Put one other manner, it units the stage for cybercriminals who&#8217;re succesful sufficient to trigger important harm, however not essentially cautious sufficient to know or care in regards to the penalties.<\/p>\n<p>\u201cThey are often noisy, they&#8217;ll make errors,\u201d he mentioned. \u201cThey will go away proof in every single place. They will take dangers {that a} skilled felony group or intelligence service would take into account utterly unacceptable. However that doesn&#8217;t essentially make them much less harmful. In some methods, it will probably make them extra harmful.\u201d<\/p>\n<p>In a current weblog put up, Eriksen known as TeamPCP\u2019s Shai-Hulud worm the \u201csmartest thing to occur to provide chain safety,\u201d as a result of it pressured GitHub and different public coding platforms to erect new safety safeguards.<\/p>\n<p>In direct response to TeamPCP\u2019s broad success at pushing poisoned variations of in style software program packages, GitHub in late July launched a three-day \u201ccooldown\u201d mechanism for Dependabot, the platform\u2019s software for auto-fetching newly shipped updates for any bundle dependencies. Cooldown durations are designed to assist purchase time for safety instruments and bundle maintainers to establish and take away any compromised variations. Different coding ecosystems like Python and numerous JavaScript platforms additionally added help for cooldown durations this yr amid rising calls from safety consultants in regards to the want for extra widespread adoption of the security characteristic.<\/p>\n<p>Eriksen mentioned TeamPCP\u2019s legacy is that they achieved within the span of some months what the provision chain safety neighborhood has been unable to do for years.<\/p>\n<p>\u201cThey managed to get up Microsoft to the truth that they&#8217;d change into negligent by way of safety,\u201d Eriksen mentioned. \u201cBy compromising GitHub and stealing their supply code, they humiliated Microsoft into motion, making them lastly act on what we had been asking them to do and take critically for some time now.\u201d<\/p>\n<p>Replace, 10:08 a.m. ET: A narrative this morning from ABC Information in Australia confirms Ruben Ian Thomson of Cottesloe was one of many two arrested. The 23-year-old suspect regarded as @pcpcasper, Michael Gaebler, additionally was arrested in Perth. ABC Information experiences that Thomson was denied bail (Mr. Gaebler\u2019s lawyer reportedly didn&#8217;t request bail for his shopper), and that each males shall be held in custody till their subsequent courtroom look on September 18.<\/p>\n<\/p><\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/krebsonsecurity.com\/2026\/08\/two-alleged-teampcp-hackers-arrested-in-australia\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Authorities in Australia have arrested two males believed to be members of TeamPCP, a prolific cybercrime and knowledge extortion group blamed for perpetrating the longest operating spree of software program provide chain assaults ever. In a press release launched at this time, the Australian Federal Police (AFP) mentioned two males from Western Australia, aged 21 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":4384,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/teampcp-shai-hulud.png","fifu_image_alt":"","jnews-multi-image_gallery":[],"jnews_single_post":[],"jnews_primary_category":[],"jnews_override_bookmark_settings":[],"jnews_social_meta":[],"jnews_override_counter":[],"footnotes":""},"categories":[7],"tags":[1021,1025,3625,162,169,171,4584],"class_list":["post-4382","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-science-mlops","tag-alleged","tag-arrested","tag-australia","tag-hackers","tag-krebs","tag-security","tag-teampcp"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Two Alleged \u2018TeamPCP\u2019 Hackers Arrested in Australia \u2013 Krebs on Safety - Future News 24<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/futurenews24.com\/index.php\/2026\/08\/27\/two-alleged-teampcp-hackers-arrested-in-australia\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Two Alleged \u2018TeamPCP\u2019 Hackers Arrested in Australia \u2013 Krebs on Safety - Future News 24\" \/>\n<meta property=\"og:description\" content=\"Authorities in Australia have arrested two males believed to be members of TeamPCP, a prolific cybercrime and knowledge extortion group blamed for perpetrating the longest operating spree of software program provide chain assaults ever. In a press release launched at this time, the Australian Federal Police (AFP) mentioned two males from Western Australia, aged 21 [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/futurenews24.com\/index.php\/2026\/08\/27\/two-alleged-teampcp-hackers-arrested-in-australia\/\" \/>\n<meta property=\"og:site_name\" content=\"Future News 24\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-27T11:04:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-29T02:59:18+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/teampcp-shai-hulud.png\" \/>\n<meta name=\"author\" content=\"Future News 24\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/teampcp-shai-hulud.png\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Future News 24\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"21 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/futurenews24.com\\\/index.php\\\/2026\\\/08\\\/27\\\/two-alleged-teampcp-hackers-arrested-in-australia\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/futurenews24.com\\\/index.php\\\/2026\\\/08\\\/27\\\/two-alleged-teampcp-hackers-arrested-in-australia\\\/\"},\"author\":{\"name\":\"Future News 24\",\"@id\":\"https:\\\/\\\/futurenews24.com\\\/#\\\/schema\\\/person\\\/cecad1bde21cfc357cf70128144d6c83\"},\"headline\":\"Two Alleged \u2018TeamPCP\u2019 Hackers Arrested in Australia \u2013 Krebs on Safety\",\"datePublished\":\"2026-08-27T11:04:00+00:00\",\"dateModified\":\"2026-08-29T02:59:18+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/futurenews24.com\\\/index.php\\\/2026\\\/08\\\/27\\\/two-alleged-teampcp-hackers-arrested-in-australia\\\/\"},\"wordCount\":4145,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/futurenews24.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/futurenews24.com\\\/index.php\\\/2026\\\/08\\\/27\\\/two-alleged-teampcp-hackers-arrested-in-australia\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/krebsonsecurity.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/teampcp-shai-hulud.png\",\"keywords\":[\"Alleged\",\"Arrested\",\"Australia\",\"Hackers\",\"Krebs\",\"Security\",\"TeamPCP\"],\"articleSection\":[\"Data Science &amp; MLOps\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/futurenews24.com\\\/index.php\\\/2026\\\/08\\\/27\\\/two-alleged-teampcp-hackers-arrested-in-australia\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/futurenews24.com\\\/index.php\\\/2026\\\/08\\\/27\\\/two-alleged-teampcp-hackers-arrested-in-australia\\\/\",\"url\":\"https:\\\/\\\/futurenews24.com\\\/index.php\\\/2026\\\/08\\\/27\\\/two-alleged-teampcp-hackers-arrested-in-australia\\\/\",\"name\":\"Two Alleged \u2018TeamPCP\u2019 Hackers Arrested in Australia \u2013 Krebs on Safety - Future News 24\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/futurenews24.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/futurenews24.com\\\/index.php\\\/2026\\\/08\\\/27\\\/two-alleged-teampcp-hackers-arrested-in-australia\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/futurenews24.com\\\/index.php\\\/2026\\\/08\\\/27\\\/two-alleged-teampcp-hackers-arrested-in-australia\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/krebsonsecurity.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/teampcp-shai-hulud.png\",\"datePublished\":\"2026-08-27T11:04:00+00:00\",\"dateModified\":\"2026-08-29T02:59:18+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/futurenews24.com\\\/index.php\\\/2026\\\/08\\\/27\\\/two-alleged-teampcp-hackers-arrested-in-australia\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/futurenews24.com\\\/index.php\\\/2026\\\/08\\\/27\\\/two-alleged-teampcp-hackers-arrested-in-australia\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/futurenews24.com\\\/index.php\\\/2026\\\/08\\\/27\\\/two-alleged-teampcp-hackers-arrested-in-australia\\\/#primaryimage\",\"url\":\"https:\\\/\\\/krebsonsecurity.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/teampcp-shai-hulud.png\",\"contentUrl\":\"https:\\\/\\\/krebsonsecurity.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/teampcp-shai-hulud.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/futurenews24.com\\\/index.php\\\/2026\\\/08\\\/27\\\/two-alleged-teampcp-hackers-arrested-in-australia\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/futurenews24.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Two Alleged \u2018TeamPCP\u2019 Hackers Arrested in Australia \u2013 Krebs on Safety\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/futurenews24.com\\\/#website\",\"url\":\"https:\\\/\\\/futurenews24.com\\\/\",\"name\":\"Future News 24\",\"description\":\"The Smart Hub for AI and Next-Gen Innovation\",\"publisher\":{\"@id\":\"https:\\\/\\\/futurenews24.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/futurenews24.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/futurenews24.com\\\/#organization\",\"name\":\"Future News 24\",\"url\":\"https:\\\/\\\/futurenews24.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/futurenews24.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/futurenews24.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/fn24-favicon.png\",\"contentUrl\":\"https:\\\/\\\/futurenews24.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/fn24-favicon.png\",\"width\":250,\"height\":250,\"caption\":\"Future News 24\"},\"image\":{\"@id\":\"https:\\\/\\\/futurenews24.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/futurenews24.com\\\/#\\\/schema\\\/person\\\/cecad1bde21cfc357cf70128144d6c83\",\"name\":\"Future News 24\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d57f07142d73cb5503ab2446ea7bc9ef3d0a5ba378d64a6157692311e42bf097?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d57f07142d73cb5503ab2446ea7bc9ef3d0a5ba378d64a6157692311e42bf097?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d57f07142d73cb5503ab2446ea7bc9ef3d0a5ba378d64a6157692311e42bf097?s=96&d=mm&r=g\",\"caption\":\"Future News 24\"},\"sameAs\":[\"https:\\\/\\\/futurenews24.com\"],\"url\":\"https:\\\/\\\/futurenews24.com\\\/index.php\\\/author\\\/mridulpahuja20\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Two Alleged \u2018TeamPCP\u2019 Hackers Arrested in Australia \u2013 Krebs on Safety - Future News 24","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/futurenews24.com\/index.php\/2026\/08\/27\/two-alleged-teampcp-hackers-arrested-in-australia\/","og_locale":"en_US","og_type":"article","og_title":"Two Alleged \u2018TeamPCP\u2019 Hackers Arrested in Australia \u2013 Krebs on Safety - Future News 24","og_description":"Authorities in Australia have arrested two males believed to be members of TeamPCP, a prolific cybercrime and knowledge extortion group blamed for perpetrating the longest operating spree of software program provide chain assaults ever. In a press release launched at this time, the Australian Federal Police (AFP) mentioned two males from Western Australia, aged 21 [&hellip;]","og_url":"https:\/\/futurenews24.com\/index.php\/2026\/08\/27\/two-alleged-teampcp-hackers-arrested-in-australia\/","og_site_name":"Future News 24","article_published_time":"2026-08-27T11:04:00+00:00","article_modified_time":"2026-08-29T02:59:18+00:00","og_image":[{"url":"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/teampcp-shai-hulud.png","type":"","width":"","height":""}],"author":"Future News 24","twitter_card":"summary_large_image","twitter_image":"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/teampcp-shai-hulud.png","twitter_misc":{"Written by":"Future News 24","Est. reading time":"21 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/futurenews24.com\/index.php\/2026\/08\/27\/two-alleged-teampcp-hackers-arrested-in-australia\/#article","isPartOf":{"@id":"https:\/\/futurenews24.com\/index.php\/2026\/08\/27\/two-alleged-teampcp-hackers-arrested-in-australia\/"},"author":{"name":"Future News 24","@id":"https:\/\/futurenews24.com\/#\/schema\/person\/cecad1bde21cfc357cf70128144d6c83"},"headline":"Two Alleged \u2018TeamPCP\u2019 Hackers Arrested in Australia \u2013 Krebs on Safety","datePublished":"2026-08-27T11:04:00+00:00","dateModified":"2026-08-29T02:59:18+00:00","mainEntityOfPage":{"@id":"https:\/\/futurenews24.com\/index.php\/2026\/08\/27\/two-alleged-teampcp-hackers-arrested-in-australia\/"},"wordCount":4145,"commentCount":0,"publisher":{"@id":"https:\/\/futurenews24.com\/#organization"},"image":{"@id":"https:\/\/futurenews24.com\/index.php\/2026\/08\/27\/two-alleged-teampcp-hackers-arrested-in-australia\/#primaryimage"},"thumbnailUrl":"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/teampcp-shai-hulud.png","keywords":["Alleged","Arrested","Australia","Hackers","Krebs","Security","TeamPCP"],"articleSection":["Data Science &amp; MLOps"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/futurenews24.com\/index.php\/2026\/08\/27\/two-alleged-teampcp-hackers-arrested-in-australia\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/futurenews24.com\/index.php\/2026\/08\/27\/two-alleged-teampcp-hackers-arrested-in-australia\/","url":"https:\/\/futurenews24.com\/index.php\/2026\/08\/27\/two-alleged-teampcp-hackers-arrested-in-australia\/","name":"Two Alleged \u2018TeamPCP\u2019 Hackers Arrested in Australia \u2013 Krebs on Safety - Future News 24","isPartOf":{"@id":"https:\/\/futurenews24.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/futurenews24.com\/index.php\/2026\/08\/27\/two-alleged-teampcp-hackers-arrested-in-australia\/#primaryimage"},"image":{"@id":"https:\/\/futurenews24.com\/index.php\/2026\/08\/27\/two-alleged-teampcp-hackers-arrested-in-australia\/#primaryimage"},"thumbnailUrl":"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/teampcp-shai-hulud.png","datePublished":"2026-08-27T11:04:00+00:00","dateModified":"2026-08-29T02:59:18+00:00","breadcrumb":{"@id":"https:\/\/futurenews24.com\/index.php\/2026\/08\/27\/two-alleged-teampcp-hackers-arrested-in-australia\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/futurenews24.com\/index.php\/2026\/08\/27\/two-alleged-teampcp-hackers-arrested-in-australia\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/futurenews24.com\/index.php\/2026\/08\/27\/two-alleged-teampcp-hackers-arrested-in-australia\/#primaryimage","url":"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/teampcp-shai-hulud.png","contentUrl":"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/teampcp-shai-hulud.png"},{"@type":"BreadcrumbList","@id":"https:\/\/futurenews24.com\/index.php\/2026\/08\/27\/two-alleged-teampcp-hackers-arrested-in-australia\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/futurenews24.com\/"},{"@type":"ListItem","position":2,"name":"Two Alleged \u2018TeamPCP\u2019 Hackers Arrested in Australia \u2013 Krebs on Safety"}]},{"@type":"WebSite","@id":"https:\/\/futurenews24.com\/#website","url":"https:\/\/futurenews24.com\/","name":"Future News 24","description":"The Smart Hub for AI and Next-Gen Innovation","publisher":{"@id":"https:\/\/futurenews24.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/futurenews24.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/futurenews24.com\/#organization","name":"Future News 24","url":"https:\/\/futurenews24.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/futurenews24.com\/#\/schema\/logo\/image\/","url":"https:\/\/futurenews24.com\/wp-content\/uploads\/2026\/06\/fn24-favicon.png","contentUrl":"https:\/\/futurenews24.com\/wp-content\/uploads\/2026\/06\/fn24-favicon.png","width":250,"height":250,"caption":"Future News 24"},"image":{"@id":"https:\/\/futurenews24.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/futurenews24.com\/#\/schema\/person\/cecad1bde21cfc357cf70128144d6c83","name":"Future News 24","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/d57f07142d73cb5503ab2446ea7bc9ef3d0a5ba378d64a6157692311e42bf097?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/d57f07142d73cb5503ab2446ea7bc9ef3d0a5ba378d64a6157692311e42bf097?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d57f07142d73cb5503ab2446ea7bc9ef3d0a5ba378d64a6157692311e42bf097?s=96&d=mm&r=g","caption":"Future News 24"},"sameAs":["https:\/\/futurenews24.com"],"url":"https:\/\/futurenews24.com\/index.php\/author\/mridulpahuja20\/"}]}},"_links":{"self":[{"href":"https:\/\/futurenews24.com\/index.php\/wp-json\/wp\/v2\/posts\/4382","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/futurenews24.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/futurenews24.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/futurenews24.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/futurenews24.com\/index.php\/wp-json\/wp\/v2\/comments?post=4382"}],"version-history":[{"count":1,"href":"https:\/\/futurenews24.com\/index.php\/wp-json\/wp\/v2\/posts\/4382\/revisions"}],"predecessor-version":[{"id":4383,"href":"https:\/\/futurenews24.com\/index.php\/wp-json\/wp\/v2\/posts\/4382\/revisions\/4383"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/futurenews24.com\/index.php\/wp-json\/wp\/v2\/media\/4384"}],"wp:attachment":[{"href":"https:\/\/futurenews24.com\/index.php\/wp-json\/wp\/v2\/media?parent=4382"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/futurenews24.com\/index.php\/wp-json\/wp\/v2\/categories?post=4382"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/futurenews24.com\/index.php\/wp-json\/wp\/v2\/tags?post=4382"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}