Australian police charge two alleged TeamPCP hackers linked to more than 1,000 organizations

Australian police have charged two alleged TeamPCP members in a cybercrime campaign that potentially compromised more than 1,000 organizations globally, stole more than 500,000 credentials and exfiltrated at least 300 gigabytes of data. KELA said it shared intelligence with the Australian Federal Police, WAPF and FBI, including a profile that named Ruben Thomson as an alleged TeamPCP member. The financially motivated group, tracked by Google as UNC6780, moved from brokering stolen data on Telegram to compromising trusted security and developer tools. Its March 2026 campaign affected projects including Aqua Security's Trivy vulnerability scanner, Checkmarx KICS and AST GitHub Actions, OpenVSX and LiteLLM. The Trivy compromise is tracked as CVE-2026-33634, which CISA added to its Known Exploited Vulnerabilities catalog on March 26. KELA said TeamPCP also worked with the Vect ransomware operation, which provided encryption and extortion infrastructure in exchange for stolen credentials used for initial access. The case is before the court, while KELA is releasing further findings and offering a threat intelligence report to customers.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.