The Australian Federal Police arrested two men in Perth and charged them with more than a dozen hacking, money laundering, and cybercrime offences, in connection with TeamPCP, a group behind a series of software supply-chain attacks in 2026.
What happened
- TeamPCP compromised open source projects, including the Trivy vulnerability scanner and the LiteLLM library, to plant code that stole developers’ credentials.
- Reported victims included AI recruiting firm Mercor and cloud infrastructure used by the European Commission, with other large technology firms also targeted.
- The FBI said the pair allegedly attacked more than 1,000 organisations and stole more than half a million credentials.
- The AFP said it began investigating in April 2026 after tips from several security firms.
Why it mattered
The case highlighted how attacks on trusted developer tools can cascade into breaches at many downstream organisations, including major AI companies. It was also a notable example of international cooperation between Australian and US law enforcement.
Lessons for organisations
Pin software dependencies to known versions, verify their integrity, and restrict the secrets available to build pipelines. Rotate credentials promptly when a tool you use is reported compromised.
Source: TechCrunch
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.