Australian authorities have arrested two men believed to be members of TeamPCP, the prolific cybercrime and data-extortion group blamed for the longest-running software supply chain attack spree on record. The Australian Federal Police said the suspects, aged 21 and 23, are linked to a “sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.” Australian media identified the 21-year-old as Ruben Ian Thomson of Cottesloe, a beach-side suburb of Perth, and the 23-year-old as Michael Gaebler of Perth. Thomson was denied bail; Gaebler’s legal representative did not request bail. Both men are being held in custody until their next court appearance on September 18.
TeamPCP first drew global attention in late 2025, when it began embedding malicious code in hundreds of open-source software tools and extorting victims for profit. Its signature weapon was Shai-Hulud, a self-propagating worm that compromised corporate cloud environments and added malicious code to open-source programs maintained by developers whose credentials at public code repositories such as GitHub or NPM had been phished or stolen.
The investigation leading to this week’s arrests is a study in operational security failures: a reused password, a HackerOne profile registered in the leader’s own name, and a company legally named after his cybercrime handle all pointed back to a house in an affluent Perth suburb.
Australian police arrest two alleged TeamPCP hackers in Perth
The Australian Federal Police described the arrests as a disruption of an alleged global cybercrime syndicate. The two men from Western Australia face a combined 14 cybercrime offenses and appeared before the Perth Magistrates Court on the day of their arrest.
The AFP did not name the defendants. A source close to the investigation said @pcpcasper was one of the two people taken into custody, a claim supported by messages the Cybercats chat server’s founder posted online the morning of the arrests. The younger suspect’s identity had been established through months of open-source investigation in June, and he had been in direct communication with researchers ever since.
In court, Thomson was denied bail, and the court was told that Gaebler’s attorney did not request bail for his client. Both were remanded in custody until their next scheduled appearance on September 18.
TeamPCP’s playbook: the Shai-Hulud worm and the open source supply chain
What is TeamPCP and how did the Shai-Hulud worm work?
TeamPCP is a cybercrime and data-extortion group that rose to prominence in late 2025 by embedding malicious code in hundreds of open-source software tools. Shai-Hulud is the self-propagating worm the group used to spread those infections: it stole credentials belonging to developers at public code repositories such as GitHub and NPM, then used those credentials to publish poisoned versions of legitimate open-source programs.
The core tactic was a form of cyclical exploitation of software developers. The group gained access to a network where an open-source tool commonly used by programmers was being developed, planted malware in that tool, and waited for the poisoned package to make its way onto other developers’ machines, including some who wrote other tools intended for fellow coders. The malware allowed TeamPCP to steal credentials and publish malicious versions of those development tools as well. The cycle repeated, and each pass expanded the group’s collection of breached networks.
By March 2026, TeamPCP had moved from individual repository takeovers to infrastructure-scale attacks. The group compromised the code for LiteLLM, an open-source AI gateway that connects users to more than 100 different large language models. A subsequent analysis by the security firm CloudSEK concluded that the LiteLLM attack harvested cloud service keys and other secrets from more than 2,500 organizations, including many of the world’s leading technology companies.
Two months later, TeamPCP claimed credit for compromising at least 3,800 code repositories at GitHub, the Microsoft-owned development platform, after a GitHub developer installed a code extension that had been compromised by TeamPCP’s malware. The scale of that breach rattled the software industry because it demonstrated that a loosely organized crew could poison some of the most trusted infrastructure in modern development.
TeamPCP also treated recruitment as an extension of its attack methodology. In May, the source code for the third iteration of Shai-Hulud was published online, and the group announced a contest offering $1,000 in virtual currency, the privacy coin Monero, to whichever participant could pull off the largest supply chain operation using the worm’s code. Participants were scored on the number of weekly and monthly downloads of the packages they compromised, a scoring system that directly incentivized targeting the most popular code libraries. The security firm Dataminr described the prize as a “recruitment floor,” noting that TeamPCP dismissed it as “just like participation trophy” and added that “if you find something good you will be paid way more”—confirming the contest’s true function as talent identification and malicious access acquisition at scale.
The Cybercats chat: where multiple crime crews converged
Security researchers who tracked TeamPCP say the group is less a structured organization than an amalgamation of threat actors from multiple cybercriminal gangs that sometimes cooperate toward shared objectives. Austin Larsen, a principal threat analyst with the Google Threat Intelligence Group, described TeamPCP as “a peer community of individually-skilled actors, with one clear center of gravity.”
That center of gravity is George Prepakis, an accomplished security researcher and self-described exploit developer who operates the Twitter/X profile @kernelstub. Early this year, Prepakis tweeted a public invite link to a Matrix chat server he created and dubbed “Cybercats.” TeamPCP and several related cybercrime entities have been using that server to communicate daily ever since.
The Cybercats member list reads almost like a roster of recent data-extortion actors. The administrator known as Boxturtle is a close TeamPCP associate who has been tweeting about the group’s conquests under the handle @xpl0itrsturtle. That account corresponds to a breach broker active on Breachforums and Darkforums who has been selling data stolen in a wave of attacks on automobile manufacturers, including BMW Group, Audi, Honda, Mercedes-Benz, Volvo, and Toyota, as well as data allegedly taken from Snapchat and SportRadar.
The administrator SeesawSec is the alias behind the cybercrime group Fulcrumsec, which recently claimed data extortion attacks against the pharmaceutical giant Novo Nordisk, the data broker LexisNexis, and Avnet, a Fortune 500 distributor of electronic components.
The administrator @pcpcasper used a matching name on X to discuss TeamPCP’s attacks and victims, and maintained an extensive Telegram history. That history shows @pcpcasper is a vocal member of the National Socialist Network, a neo-Nazi political organization based in Australia. At one point in the chats, @pcpcasper shared videos and images purportedly of their cat, several of which place the user in Western Australia. A source close to the investigation said @pcpcasper was one of the two arrested; the 23-year-old suspect, Michael Gaebler, matches that profile.
The roster also included an administrator with the username “T,” short for the now-banned Twitter/X profile @pcpcats, the account operated by the TeamPCP self-described spokesperson arrested this week. As the investigation later showed, @pcpcats also is from Western Australia.
By the time Prepakis tweeted the public invite to the Cybercats server, T was posting only infrequently, with other members often inquiring about his whereabouts and health. The group’s collective concern related to T’s habit of blaming his increasingly long absences on hallucinogens and other narcotics that kept him awake for days at a stretch, but that also caused him to crash in bed for several days once the highs wore off. In several cases, the X accounts of Cybercats members taunted cybercrime victims publicly before the incidents appeared in any news report.
The investigation: how the TeamPCP leader was identified
How did investigators trace the TeamPCP leader?
Investigators traced the TeamPCP leader through a chain of accounts, reused passwords, and internet infrastructure records. The forum alias Express was linked to the email address [email protected], which breach data tied to a Raidforums account accessed almost exclusively from internet addresses in Perth, Australia. Passive DNS records connected one of those addresses to the Thomson family’s private file servers, and a single reused password—joshuathomson1—linked the family’s email domain to years of cybercrime forum activity. A HackerOne profile registered under the name Ruben Thomson with the username Deadcatx3, an alias that multiple security firms had flagged as TeamPCP’s, completed the identification.
From forum handles to a Gmail address
The Cybercats member behind @pcpcats used multiple nicknames across the cybercrime underground: EllisD25/LSD on Darkforums, BulkDMT on Breachstars, and Express on Breachforums. The accounts were linked because they advertised the same Tox ID or Session ID as instant-message contact handles in their forum posts. BulkDMT was also known as DMT Host, a virtual private server hosting service peddled on Darkforums and Breachstars.
Intel 471 found that Express registered on Breachforums using [email protected] and posted across a two-month period in 2025 through four different internet addresses located in South Africa. On July 30, 2025, Express announced on Breachforums the sale of access to 14 gigabytes of data stolen from South Africa’s State Information Technology Agency.
Telegram activity recorded by the threat intelligence platform Flashpoint reinforced the South Africa connection. For more than a year, the TeamPCP leader’s Telegram alter ego, Persy_PCP, told another user in November 2025 that “I have these [files] as well, problem is these are in another country.” Later that month, Persy_PCP complained, “My whole country is racist and they want people like me dead.” BulkDMT shared in September 2025 that “this country is going to fucking starve when they take the farmers land,” a likely reference to the South African farming community. By June, Google had traced TeamPCP’s residential and mobile internet connections to South Africa, indicating the primary operator was located there during at least some of its attacks.
A reused password and the Thomson family trail
The decisive pivot to Australia came from breach data and domain records. SpyCloud found that [email protected] appeared in the registration of an account called ChristmasSnow on the cybercrime community Raidforums in 2022. Nearly all of the internet addresses used to access that account came from ISPs in Perth, Australia.
A lookup of those Perth addresses in passive DNS records maintained by DomainTools showed that one of them—211.27.196.111—had for years served as a private file server for a family named Thomson in Perth. The records showed at least three hosts persisting at that address between 2022 and 2025, including joshuawthomson39.myqnapcloud.com, a QNAP network storage device.
Searching on “joshuathomson39” in breach tracking data from Constella Intelligence revealed an account at the freight forwarding company kwe.com created in the name of Joshua Thomson of Perth. The phone number attached to that account was used to register a Facebook profile for Josh Thomson, which lists his brother Ruben, father Ian, and mother Cindy. The profile says the family is originally from Pietermaritzburg, in KwaZulu-Natal, South Africa, and now lives in Cottesloe. Ian Thomson is a dentist in Cottesloe who graduated from the University of the Witwatersrand in Johannesburg; his name appears on registrations for five domains, including securecomputing.au, thomson.org.au, and thomsonfamily.net.au.
Joshua Thomson appears to have no meaningful connection to cybercrime forums. His brother Ruben, by contrast, has a significant presence on them going back years. Constella found that [email protected] frequently reused the password “joshuathomson1,” and that the same password protected only a handful of accounts, including [email protected] and [email protected]. Intel 471 reported that [email protected] registered the user Yolosolo17 on the crime forum Altenen in 2018 from a Perth address. The same address hosted rubenthomson.com, a domain once used to sell steeply discounted iPhones and registered to [email protected].
From there, the trail branched into a small forest of linked aliases. SpyCloud reported that the same Perth address was used by [email protected] on Raidforums and [email protected] on Nulled, and connected [email protected] to the accounts Sheep420, YoloSolo117, and Yakuza.cc on Raidforums, as well as to the account “Sheep Stealing” on Hackforums. Intel 471 found [email protected] was used to register DingoFlour on Breachforums in October 2023 and Sheepx on Altenen.
The pattern extended beyond forums. Epieos found that [email protected] is tied to an Airbnb account under the name Ruben, who described himself as a Web developer who attended the University of Western Australia and lived outside the country. “Hey, I’m Ruben, my friends call me Ellis,” the profile reads. “I’m a Perth creative who occasionally books rooms when visiting family and for photography.” An Upwork profile registered to [email protected] under the name Ruben lists his main skills as secure server hosting and PHP full-stack Web development. “I’m familiar with Linux, working with relational databases (SQL),” it reads. “I also script in Python mainly for writing social media bots.”
Epieos further linked [email protected] to a Microsoft account for Ruben Thomson and to a defunct GitHub account called XmasSnow/XmasSnowisBack that scammed people on the forums in 2022 by selling nonexistent exploits for newly released software patches. The same email registered a Twitter/X account in 2026 called “Gone Fishing” that lists its location as South Africa. Yet the Google Maps reviews left under this Gmail account over the past seven years all concern businesses on the west coast of Australia. Pipl found a 21-year-old Ruben Thomson in Western Australia whose phone number is connected to a TikTok account under the name Ellis and to a PayPal account in Ruben Thomson’s name.
Operational security at its worst
A search of the Australian government’s registry of registered businesses shows Ruben Thomson of Cottesloe has incorporated or served as an official in multiple companies created since 2024, including Secure Computing Solutions, Tensor Industries, and an entity ironically named OPSEC Express. Express, of course, was BulkDMT’s nickname on Breachforums. Embedding your own cybercrime handle in the legal name of a company is the antithesis of operational security—the discipline of protecting your real identity—and it gave investigators a convenient map of the suspect’s commercial life.
There was at least one more direct link. In June 2025, someone using the name Ruben Thomson registered on HackerOne, the bug bounty platform that rewards researchers for helping vendors fix vulnerabilities before publishing details. The chosen username was Deadcatx3, a nickname multiple security firms have flagged as an alias used by TeamPCP.
Inside the interview: “Blackhatting is fun”
In early July 2026, the TeamPCP leader agreed to an interview over the encrypted messaging app Signal. He asked to be called Ellis, the name his friends use and one of his earliest aliases, and the investigation had by then linked that identity to Ruben Thomson. He was remarkably open about his activities and his personal struggles. He claims he stopped doing cybercrime for TeamPCP in March 2026, just before the LiteLLM compromise, and that at least one other individual has taken over the group’s leadership since then. He said a year earlier he had just completed the latest in a series of detox and sobriety programs and was two months sober when he reconnected with old friends from the malware development scene.
“One year ago I needed help monetizing some [GitHub credentials], I was two months sober and needed a distraction and something to keep busy as well as people to speak to,” he said. “I had largely disconnected from my old circle, they had become very toxic and I needed to get away from the substances. Previously I had done some mass exploitation campaigns and grew up doing [malware development] and [capture the flag] contests. There were some friends who were also vending but had stopped a while, and one of them introduced me to some chats where I posted access for sale.”
Before that, Ellis said, he was homeless and hopping between “some very unstable places.”
“Blackhatting is fun,” he said. “There are actual rewards and incentives to learn and you grow with your team. Without qualifications, no employer will even take the time to hear you out.”
Ellis claimed he earned a grand total of about $20,000 from his activities with TeamPCP, and said it was never about the money or fame for him. Asked whether his experience might prepare him for legitimate IT work, he said he doubted it. “I am nowhere close to a skill level where I am comfortable, and this would take maybe half a decade of further experience.” He added: “I no longer have to choose between rent and food for that I’m grateful and so are the team members.”
He expressed no remorse, said he was grateful for the relationships built during his time with TeamPCP, and seemed resigned to his fate. “If I’ve already been found out then its out of my control, I’ll make peace with that,” he said. “Honestly, I think someone like me needs a lot of help that prison just can’t provide. If I had the funds to study different parts of the field and closer guidance, this would have turned out differently. But that’s a pipe dream and we both know this.”
His struggles with sobriety were on open display in the group’s chats until the very end. On June 25, Ellis told @kernelstub he was about to “trip” with his “homie.” When @kernelstub asked what kind, Ellis replied, “Ketty and some DMT,” referring to the dissociative anesthetic ketamine and the powerful psychedelic dimethyltryptamine. “There’s a little 2cb so we might throw that in the mix,” he continued, naming a third hallucinogen by its chemical shorthand.
Roughly two weeks before his arrest, Ellis said he was ready to leave his life of crime behind and prepared to turn himself in, but that he was first making plans to tie up loose ends. Less than 24 hours later, he posted an image on Telegram showing a yellowish powdered substance in a baggie on a scale—possibly synthetic DMT—arranged next to a row of small vape cartridges.
A new breed of threat actor and a supply chain security wake-up call
Charlie Eriksen, a security researcher at Aikido Security who has closely followed TeamPCP’s campaigns, argues that the group represents a kind of threat actor that does not fit neatly into established categories. “They are not a state actor, not quite organized cybercrime, and not purely ideological,” he said. “Their motivations seem to mix money, disruption, attention, and ideology.”
Eriksen also sees TeamPCP as an early beneficiary of a structural shift in cybercrime. For years, a meaningful gap separated reading about an attack technique and turning it into a reliable operational campaign. “You had to understand the research, adapt the code, troubleshoot it, build infrastructure around it, and then repeat that process across different targets,” he said. “LLMs have compressed that gap significantly.”
That compression creates a dangerous class of actor: groups with the ability to operate at significant scale without the operational discipline that traditionally accompanies that level of capability. “They can be noisy, they can make mistakes,” Eriksen said. “They can leave evidence everywhere. They can take risks that a professional criminal group or intelligence service would consider completely unacceptable. But that does not necessarily make them less dangerous. In some ways, it can make them more dangerous.”
TeamPCP’s impact on the software industry, however, has not been purely destructive. Eriksen has called the Shai-Hulud worm the “best thing to happen to supply chain security,” because it forced GitHub and other public coding platforms to adopt safeguards researchers had spent years requesting. In late July, GitHub introduced a three-day “cooldown” mechanism for Dependabot, its tool for automatically fetching newly shipped updates for package dependencies. Cooldown periods buy time for security tools and package maintainers to identify and remove compromised versions before a poisoned update reaches thousands of downstream projects. Other coding ecosystems, including Python and several JavaScript platforms, added support for cooldown periods this year amid mounting calls for wider adoption of the safety feature.
“They managed to wake up Microsoft to the fact that they had become negligent in terms of security,” Eriksen said. “By compromising GitHub and stealing their source code, they humiliated Microsoft into action, making them finally act on what we had been asking them to do and take seriously for a while now.”
The Perth arrests may not end TeamPCP’s story. Ellis claimed in July that at least one other individual has taken over the group’s leadership, and the Shai-Hulud contest was explicitly designed to bring in new talent that does not depend on any single operator. What the case does prove is that the current generation of AIa-assisted cybercriminals can be extraordinarily capable and extraordinarily careless at the same time. Their tools scale; their judgment often does not. For defenders, that combination is a warning. For law enforcement, it is an opportunity—and one the Australian Federal Police have just shown they know how to take.