Two Western Australian men have been charged over alleged TeamPCP supply-chain attacks that police say planted malicious open-source code and reached more than 1,000 organizations worldwide.
The Australian Federal Police charged the pair on 26 August 2026 with a combined 14 offenses after search warrants in Perth, working with the Western Australia Police Force and the FBI. Both men are due to appear in Perth Magistrates Court on 27 August 2026.
Police will allege the men were principal participants in a highly organized syndicate involved in data intrusion, identity crime and cryptocurrency-based money laundering. Investigators say the group inserted malicious code into software on an open-source repository that other developers then used unwittingly.
Infected software was allegedly distributed into systems across government, academia and the private sector, enabling the theft of user credentials and authentication materials. Parallel AFP and FBI investigations began in April 2026 after multiple cyber threat assessment companies flagged the campaign.
Two Australians Charged
FBI Cyber Division Assistant Director Brett E. Leatherman said the suspects are allegedly members of TeamPCP and that the arrests impose costs on actors behind software supply-chain attacks.
Authorities estimate the malicious code potentially compromised more than 1,000 organizations globally, enabling the theft of more than 500,000 credentials and the exfiltration of at least 300 gigabytes of data.
The alleged compromise of a small number of trusted software components had a significant global impact, with remediation costs estimated in the hundreds of millions of dollars. Because developers treat open-source packages as trusted building blocks, a poisoned component can spread far beyond the original repository once it is pulled into production.
AFP and WAPF officers executed warrants on 26 August 2026 at properties in Cottesloe, Hamilton Hill and Mandurah, seizing devices for forensic analysis. Police allege the men received cryptocurrency payments whose value is still under investigation.
A 21-year-old Cottesloe man faces eight charges, including unauthorised modification of data, possessing and supplying data with intent to commit a computer offence, failing to comply with a section 3LA order, and dealing with proceeds of crime worth $100,000 or more, which carries up to 20 years’ imprisonment.
A 23-year-old Mandurah man faces six similar computer offenses. The investigation remains ongoing and further arrests have not been ruled out.
AFP Commander Graeme Marshall said cybercrime syndicates increasingly operate like professional businesses and that industry intelligence was crucial in this case.
Western Australia Police Force Acting Commander Peter Foley said the disruption shows cybercriminals can live among the community and urged organizations to maintain up-to-date security and report incidents through Report Cyber. People concerned their identity was compromised can contact IDCARE, with further advice available from the Australian Cyber Security Center.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

