Australiancybersecuritymagazine

Two WA men charged after AFP-FBI-WAPF probe into alleged open-source supply-chain attack


Two Western Australian men have been charged with a combined 14 offences following an international cybercrime investigation into an alleged syndicate accused of compromising open-source software to infiltrate more than 1,000 organisations worldwide.

The Australian Federal Police (AFP) charged the men on 26 August following a joint investigation with the Western Australia Police Force (WAPF), conducted in parallel with the US Federal Bureau of Investigation (FBI).

Police allege the cybercrime syndicate inserted malicious code into software hosted on an open-source repository, which was subsequently and unknowingly incorporated into systems by other software developers.

The compromised software was then allegedly distributed into computer systems across government, academia and the private sector, creating what authorities describe as a significant global software supply-chain attack.

Investigators estimate the malicious code potentially compromised more than 1,000 organisations globally, enabling the theft of more than 500,000 credentials and the exfiltration of at least 300GB of data.

According to the AFP, the financial impact has been substantial, with remediation costs globally estimated to be in the hundreds of millions of dollars.

Investigation leads to Perth arrests

Parallel investigations commenced in April 2026 after the AFP and FBI received information from several cyber threat assessment companies concerning the alleged syndicate.

Investigators allege the compromised software provided the syndicate with access to affected organisations, allowing members to steal or harvest sensitive information including user credentials and authentication materials.

The AFP, FBI and WAPF subsequently linked two Western Australian men to the alleged activity.

Search warrants were executed on 26 August at properties in Cottesloe, Hamilton Hill and Mandurah. Two men, aged 21 and 23, were arrested and electronic devices and other material were seized for forensic examination.

Police allege the two men were principal participants in the cybercrime syndicate and received cryptocurrency payments for their involvement. Authorities are continuing to investigate the value of those payments.

FBI Cyber Division Assistant Director Brett E. Leatherman identified the alleged cybercriminal group as TeamPCP.

“These men are allegedly members of the cybercriminal group TeamPCP, whose malicious code potentially compromised more than a thousand organizations worldwide,” Leatherman said.

He said the FBI’s cooperation with Australian authorities demonstrated the international response required to counter the growing threat posed by software supply-chain attacks.

Fourteen charges laid

The 21-year-old Cottesloe man faces eight charges, including possession of data with intent to commit a computer offence, four counts of unauthorised modification of data with intention to commit a serious offence, supplying data with intent to commit a computer offence, failing to comply with a section 3LA order, and dealing with proceeds of crime valued at $100,000 or more.

The proceeds-of-crime offence carries a maximum penalty of 20 years’ imprisonment, while failing to comply with a section 3LA order carries a maximum penalty of 10 years.

The 23-year-old Mandurah man faces six charges, including possession of data with intent to commit a computer offence, four counts of unauthorised modification of data with intention to commit a serious offence, and supplying data with intent to commit a computer offence.

Both men were scheduled to appear before Perth Magistrates Court on 27 August.

The allegations have not been proven and the men are entitled to the presumption of innocence.

Open-source software attack highlights supply-chain risk

The investigation highlights the potentially disproportionate impact of compromising trusted components within modern software supply chains.

Open-source packages and libraries are extensively reused by developers rather than rebuilding common software functions from the ground up. While this model supports rapid development and innovation, compromising a trusted component can potentially provide an attacker with a pathway into numerous downstream applications and organisations.

In this case, police allege the compromise of only a small number of trusted software components ultimately affected organisations across multiple sectors and jurisdictions.

The reported theft of authentication materials is particularly significant. Credentials and other authentication information can potentially provide attackers with additional access to corporate systems, cloud services and other resources beyond the initially compromised software.

Industry intelligence critical to investigation

AFP Commander Graeme Marshall highlighted the role played by cybersecurity companies in identifying the alleged activity and bringing it to the attention of authorities.

“In this matter, the information provided to authorities by a number of threat assessment companies proved crucial for investigators,” Marshall said.

He said cooperation between private-sector organisations and law enforcement was an important component of responding to cybercrime, alongside international intelligence sharing between police agencies.

Marshall said cybercrime syndicates were becoming increasingly organised and frequently operated in a manner resembling professional businesses, while exploiting digital anonymity and international borders.

The operation brought together state, federal and international law enforcement capabilities, with the AFP describing its network of domestic and overseas partners as a significant force multiplier in combating transnational cybercrime.

WAPF warns cybercriminals can operate locally

WAPF Acting Commander Peter Foley said the arrests demonstrated that globally focused cybercriminals could still be operating within local Australian communities.

“It shows the prevalence of cybercrime in our community and that cybercriminals live amongst us,” Foley said.

He encouraged businesses and individuals to report cybercrime regardless of its scale, noting that reports provide investigators with opportunities to identify patterns, engage with victims and collect digital evidence.

Foley also urged organisations and individuals to ensure cybersecurity measures protecting their computing infrastructure and devices remained up to date.

Investigation continues

Authorities are now conducting forensic examinations of the large volume of data and electronic material seized during the Western Australian searches.

The investigation remains active and police have not ruled out further arrests or charges.

The case provides another indication of the increasingly international nature of cybercrime investigations, particularly where malicious software, cryptocurrency and globally distributed infrastructure allow alleged offenders to target organisations far beyond the jurisdictions in which they physically operate.

It also reinforces the growing cybersecurity focus on software supply-chain integrity. For organisations relying on extensive ecosystems of open-source libraries, third-party software and externally developed components, understanding where software originates, how it is maintained and whether it has been maliciously modified is becoming an increasingly important part of managing enterprise cyber risk.





Source link