Australian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and others

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Australian Federal Police arrested two men in Perth accused of being members of TeamPCP, charging them with more than a dozen hacking, money laundering, and cybercrime offenses expected to be heard in court Thursday.
- FBI cyber division chief Brett Leatherman said the two suspects are accused of breaching more than 1,000 organizations through their attacks, per the AFP statement.
- TeamPCP compromised and tampered with popular open source projects to install malware on developers' systems, stealing private keys and credentials to access cloud storage and customer data — and extorting victims after.
- The hackers stole more than half a million credentials to fuel further attacks into other companies, according to Australian authorities.
- Confirmed or suspected targets included the European Commission's cloud infrastructure, AI recruiting startup Mercor, OpenAI, and downstream users of the compromised vulnerability scanner Trivy (including LiteLLM).
- Brian Krebs independently identified one suspect as Ruben Thomson (handle "Ellis"), who told the journalist he led TeamPCP until March 2026 before operational mistakes exposed his real identity.
- Australian police began the investigation in April 2026 after receiving intelligence from multiple cybersecurity companies and seized allegedly stolen data, devices, and electronics during the arrests.
Why it matters: The takedown targets a cybercrime gang that allegedly stole over 500,000 credentials and weaponized trusted open source developer tools to breach more than 1,000 organizations — including OpenAI, Mercor, and the European Commission — forcing the software supply chain into immediate reassessment. Authorities seized allegedly stolen data and plan to notify victims, though it's unclear whether the U.S. Justice Department will seek extradition.
Ask SkimNews



