Australian Authorities Arrest Two Suspects Linked to TeamPCP Cyber Attacks Targeting Mercor, OpenAI, and Others
In Perth, Australia, authorities have arrested two people suspected of being affiliated with TeamPCP, a well-known hacking group linked to significant breaches affecting major tech firms. The two face multiple charges, including hacking, money laundering, and other cybercrime offenses, and are scheduled to appear in court later on Thursday.
The Australian Federal Police have indicated that the detainees are involved in serious infractions that include tampering with and compromising widely-used open-source projects. Their aim was to infiltrate numerous computers to extract credentials and data, using extortion tactics to compel victims into paying ransoms.
Brett Leatherman, head of the FBI’s cyber division, stated that the two suspects are accused of breaching more than a thousand organizations during their hacking activities.
It remains unclear whether the Justice Department will seek extradition, and a representative from the FBI did not promptly respond to inquiries from TechCrunch.
TeamPCP is notorious for conducting extensive hacking campaigns aimed at the software supply chain, where hackers illegitimately access and modify popular open-source software tools relied upon by potentially thousands of businesses.
When malicious code is introduced into a company’s or developer’s systems, it can capture sensitive credentials, including private keys used for accessing cloud storage and often customer data. Authorities report that the hackers acquired over half a million credentials to enable further assaults on additional companies.
The hackers are held accountable for a cyberattack on Trivy, a widely used vulnerability scanner, affecting organizations that depend on it, including LiteLLM and the AI recruitment firm Mercor. Furthermore, they are suspected of breaching the European Commission’s cloud infrastructure and targeting other open-source projects and developer applications that provide access to major tech platforms like GitHub and OpenAI.

Investigations by Australian authorities began in April 2026 after receiving information from multiple cybersecurity firms.
While the identities of the arrested individuals have not been publicly disclosed, investigative journalist Brian Krebs reported that one of the detained hackers, known by the alias Ellis, is Ruben Thomson. Krebs stated he had been in contact with Ellis for several months, during which the hacker claimed to have led TeamPCP until March 2026.
Krebs pointed out that Ellis made several mistakes, which ultimately led to the discovery of the alleged hacker’s true identity.
During a press conference on Wednesday regarding the arrests, Australian officials disclosed that they had also seized a large quantity of purportedly stolen data, as well as devices and electronics from the suspects. The authorities indicated that they plan to notify the victims of the cyberattacks.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.


