{"id":26114,"date":"2026-09-18T10:12:02","date_gmt":"2026-09-18T18:12:02","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2026\/09\/18\/two-alleged-teampcp-hackers-arrested-in-australia\/"},"modified":"2026-09-18T10:12:02","modified_gmt":"2026-09-18T18:12:02","slug":"two-alleged-teampcp-hackers-arrested-in-australia","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2026\/09\/18\/two-alleged-teampcp-hackers-arrested-in-australia\/","title":{"rendered":"Two Alleged \u2018TeamPCP\u2019 Hackers Arrested in Australia"},"content":{"rendered":"<p>Authorities in Australia have arrested two men believed to be members of <strong>TeamPCP<\/strong>, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever.<\/p>\n<p>In <a href=\"https:\/\/www.afp.gov.au\/news-centre\/media-release\/two-wa-men-charged-following-afp-fbi-wapf-disruption-alleged-global\" rel=\"noopener\" target=\"_blank\">a statement<\/a> released today, the <strong>Australian Federal Police<\/strong> (AFP) said two men from Western Australia, aged 21 and 23, were arrested in connection with a \u201csophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.\u201d<\/p>\n<p>The AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old suspect\u2019s real identity in June, and has been communicating with him ever since. This story includes interviews with TeamPCP\u2019s self-described spokesperson, and examines clues left behind by the TeamPCP leader that likely led to his undoing.<\/p>\n<p>TeamPCP vaulted onto the cybercrime scene in late 2025, embedding malicious code in hundreds of open source software tools and extorting victims for profit. Members of the group made headlines by compromising corporate cloud environments using a self-propagating worm dubbed\u00a0<strong>Shai-Hulud<\/strong>, which added malicious code to open source programs maintained by developers whose credentials at public code repositories like GitHub or NPM were phished or stolen.<\/p>\n<p>Writing for <em>Wired<\/em>, journalist <strong>Andy Greenberg<\/strong> described TeamPCP\u2019s core tactic as a kind of cyclical exploitation of software developers.<\/p>\n<p>\u201cThe hackers gain access to a network where an open source tool commonly used by coders is being developed,\u201d Greenberg <a href=\"https:\/\/www.wired.com\/story\/teampcp-software-supply-chain-attack-spree-github\/\" rel=\"noopener\" target=\"_blank\">wrote in May<\/a>. \u201cThe hackers plant malware in the tool that ends up on other software developers\u2019 machines, including some who are writing other tools intended to be used by coders. The malware allows TeamPCP\u2019s hackers to steal credentials that let them publish malicious versions of those software development tools, too. The cycle repeats, and TeamPCP\u2019s collection of breached networks grows.\u201d<\/p>\n<p>TeamPCP also has practiced something akin to cyclical recruitment. In May, the source code for the third iteration of Shai-Hulud was published online, and TeamPCP soon after launched a contest offering $1,000 in virtual currency to whichever participant could conduct the largest supply chain operation using the worm\u2019s code. According to the contest rules, participants were scored based on the number of weekly and monthly downloads of packages they compromised \u2014 directly incentivizing them to target the most popular code libraries.<\/p>\n<div class=\"wp-caption aligncenter\" id=\"attachment_74036\" style=\"width: 700px;\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" class=\"size-full wp-image-74036\" height=\"581\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/teampcp-shai-hulud.png\" width=\"690\"\/><\/p>\n<p class=\"wp-caption-text\" id=\"caption-attachment-74036\">A screenshot of a message from TeamPCP\u2019s Telegram account, announcing the supply chain hacking contest. Image: dataminr.com.<\/p>\n<\/div>\n<p>\u201cTeamPCP has stated the competition is a recruiting opportunity and they intend to purchase all meaningful access harvested from participants\u2019 campaigns,\u201d the security firm Dataminr <a href=\"https:\/\/www.dataminr.com\/resources\/cyber-intel-deep-dive-teampcp-shai-hulud-3-0\/\" rel=\"noopener\" target=\"_blank\">wrote<\/a>. \u201cThe $1,000 XMR (Monero) prize is a recruitment floor and has been dismissed by the actor as \u2018just like participation trophy,\u2019 adding \u2018if you find something good you will be paid way more,\u2019 confirming the contest\u2019s true function as talent identification and malicious access acquisition at scale.\u201d<\/p>\n<p>In March, TeamPCP executed a supply chain attack targeting AI infrastructure by compromising the code for <strong>LiteLLM<\/strong>, an open source AI gateway that connects users to more than 100 different large language models. A <a href=\"https:\/\/www.cloudsek.com\/blog\/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines#\" rel=\"noopener\" target=\"_blank\">recent analysis<\/a> by the security firm <strong>CloudSEK<\/strong> found TeamPCPs attack on LiteLLM harvested cloud service keys and other secrets from more than 2,500 organizations, including many of the world\u2019s top technology companies.<\/p>\n<p>In May, TeamPCP claimed credit for compromising at least 3,800 code repositories at the Microsoft-owned <strong>GitHub<\/strong>, after a GitHub developer installed a code extension that was compromised by TeamPCP\u2019s malware.<\/p>\n<h2>MEET THE CYBERCATS<\/h2>\n<p>Security experts say TeamPCP is less of a hacker group than an amalgamation of threat actors from multiple cybercriminal gangs who sometimes work together toward similar goals.<\/p>\n<p>\u201cIt is not a structured criminal crew with a single operator,\u201d said <strong>Austin Larsen<\/strong>, a principal threat analyst with the <strong>Google Threat Intelligence Group<\/strong>. \u201cIt is a peer community of individually-skilled actors, with one clear center of gravity.\u201d<\/p>\n<p>That center of gravity is <strong>George Prepakis<\/strong>, an accomplished security researcher and self-described exploit developer who operates the Twitter\/X profile <a href=\"https:\/\/x.com\/kernelstub\" rel=\"noopener\" target=\"_blank\">@kernelstub<\/a>. Earlier this year, @kernelstub tweeted a public invite link to a Matrix chat server he created and dubbed \u201cCybercats,\u201d and TeamPCP and several other cybercrime entities have been using this server to communicate daily for the past several months.<\/p>\n<div class=\"wp-caption aligncenter\" id=\"attachment_74165\" style=\"width: 758px;\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" class=\"wp-image-74165\" height=\"590\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/matrix-tpcp-xpl0itrs.png\" width=\"748\"\/><\/p>\n<p class=\"wp-caption-text\" id=\"caption-attachment-74165\">A screenshot of the Matrix chat server \u201cCybercats,\u201d whose members used hacker handles associated with multiple distinct cybercrime groups that have occasionally collaborated on a series of supply chain and data ransom attacks over the past nine months.<\/p>\n<\/div>\n<p>Kernelstub, like other administrators in the Cybercats chat, has been using his Twitter\/X profile name as his handle in these Matrix communications, frequently tweeting references to other members and to conversations taking place in the Cybercats chat. In a number of cases, the corresponding X accounts for members of the Cybercats chat taunted cybercrime victims publicly before the incidents were reported in the news media.<\/p>\n<p>The Cybercats administrator listed at the top of the screenshot above \u2014 \u201c<strong>Boxturtle<\/strong>\u201d \u2014 is a close associate of TeamPCP who has been tweeting about the group\u2019s conquests under the name <a href=\"https:\/\/x.com\/xploitrsturtle2\/\" rel=\"noopener\" target=\"_blank\">@xpl0itrsturtle<\/a>. This handle corresponds to a data breach broker active on Breachforums and Darkforums who has been selling data stolen in a wave of recent breaches at automobile manufacturers, including <strong>BMW Group<\/strong>, <strong>Audi<\/strong>, <strong>Honda<\/strong>, <strong>Mercedes-Benz<\/strong>, <strong>Volvo<\/strong> and <strong>Toyota<\/strong>, as well as data allegedly taken from <strong>Snapchat<\/strong> and <strong>SportRadar<\/strong>.<\/p>\n<div class=\"wp-caption aligncenter\" id=\"attachment_74174\" style=\"width: 760px;\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" class=\"wp-image-74174\" height=\"525\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/xpl0itrs-dls.png\" width=\"750\"\/><\/p>\n<p class=\"wp-caption-text\" id=\"caption-attachment-74174\">The data leak site for the extortion group or handle \u201cxpl0itrs.\u201d<\/p>\n<\/div>\n<p>The Cybercats administrator \u201c<strong>SeesawSec<\/strong>\u201d in the screenshot above is the alias of whoever is behind the cybercrime group known as <strong>Fulcrumsec<\/strong>, which recently claimed credit for data extortion attacks against the pharmaceutical giant <strong>Novo Nordisk<\/strong>, the data broker <strong>LexisNexis<\/strong>, and <strong>Avnet<\/strong>, a Fortune 500 distributor of electronic components.<\/p>\n<div class=\"wp-caption aligncenter\" id=\"attachment_74175\" style=\"width: 686px;\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" class=\"wp-image-74175\" height=\"858\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/fulcrumsec-dls.png\" width=\"676\"\/><\/p>\n<p class=\"wp-caption-text\" id=\"caption-attachment-74175\">The data leak site of Fulcrum Security, a.k.a. Fulcrumsec.<\/p>\n<\/div>\n<p>The Cybercats administrator \u201c<strong>@pcpcasper<\/strong>\u201d also has been using a similar name on X to discuss TeamPCP\u2019s attacks and victims. This person has an extensive message history on Telegram, where their messages and shared videos show @pcpcasper is an active and vocal member of the National Socialist Network, a neo-Nazi political organization based in Australia.<\/p>\n<p>At one point in these chats, @pcpcasper shared videos and images of what they claimed was their cat, and several of those videos place this user in Western Australia. One source close to the investigation told KrebsOnSecurity that @pcpcasper was one of the two arrested, a claim supported by messages that @kernelstub posted online this morning.<\/p>\n<p>The Cybercats member roster pictured above also features an administrator with the username \u201c<strong>T<\/strong>,\u201d which is short for the now-banned Twitter\/X profile <strong>@pcpcats<\/strong>, the account operated by the self-described TeamPCP spokesperson who was arrested today. As we\u2019ll see in a moment, @pcpcats also is from Western Australia.<\/p>\n<p>By the time @kernelstub tweeted a public invite link to the Cybercats Matrix server, T\/@pcpcats was posting only infrequently to the group chat, with other members often inquiring as to his whereabouts and well-being. The group\u2019s collective concern related to @pcpcats\u2019s tendency to blame his increasingly extended absences on the use of hallucinogens and other narcotics that kept him awake for days on end, but also caused him to crash in bed for several days after the highs wore off.<span id=\"more-73635\"><\/span><\/p>\n<h2>WHO IS THE TEAMPCP LEADER?<\/h2>\n<p>The Cybercats member @pcpcats has used multiple nicknames on the cybercrime forums, including <strong>EllisD25\/LSD<\/strong> on Darkforums, <strong>BulkDMT<\/strong> on Breachstars, and <strong>Express<\/strong> on Breachforums. These accounts are linked because they all advertised the same Tox ID and\/or Session ID as instant message contact handles in their cybercrime forum posts. BulkDMT was also known on the forums as <strong>DMT Host<\/strong>, which was a <a href=\"https:\/\/cloud.google.com\/learn\/what-is-a-virtual-private-server\" rel=\"noopener\" target=\"_blank\">virtual private server<\/a> (VPS) hosting service that was peddled on Darkforums and Breachstars.<\/p>\n<div class=\"wp-caption aligncenter\" id=\"attachment_74040\" style=\"width: 760px;\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" class=\"wp-image-74040\" height=\"356\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/dmthost.png\" width=\"750\"\/><\/p>\n<p class=\"wp-caption-text\" id=\"caption-attachment-74040\">DMT Host\/EllisD25, posting on the English-language cybercrime community DarkForums in September 2025. Image: ke-la.com.<\/p>\n<\/div>\n<p>According to the cyber intelligence firm <strong>Intel 471<\/strong>, Express registered on Breachforums using the email address <strong>shitstickpp@gmail.com<\/strong>. Intel 471 finds Express posted on Breachforums across a two-month period in 2025 using four different Internet addresses located in <strong>South Africa<\/strong>. On July 30, 2025, Express announced on Breachforums they were selling access to 14 gigabytes of data stolen from South Africa\u2019s State Information Technology Agency.<\/p>\n<p>The threat intelligence platform <strong>Flashpoint<\/strong> recorded more than a year\u2019s worth of messages from the TeamPCP leader\u2019s alter ego on Telegram \u2014 <strong>Persy_PCP<\/strong> \u2014 \u00a0who claimed they split their life living between two countries [full disclosure: Flashpoint is an advertiser on this blog]. \u201cI have these [files] as well, problem is these are in another country,\u201d Persy_PCP explained to another user inquiring about a stolen data set in November 2025.<\/p>\n<p>Later that month, Persy_PCP complained, \u201cMy whole country is racist and they want people like me dead.\u201d Flashpoint records show BulkDMT shared in September 2025 that \u201cthis country is going to fucking starve when they take the farmers land,\u201d a likely reference to white landowners in South Africa who <a href=\"https:\/\/www.pbs.org\/newshour\/world\/a-hillside-of-white-crosses-fuels-a-misleading-story-about-south-africas-farm-killings\" rel=\"noopener\" target=\"_blank\">claim to be targeted by an ongoing genocide campaign<\/a>.<\/p>\n<p>This tracks with public reporting on TeamPCP. <em>Cyberscoop<\/em> <a href=\"https:\/\/cyberscoop.com\/teampcp-breaks-open-source-software-trust-model\/\" rel=\"noopener\" target=\"_blank\">reported in June<\/a> that <strong>Google<\/strong> had traced TeamPCP\u2019s residential and mobile Internet address connections to South Africa, \u201cindicating the primary operator was located there during at least some of its attacks.\u201d<\/p>\n<p>BulkDMT also shared on the group chat at Breachforums that they were recovering from an addiction to methamphetamine. \u201cMy life is kinda fucked rn [right now], but that\u2019s fine and there isn\u2019t really a point in pouring so much emotional energy into that fact, my parents had money but I unfortunately got really addicted to some things so I don\u2019t get to benefit from that. As long as I continue to survive, stay sober, and move closer towards my goals that\u2019s enough drive and meaning.\u201d<\/p>\n<p>The identity threat protection company <strong>SpyCloud<\/strong> finds shitstickpp@gmail.com shows up in the registration of an account called <strong>ChristmasSnow<\/strong> on the cybercrime community <strong>Raidforums<\/strong> in 2022. Nearly all of the Internet addresses used to access that account came from ISPs in Perth, Australia, SpyCloud found.<\/p>\n<p>KrebsOnSecurity looked up all of those Perth IP addresses in <a href=\"https:\/\/docs.domaintools.com\/iris\/investigate\/data-panels\/pdns\/\" rel=\"noopener\" target=\"_blank\">passive DNS<\/a> records maintained by <strong>DomainTools.com<\/strong>, and found one of them \u2014 <strong>211.27.196.111<\/strong> \u2014 for several years was used as a private file server by a family in Perth with the last name of <strong>Thomson<\/strong>. Those records show at least three hosts \u2014 ithomson.direct.quickconnect.to (a remote Synology server), kthomson0061.direct.quickconnect.to, and <strong>joshuawthomson39.myqnapcloud.com<\/strong> (a QNAP network storage device) \u2014 persisted at that address between 2022 and 2025.<\/p>\n<p>Searching on \u201c<strong>joshuathomson39<\/strong>\u201d in the breach tracking service <strong>Constella Intelligence<\/strong> reveals an account at the freight forwarding company kwe.com created in the name of Joshua Thomson from Perth, Australia. The open source intelligence platform <strong>Epieos<\/strong> finds the phone number attached to that kwe.com account was used to register a Facebook profile for Josh Thomson, which says his family includes a brother named <strong>Ruben<\/strong>, his father <strong>Ian<\/strong>, and his mom Cindy.<\/p>\n<p>That Facebook profile also says Josh and his family are originally from <a href=\"https:\/\/en.wikipedia.org\/wiki\/Pietermaritzburg\" rel=\"noopener\" target=\"_blank\">Pietermaritzburg<\/a>, in KwaZulu-Natal, South Africa, but currently living in <a href=\"https:\/\/en.wikipedia.org\/wiki\/Cottesloe,_Western_Australia\" rel=\"noopener\" target=\"_blank\">Cottesloe<\/a>, a beach-side suburb of Perth. A search in DomainTools for Ian Thomson and Australia unearthed five domains by the same registrant, including <strong>securecomputing.au<\/strong>, <strong>thomson.org.au<\/strong>, and <strong>thomsonfamily.net.au<\/strong>. Ian Thomson is a dentist in Cottesloe, and a biography says he graduated from The University of the Witwatersrand in Johannesburg, South Africa.<\/p>\n<p>Constella finds a joshua@thomson.org.au registered a number of accounts online, but Josh doesn\u2019t seem to have much of a connection to dodgy cybercrime forums. His brother Ruben, on the other hand, has quite the presence on these communities, dating back to at least 2018. Constella reports <strong>ruben@thomson.org.au<\/strong> frequently reused the password \u201cjoshuathomson1,\u201d and Constella further finds that password was used by just a handful of accounts, including <strong>yolosolo17@gmail.com<\/strong> and <strong>surfinup8@gmail.com<\/strong>.<\/p>\n<p>According to Intel 471, surfinup8@gmail.com was used to register the user <strong>Yolosolo17<\/strong> on the crime forum <strong>Altenen<\/strong> in 2018, and that user account was registered from the Perth address <strong>110.141.230.15<\/strong>. On Altenen, Yolosolo17 advertised free web proxies, as well as the domain rubenthomson.com, which was at one point used to sell steeply discounted iPhones. <strong>DomainTools<\/strong> says rubenthomson.com was hosted at 110.141.230.15 and registered to surfinup8@gmail.com.<\/p>\n<div class=\"wp-caption aligncenter\" id=\"attachment_73723\" style=\"width: 758px;\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" class=\"wp-image-73723\" height=\"483\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/05\/rubenthomsondotcom.png\" width=\"748\"\/><\/p>\n<p class=\"wp-caption-text\" id=\"caption-attachment-73723\">A cached copy of the domain rubenthomson.com from 2017 shows a login page underneath a banded stack of money. Image: archive.org.<\/p>\n<\/div>\n<p>SpyCloud reports 10.141.230.15 was used by the email address <strong>sheepstealing@gmail.com<\/strong> on Raidforums and surfinup8@gmail.com on Nulled, and that the same IP was used by the email addresses ian@thomsonfamily.net.au, jasper@yakuza.cc, and rubenthomson1@gmail.com. SpyCloud also shows that sheepstealing Gmail address is tied to the accounts <strong>Sheep420<\/strong>, <strong>YoloSolo117<\/strong> and <strong>Yakuza.cc<\/strong> on Raidforums, and to the account \u201cSheep Stealing\u201d on Hackforums. Intel 471 says sheepstealing@gmail.com was used to register the account <strong>DingoFlour<\/strong> on Breachforums in October 2023, as well <strong>Sheepx<\/strong> on Altenen.<\/p>\n<p>Epieos reports that <strong>ruben@securecomputing.au<\/strong> is tied to an <strong>Airbnb<\/strong> account for Ruben, who described himself as a Web developer who went to school at the University of Western Australia and was living outside the country. \u201cHey, I\u2019m Ruben, my friends call me <strong>Ellis<\/strong>. I\u2019m a Perth creative who occasionally books rooms when visiting family and for photography.\u201d<\/p>\n<p>Epieos also finds sheepstealing@gmail.com registered an upwork.com profile under the name Ruben, who said his main skills are setting up secure server hosting solutions and PHP full-stack Web development.<\/p>\n<p>\u201cI\u2019m familiar with Linux, working with relational databases (SQL),\u201d the Upwork profile reads. \u201cI also script in Python mainly for writing social media bots.\u201d<\/p>\n<div class=\"wp-caption aligncenter\" id=\"attachment_74038\" style=\"width: 760px;\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" class=\"wp-image-74038\" height=\"397\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/upwork-thomson.png\" width=\"750\"\/><\/p>\n<p class=\"wp-caption-text\" id=\"caption-attachment-74038\">The Upwork profile for Ruben Thomson in Cottesloe, Australia.<\/p>\n<\/div>\n<p>Epieos further discovered sheepstealing@gmail.com is connected to a Microsoft account for Ruben Thomson, and to a now-defunct GitHub account called <a href=\"https:\/\/web.archive.org\/web\/*\/https:\/\/github.com\/XmasSnow*\" rel=\"noopener\" target=\"_blank\">XmasSnow\/XmasSnowisBack<\/a> that scammed people on the forums in 2022 by claiming to sell exclusive exploits for recently-released software patches (recall that shitstickpp@gmail.com was used to register a forum account named ChristmasSnow).<\/p>\n<p>This same sheepstealing email address registered a Twitter\/X account in 2026 called \u201cGone Fishing\u201d that lists its location as South Africa. That Gmail account also <a href=\"https:\/\/www.google.com\/maps\/contrib\/116139896651889086279\/reviews\/@-32.2179865,115.5244308,99089m\/data=!3m2!1e3!4b1!4m3!8m2!3m1!1e1?entry=ttu&#038;g_ep=EgoyMDI2MDUxMS4wIKXMDSoASAFQAw%3D%3D\" rel=\"noopener\" target=\"_blank\">left several reviews<\/a> for businesses listed on Google Maps over the past seven years, but all of those establishments are located on the west coast of Australia.<\/p>\n<div class=\"wp-caption aligncenter\" id=\"attachment_74037\" style=\"width: 760px;\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" class=\"wp-image-74037\" height=\"547\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/gonefishing.png\" width=\"750\"\/><\/p>\n<p class=\"wp-caption-text\" id=\"caption-attachment-74037\">Business reviews in Western Australia left by the Google account sheepstealing at gmail.com.<\/p>\n<\/div>\n<p>The people search service <strong>Pipl<\/strong> finds a 21-year-old Ruben Thomson in Western Australia who has a phone number ending in 979. A lookup on that number at Epieos reveals it is connected to <a href=\"https:\/\/www.tiktok.com\/@user7508029790800\" rel=\"noopener\" target=\"_blank\">a TikTok account<\/a> under the name Ellis, and to a PayPal account in the name of Ruben Thomson.<\/p>\n<p>Finally, a search on the name Ruben Thomson from Cottesloe at the Australian government\u2019s record of registered businesses finds he has incorporated or served as an official in multiple companies created since 2024, including <strong>Secure Computing Solutions<\/strong>, <a href=\"https:\/\/connectonline.asic.gov.au\/RegistrySearch\/faces\/landing\/bySearchId.jspx?searchIdType=BUSN&#038;searchId=698546137\" rel=\"noopener\" target=\"_blank\">Tensor Industries<\/a>, and another entity ironically named <a href=\"https:\/\/connectonline.asic.gov.au\/RegistrySearch\/faces\/landing\/bySearchId.jspx?searchIdType=BUSN&#038;searchId=684301513\" rel=\"noopener\" target=\"_blank\">OPSEC Express<\/a>. Recall that Express was BulkDMT\u2019s nickname on Breachforums.<\/p>\n<div class=\"wp-caption aligncenter\" id=\"attachment_74206\" style=\"width: 760px;\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" class=\"wp-image-74206\" height=\"449\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/rthomson-companies.png\" width=\"750\"\/><\/p>\n<p class=\"wp-caption-text\" id=\"caption-attachment-74206\">Australian companies connected to Ruben Thomson. Image: abr.business.gov.au.<\/p>\n<\/div>\n<p>It\u2019s ironic because OPSEC is short for the term \u201coperational security,\u201d which refers to techniques and behaviors used to obfuscate and compartmentalize one\u2019s real-life identity online, and using your cybercrime handle as part of your own company name is very much the antithesis of that practice.<\/p>\n<p>There is at least one other major opsec failure by Ruben that exposed a link to TeamPCP. In June 2025, someone using the name Ruben Thomson registered on <strong>HackerOne<\/strong>, a popular \u201cbug bounty\u201d program that seeks to reward and recognize researchers who agree to work with affected software vendors to help fix the flaws before publishing about their findings. What was Ruben Thomson\u2019s chosen HackerOne username? <strong>Deadcatx3<\/strong>, a nickname that has been <a href=\"https:\/\/labs.cloudsecurityalliance.org\/research\/csa-research-note-teampcp-multi-ecosystem-supply-chain-20260\/\" rel=\"noopener\" target=\"_blank\">flagged by multiple security firms<\/a> as an alias used by TeamPCP.<\/p>\n<div class=\"wp-caption aligncenter\" id=\"attachment_74167\" style=\"width: 756px;\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" class=\"wp-image-74167\" height=\"415\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/ruben-deadcatx3.png\" width=\"746\"\/><\/p>\n<p class=\"wp-caption-text\" id=\"caption-attachment-74167\">The HackerOne profile for \u201cRuben Thomson\u201d uses the nickname Deadcatx3, which multiple security firms have concluded is an alias used by TeamPCP. Image credit: flare.io.<\/p>\n<\/div>\n<h2>INTERVIEW WITH ELLIS<\/h2>\n<p>In early July 2026, not long after having discovered clues about Ellis\u2019s real life identity, KrebsOnSecurity interviewed the TeamPCP leader via Signal, where he was remarkably open about his activities and personal struggles [for the sake of simplicity, the TeamPCP spokesperson will be referred to from here on as Ellis].<\/p>\n<p>Ellis claims he stopped doing cybercrime for TeamPCP in March 2026 \u2014 just before the attacks that compromised LiteLLM \u2014 and that at least one other individual has taken over the group\u2019s leadership since then. Ellis shared that a year earlier he had just completed the latest in a series of detox and sobriety programs, and was two months sober when he reconnected with some old friends from the malware development scene.<\/p>\n<p>\u201cOne year ago I needed help monetizing some [GitHub credentials], I was two months sober and needed a distraction and something to keep busy as well as people to speak to,\u201d Ellis said. \u201cI had largely disconnected from my old circle, they had become very toxic and I needed to get away from the substances. Previously I had done some mass exploitation campaigns and grew up doing [malware development] and [capture the flag] contests. There were some friends who were also vending but had stopped a while, and one of them introduced me to some chats where I posted access for sale.\u201d<\/p>\n<p>Prior to that, Ellis said, he was homeless and hopping between \u201csome very unstable places.\u201d<\/p>\n<p>\u201cBlackhatting is fun,\u201d he said. \u201cThere are actual rewards and incentives to learn and you grow with your team. Without qualifications, no employer will even take the time to hear you out.\u201d<\/p>\n<p>Ellis claims he\u2019s earned a grand total of about $20,000 for his activities with TeamPCP, and that it was never about the money or fame for him. Asked whether his experiences with TeamPCP might prepare him for gainful employment in a legitimate IT job, Ellis said he doubted it.<\/p>\n<p>\u201cI am nowhere close to a skill level where I am comfortable, and this would take maybe half a decade of further experience,\u201d he said. \u201cI no longer have to choose between rent and food for that I\u2019m grateful and so are the team members.\u201d<\/p>\n<p>Ellis expressed no remorse over his cybercrime activities, and said he was grateful for the friendships and relationships built throughout his engagement with TeamPCP. The young hacker also seemed resigned to his fate, and told KrebsOnSecurity that he\u2019ll accept the consequences if he\u2019s ever arrested.<\/p>\n<p>\u201cIf I\u2019ve already been found out then its out of my control, I\u2019ll make peace with that,\u201d he said. \u201cHonestly, I think someone like me needs a lot of help that prison just can\u2019t provide. If I had the funds to study different parts of the field and closer guidance, this would have turned out differently. But that\u2019s a pipe dream and we both know this.\u201d<\/p>\n<p>It is clear from reading Ellis\u2019s posts to the group\u2019s Matrix server chats that his struggles with sobriety are ongoing. On Thursday, June 25, Ellis told @kernelstub he was about to \u201ctrip\u201d with his \u201chomie.\u201d<\/p>\n<p>\u201cWhat kind,\u201d @kernelstub inquired.<\/p>\n<p>\u201cKetty and some DMT,\u201d Ellis replied, referring to the dissociative anesthetic <a href=\"https:\/\/en.wikipedia.org\/wiki\/Ketamine\" rel=\"noopener\" target=\"_blank\">ketamine<\/a> and <a href=\"https:\/\/en.wikipedia.org\/wiki\/Dimethyltryptamine\" rel=\"noopener\" target=\"_blank\">dimethyltryptamine<\/a> (DMT), a powerful psychedelic compound that is found naturally in some plants but is also synthetically produced in underground lab environments. \u201cThere\u2019s a little 2cb so we might throw that in the mix,\u201d he continued, referring to <a href=\"https:\/\/en.wikipedia.org\/wiki\/2C-B\" rel=\"noopener\" target=\"_blank\">another psychedelic compound<\/a> by its chemical shorthand.<\/p>\n<p>Roughly two weeks before his arrest, Ellis told KrebsOnSecurity he was ready to leave his life of crime behind and was prepared to turn himself in, but that in the meantime he was making plans to tie up loose ends.<\/p>\n<p>Less than 24 hours later, the TeamPCP leader posted an image on Telegram showing a yellowish powdered substance in a baggie and on a scale, possibly synthetic DMT. The image shows the powder being weighed next to a series of small vape cartridges, two of which are open on the table in front of the photographer.<\/p>\n<div class=\"wp-caption aligncenter\" id=\"attachment_74171\" style=\"width: 759px;\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" class=\"wp-image-74171\" height=\"412\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/teampcp-dmtmaybe.png\" width=\"749\"\/><\/p>\n<p class=\"wp-caption-text\" id=\"caption-attachment-74171\">An image posted by the TeamPCP leader to Telegram, advertising his acquisition of some type of psychoactive substance, most likely a synthetic version of the powerful hallucinogen known as DMT.<\/p>\n<\/div>\n<p>The two defendants were arrested Wednesday morning. The AFP said the men face a combined 14 cybercrime offenses and are scheduled to appear in Perth Magistrates Court today.<\/p>\n<p><strong>Charlie Eriksen<\/strong> is a security researcher at <strong>Aikido Security<\/strong> who has closely followed TeamPCP\u2019s cybercrime campaigns. Eriksen said TeamPCP are a good example of a new kind of threat actor that does not fit neatly into the usual categories.<\/p>\n<p>\u201cThey are not a state actor, not quite organized cybercrime, and not purely ideological,\u201d he said. \u201cTheir motivations seem to mix money, disruption, attention, and ideology.\u201d<\/p>\n<p>Eriksen said that historically there has always been a meaningful gap between reading about an attack technique and being able to reliably turn it into an operational campaign, but that large language models (LLMs) and artificial intelligence increasingly are helping threat actors to bypass that knowledge gap.<\/p>\n<p>\u201cYou had to understand the research, adapt the code, troubleshoot it, build infrastructure around it, and then repeat that process across different targets,\u201d he said. \u201cLLMs have compressed that gap significantly.\u201d<\/p>\n<p>According to Eriksen, this creates an environment where threat actors suddenly have the ability to operate at significant scale without having developed the operational discipline that traditionally accompanies that level of capability. Put another way, it sets the stage for cybercriminals who are capable enough to cause significant damage, but not necessarily careful enough to understand or care about the consequences.<\/p>\n<p>\u201cThey can be noisy, they can make mistakes,\u201d he said. \u201cThey can leave evidence everywhere. They can take risks that a professional criminal group or intelligence service would consider completely unacceptable. But that does not necessarily make them less dangerous. In some ways, it can make them more dangerous.\u201d<\/p>\n<p>In a recent <a href=\"https:\/\/www.aikido.dev\/blog\/shai-hulud-trusted-publishing\" rel=\"noopener\" target=\"_blank\">blog post<\/a>, Eriksen called TeamPCP\u2019s Shai-Hulud worm the \u201cbest thing to happen to supply chain security,\u201d because it forced GitHub and other public coding platforms to erect new security safeguards.<\/p>\n<p>In direct response to TeamPCP\u2019s broad success at pushing poisoned versions of popular software packages, GitHub in late July introduced a <a href=\"https:\/\/github.blog\/security\/supply-chain-security\/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates\/\" rel=\"noopener\" target=\"_blank\">three-day \u201ccooldown\u201d mechanism<\/a> for Dependabot, the platform\u2019s tool for auto-fetching newly shipped updates for any package dependencies. Cooldown periods are designed to help buy time for security tools and package maintainers to identify and remove any compromised versions. Other coding ecosystems like Python and various JavaScript platforms <a href=\"https:\/\/cooldowns.dev\/\" rel=\"noopener\" target=\"_blank\">also added support<\/a> for cooldown periods this year amid growing calls from security experts about the need for more widespread adoption of the safety feature.<\/p>\n<p>Eriksen said TeamPCP\u2019s legacy is that they achieved in the span of a few months what the supply chain security community has been unable to do for years.<\/p>\n<p>\u201cThey managed to wake up Microsoft to the fact that they had become negligent in terms of security,\u201d Eriksen said. \u201cBy compromising GitHub and stealing their source code, they humiliated Microsoft into action, making them finally act on what we had been asking them to do and take seriously for a while now.\u201d<\/p>\n<p><strong>Update, 10:08 a.m. ET:<\/strong> A <a href=\"https:\/\/www.abc.net.au\/news\/2026-08-27\/two-wa-men-charged-after-investigation-into-alleged-cybercrime\/107084796\" rel=\"noopener\" target=\"_blank\">story<\/a> this morning from <strong>ABC News<\/strong> in Australia confirms Ruben Ian Thomson of Cottesloe was one of the two arrested. The 23-year-old suspect thought to be @pcpcasper, Michael Gaebler, also was arrested in Perth. ABC News reports that Thomson was denied bail (Mr. Gaebler\u2019s attorney reportedly did not request bail for his client), and that both men will be held in custody until their next court appearance on September 18.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever.<\/p>\n<p>In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a &#8220;sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.&#8221;<\/p>\n<p>The AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old suspect&#8217;s real identity in June, and has been communicating with him ever since. This story includes interviews with TeamPCP&#8217;s self-described spokesperson, and examines clues left behind by the TeamPCP leader that likely led to his undoing.<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10643,32701],"tags":[28477,16740,29556,32765,17600,30064,32743,32752,32720,32338,31554,32702,30119,32739,31556,28752,32753,32754,16695,32759,32721,32258,32722,17774,32103,24608,32766,32767,32768,32769,32744,32745,32708,32709,32746,32710,32711,32713,32723,11740,32714,31558,24613,32747,32724,32725,11638,32726,32740,11869,28567,31016,11863,32755,32715,21409,32716,31561,30434,22313,32104,19277,32105,14947,32770,32717,32106,32760,31895,32056,32748,32718,16888,32761,32703,32704,22255,32749,32712,16696,22836,32750,31157,31158,19013,32727,32771,32772,32728,32756,32705,31162,31163,32729,32741,32719,31164,31030,32706,3765,15227,22691,27009,32730,32731,32732,8223,32751,20501,17220,32733,32734,31492,32762,26016,32735,32736,20502,32737,17061,16936,11884,32763,31636,32742,31564,32707,32757,31911,17006,32764,32773,17091,32738,28020,32758],"class_list":["post-26114","post","type-post","status-publish","format-standard","hentry","category-independent","category-kreb","tag-1password","tag-a-little-sunshine","tag-action1","tag-active-directory-federation-services","tag-adblock","tag-adblock-plus","tag-afd-sys","tag-ai-digital-humans","tag-aikido-security","tag-alfa-bank","tag-andtop-company","tag-atlas-data-privacy","tag-automox","tag-between-digital","tag-bitseller-expert-limited","tag-bitsight","tag-bitsight-trace","tag-blockly","tag-breadcrumbs","tag-bright-data","tag-bulkdmt","tag-cameron-john-wagenius","tag-charlie-eriksen","tag-chris-goettl","tag-connor-riley-moucka","tag-constella-intelligence","tag-cve-2026-48561","tag-cve-2026-50661","tag-cve-2026-56155","tag-cve-2026-56164","tag-cve-2026-62832","tag-cve-2026-68820","tag-cve-2026-69730","tag-cve-2026-69829","tag-cve-2026-72971","tag-cve-2026-81963","tag-cve-2026-85880","tag-cybera","tag-cybercats","tag-data-breaches","tag-decryptads","tag-dmitry-lubarsky","tag-domaintools","tag-ed-skoudis","tag-ellis","tag-epieos","tag-exploit","tag-express","tag-fengwo-group","tag-flashpoint","tag-fortra","tag-gary-norden","tag-github","tag-h96","tag-hertz","tag-huawei","tag-idscan-net","tag-igor-lubarsky","tag-infoblox","tag-intel-471","tag-intelsecrets","tag-internet-of-things-iot","tag-irdev","tag-ivanti","tag-jack-bicer","tag-jillian-kossman","tag-john-erin-binns","tag-john-taylor","tag-judische","tag-justin-sherman","tag-landon-miles","tag-larry-baldwin","tag-latest-warnings","tag-lg-electronics-usa","tag-lifetime-value-company","tag-matt-adkisson","tag-microsoft-corp","tag-microsoft-patch-tuesday-august-2026","tag-microsoft-patch-tuesday-september-2026","tag-neer-do-well-news","tag-nexus","tag-nightmare-eclipse","tag-numberguru","tag-onerep","tag-opera","tag-opsec-express","tag-patch-tuesday-july-2026","tag-pavan-davuluri","tag-pcpcats","tag-pedro-fale","tag-pem-law","tag-peoplelooker","tag-peoplesmart","tag-persy_pcp","tag-pi-hole","tag-planet13","tag-radaris","tag-radaris-com","tag-raj-parikh","tag-ransomware","tag-raspberry-pi","tag-residential-proxies","tag-residential-proxy","tag-ruben-thomson","tag-rubensecurecomputing-au","tag-rubenthomson-com","tag-samsung","tag-sans-technology-institute","tag-satnam-narang","tag-security-tools","tag-sheepstealinggmail-com","tag-shitstickppgmail-com","tag-snowflake","tag-spur","tag-spycloud","tag-surfinup8gmail-com","tag-teampcp","tag-tenable","tag-tensor-industries","tag-the-coming-storm","tag-time-to-patch","tag-tizen","tag-trevor-sutter","tag-tyler-reguly","tag-ublock-origin","tag-val-gurvits","tag-victor-worms","tag-vivo","tag-waifu","tag-web-fraud-2-0","tag-webos","tag-windows-bitlocker","tag-xiaomi","tag-yolosolo17gmail-com","tag-zach-edwards","tag-zhejiang-fengwo-iot-technology-ltd"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26114","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=26114"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26114\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=26114"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=26114"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=26114"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}