THREAT OPS › Threat News › Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
<p>Authorities in Australia have arrested two men believed to be members of <strong>TeamPCP</strong>, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever.</p> <p>In <a href="https://www.afp.gov.au/news-centre/media-release/two-wa-men-charged-following-afp-fbi-wapf-disruption-alleged-global" rel="noopener" target="_b
MITRE ATT&CK techniques
- Artificial IntelligenceT1588.007
- IP AddressesT1590.005
- JavaScriptT1059.007
- Virtual Private ServerT1584.003
- Email AddressesT1589.002
- Code RepositoriesT1593.003
- Virtual Private ServerT1583.003
- Social MediaT1593.001
- CredentialsT1589.001
- Code RepositoriesT1213.003
- Software ToolsAML.T0016.001
- Code RepositoriesAML.T0095.000
Indicators of compromise
- https://www.afp.gov.au/news-centre/media-release/two-wa-men-charged-following-afp-fbi-wapf-disruption-alleged-globalurl
- https://www.wired.com/story/teampcp-software-supply-chain-attack-spree-github/url
- https://www.dataminr.com/resources/cyber-intel-deep-dive-teampcp-shai-hulud-3-0/url
- https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines#url
- https://www.pbs.org/newshour/world/a-hillside-of-white-crosses-fuels-a-misleading-story-about-south-africas-farm-killingsurl
- https://docs.domaintools.com/iris/investigate/data-panels/pdns/url
- https://web.archive.org/web/*/https://github.com/XmasSnow*url
- https://www.tiktok.com/@user7508029790800url
- https://connectonline.asic.gov.au/RegistrySearch/faces/landing/bySearchId.jspx?searchIdType=BUSN&searchId=698546137url
- https://connectonline.asic.gov.au/RegistrySearch/faces/landing/bySearchId.jspx?searchIdType=BUSN&searchId=684301513url
- https://labs.cloudsecurityalliance.org/research/csa-research-note-teampcp-multi-ecosystem-supply-chain-20260/url
- https://www.aikido.dev/blog/shai-hulud-trusted-publishingurl
- https://github.blog/security/supply-chain-security/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates/url
- https://cooldowns.dev/url
- shitstickpp@gmail.comemail
- joshua@thomson.org.auemail
- ruben@thomson.org.auemail
- yolosolo17@gmail.comemail
- surfinup8@gmail.comemail
- sheepstealing@gmail.comemail
- ian@thomsonfamily.net.auemail
- jasper@yakuza.ccemail
- rubenthomson1@gmail.comemail
- ruben@securecomputing.auemail
- 211.27.196.111ipv4
- 110.141.230.15ipv4
- ke-la.comdomain
- joshuawthomson39.myqnapcloud.comdomain
- kwe.comdomain
- rubenthomson.comdomain
- upwork.comdomain
- flare.iodomain
Original source: https://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in-australia/
Same event, other sources
- Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacksthehackernews · 2026-08-27
- Australia arrests alleged TeamPCP hackers behind supply-chain attacksbleepingcomputer · 2026-08-27