IndiaFocal.

India, in focus.

World

Representative image · Photo: cms.therecord.media
Representative image · Photo: cms.therecord.media

Australia arrests two men over global open-source software hacking spree

Australian police arrested two men accused of hacking open-source software, compromising over 1,000 organisations and stealing 500,000 credentials.

Australian police have arrested two men accused of being part of a cybercrime syndicate that targeted widely used open-source software, compromising thousands of businesses globally. The Australian Federal Police (AFP) announced the charges on Thursday, stating the two men face a combined 14 charges for their alleged roles in the hacking collective known as TeamPCP.

The syndicate is accused of inserting malicious code into popular open-source tools, which were then used to compromise businesses. According to a July FBI advisory, some of the affected businesses were later extorted. The AFP said the malicious code potentially compromised more than 1,000 organisations worldwide, leading to the theft of over 500,000 credentials and more than 300 gigabytes of data.

The police did not name the men, but the Australian Broadcasting Corporation identified them as Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23. Paul Holmes, Thomson's current attorney, declined to comment, as did James Gatti, Gaebler's attorney.

The investigation was conducted in parallel with the FBI, beginning in April after the AFP received information from unnamed cybersecurity threat assessment companies. FBI Cyber Division Assistant Director Brett Leatherman praised the collaboration, saying, "We are proud to work with the Australian Federal Police and the Western Australia Police Force to impose cost on criminal actors and combat the growing threat of software supply-chain attacks."

Late Thursday, the U.S. Attorney's Office for the Northern District of California announced a separate U.S. indictment against Thomson on charges of conspiracy to commit Computer Fraud and Abuse Act violations and obtaining information from a protected computer.

Austin Larsen, a principal threat analyst with Google Threat Intelligence Group, described TeamPCP as "one of the most impactful threat actors of 2026" and characterised the group as a "peer community of individually skilled actors with one clear center of gravity," rather than a single, unified organisation.