Industry News

Two Australian Men Arrested Over 'TeamPCP' Software Supply Chain Attacks

Krebs on Security · 27 Aug 2026
Key Takeaway Regularly review and vet the third-party and open-source software your business relies on, since attackers increasingly target trusted supply chains rather than businesses directly.

The Australian Federal Police (AFP) has arrested two men, aged 21 and 23, from Western Australia in connection with TeamPCP, a cybercrime group accused of creating malicious open-source software packages to defraud thousands of businesses worldwide. The AFP described the group as a "sophisticated cybercrime syndicate" and said the arrests followed an investigation into software supply chain attacks—incidents where hackers insert malicious code into trusted software components that many other businesses rely on.

Software supply chain attacks are particularly dangerous because they exploit trust: a business may unknowingly install compromised code through a legitimate-looking update or open-source library, giving attackers a foothold without ever directly targeting the victim. These attacks can spread widely and quickly, affecting any organisation that uses the tainted software.

While the AFP did not publicly name the suspects, the case highlights the growing risk small and medium businesses face from compromised software dependencies, even when they have no direct connection to the attackers. As more businesses rely on third-party and open-source tools, verifying the integrity of software suppliers has become an essential part of basic cybersecurity hygiene.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from Krebs on Security. We link back to every original so you can read it yourself.