Threat Intelligence

Two Australians Charged Over Alleged TeamPCP Supply Chain Hacking Attacks

The Hacker News · 27 Aug 2026
Key Takeaway Regularly update software from trusted sources and monitor vendor security advisories, since even security tools themselves can be compromised in supply chain attacks.

The Australian Federal Police (AFP) has charged two men from Western Australia over their alleged roles in TeamPCP, a cybercrime group linked to the compromise of widely used open-source security scanners Trivy and Checkmarx KICS, as well as the AI gateway LiteLLM. Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, face a combined 14 charges and appeared before Perth Magistrates Court on August 27.

The alleged attacks targeted software supply chain tools that many organisations, including security teams, rely on to scan code and infrastructure for vulnerabilities. Compromising such tools can be particularly damaging, as it may allow attackers to insert malicious code that spreads to every business using the affected software.

While the case is still before the courts, it highlights the growing risk posed by supply chain attacks, where hackers target trusted software providers rather than individual businesses directly. For Australian SMBs that rely on third-party tools and open-source software, this case is a reminder that even reputable security products can become an attack vector.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.