1 day ago
Australian Police Charge Two Men in Open-Source Software Hacking Case
Australian police accused two men of helping a hacking group called TeamPCP.
The group allegedly placed harmful computer code inside widely used open-source software tools.
Businesses using those tools may have been exposed to hackers.
Police said more than 1,000 organizations could have been affected.
They also said more than 500,000 passwords or other credentials and over 300 gigabytes of data may have been stolen.
Some businesses were reportedly threatened for money afterward.
The FBI helped Australian authorities investigate the case.
The men have been charged, but the allegations have not been proven in court.
Australian police charged two men over alleged involvement in TeamPCP, a cybercrime collective targeting open-source software.
Authorities allege malicious code in popular tools potentially compromised more than 1,000 organizations worldwide.
Police said the activity enabled the theft of more than 500,000 credentials and over 300 gigabytes of data.
The Australian Federal Police investigated the case with the FBI after receiving information from cybersecurity threat assessment companies.
A U.S. indictment separately charged Ruben Ian Thomson with alleged computer fraud and obtaining information from a protected computer.
- Who
- Australian police accused Ruben Ian Thomson and Louis Michael Gaebler of alleged involvement in TeamPCP; the FBI assisted the investigation.
- What
- The men face a combined 14 Australian charges related to alleged hacking of open-source software and a wider U.S. indictment against Thomson.
- Where
- The arrests and Australian charges occurred in Australia, while the alleged cybercrime affected organizations globally and Thomson faces a U.S. case in Northern California.
- When
- Australian police announced the charges on Thursday, August 27; the joint investigation began in April, and an FBI advisory was issued in July.
- Why
- Authorities allege TeamPCP inserted malicious code into popular software to compromise businesses, steal data and credentials, and in some cases extort victims.
Authorities' allegations
Defense position
Responsibility for the alleged hacking
Authorities' allegations
Australian and U.S. authorities allege that Thomson and Gaebler participated in TeamPCP, which inserted malicious code into widely used open-source tools and compromised businesses.
Defense position
The accused men's attorneys declined to comment, so no detailed defense position was publicly provided in the report.
Nature of TeamPCP
Authorities' allegations
Authorities describe TeamPCP as a hacking collective involved in software supply-chain attacks and later extortion of some businesses.
Defense position
Google Threat Intelligence Group analyst Austin Larsen characterized TeamPCP as a peer community of individually skilled actors with a center of gravity, rather than a single unified group.
Key facts
- Accused
- Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, according to the Australian Broadcasting Corporation.
- Australian charges
- The men face a combined 14 charges over their alleged roles in TeamPCP.
- Potential reach
- More than 1,000 organizations worldwide may have been compromised.
- Data allegedly stolen
- More than 500,000 credentials and over 300 gigabytes of data.
- Investigation
- The Australian Federal Police and FBI began a parallel investigation in April after receiving information from multiple cybersecurity threat assessment companies.
- U.S. case
- Thomson was separately indicted in the Northern District of California on alleged conspiracy and computer-related offenses.
- Threat actor description
- Google Threat Intelligence Group analyst Austin Larsen described TeamPCP as a community of individually skilled actors rather than one unified group.
Quotes
Brett Leatherman
Assistant director of the FBI Cyber Division
“We are proud to work with the Australian Federal Police and the Western Australia Police Force to impose cost on criminal actors and combat the growing threat of software supply-chain attacks”
theprint.in









