Two Western Australian men charged in international cybercrime supply-chain attack

Investigators say the compromised open-source software affected more than 1,000 organisations globally, with more than 500,000 credentials stolen and at least 300GB of data exfiltrated.
Louis Gaebler and Ruben Thomson, aged 23 and 21, are the two Western Australian men charged; FBI officials have described Thomson as the leader of the TeamPCP group.
Authorities allege the group tampered with software updates for widely used development tools, enabling the malware to spread via trusted open-source components.
Parallel investigations into the alleged supply-chain attack began in April 2026 after information provided by multiple cyber threat assessment firms.
The two WA men are charged with a combined total of 14 offences in relation to the alleged cybercrime operation.
Australian police and the FBI have charged two Western Australian men — Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23 — for their alleged roles in TeamPCP, a global cybercrime group that inserted malicious code into widely used open-source software. According to Cybernews, the compromised software affected more than 1,000 organisations worldwide, with attackers stealing over 500,000 credentials and exfiltrating at least 300GB of data.
The joint AFP, WA Police, and FBI investigation began in April 2026 after cybersecurity firms detected the supply-chain attack. Bleeping Computer reports that the two men face a combined 14 charges related to the operation, which allowed the group to access sensitive systems across government, academia, and the private sector.
TeamPCP tampered with updates for widely used developer tools, embedding malware into trusted open-source components. Security Week explains that this method allowed the malicious code to spread automatically to thousands of organisations that relied on these tools without knowing they had been compromised.
The attack gave the group access to credentials and data across multiple sectors. Global remediation costs are running into hundreds of millions of dollars as affected organisations work to patch systems and secure their networks.
Investigators conducted raids on residences in Cottesloe, Hamilton Hill, and Mandurah in Western Australia. Cybernews reports that the arrests came after multiple cyber threat assessment firms tipped off authorities to the suspicious activity in the supply-chain attack.
Thomson and Gaebler allegedly received cryptocurrency payments to help cover their tracks during the operation. The two men are scheduled to appear in Perth Magistrates Court as authorities pursue the case.
The investigation represents a significant multinational law-enforcement collaboration. Oz Arab Media notes that the Australian Federal Police, WA Police, and FBI worked together on parallel investigations to build charges against the two suspects.
FBI officials have described Thomson as the leader of the TeamPCP group. The case highlights growing efforts by international agencies to prosecute cybercriminals who target critical infrastructure and private organisations through supply-chain vulnerabilities.
Publishers
20
Articles
12
Reach
32