Two men from Western Australia have been charged following a joint investigation by the Australian Federal Police, the FBI, and the Western Australia Police Force into TeamPCP, a group accused of running the longest software supply-chain attack spree on record. A 21-year-old from Cottesloe faces seven charges, including possessing and supplying data to commit computer offences, four counts of unauthorized data modification, failing to comply with a data-access order, and dealing with proceeds of crime worth more than AU$100,000. A 23-year-old from Mandurah faces six related computer-offence charges. Both were arrested on August 26.

According to the AFP, malicious code distributed by TeamPCP potentially compromised more than 1,000 organizations worldwide, enabling theft of over 500,000 credentials and exfiltration of at least 300 gigabytes of data, with global remediation costs estimated in the hundreds of millions of dollars. “These men are members of TeamPCP, whose code potentially compromised over a thousand organizations worldwide,” said FBI Assistant Director Brett E. Leatherman. AFP Commander Graeme Marshall added: “Cybercrime syndicates are becoming increasingly organised and operate like professional businesses, but investigators are relentless in tracking down criminals.”

Why it matters: this is one of the few software supply-chain campaigns in recent memory to produce arrests rather than just an incident timeline. The investigation, which authorities say began in April 2026 after tips from multiple cybersecurity companies, took roughly four months to move from private-sector detection to criminal charges, fast by the standards of cross-border cybercrime cases and worth noting for teams who assume law enforcement engagement is a dead end.

The original insight: the case shows today’s most damaging supply-chain compromises increasingly trace back to individual actors exploiting open-source trust, not just nation-state units or ransomware affiliates. Two people, working through poisoned open-source packages, reportedly reached organizations as prominent as the European Commission, Mistral AI, OpenAI, and GitHub. That scale-to-headcount ratio is the real lesson: open-source dependency review needs to assume one motivated actor can reach nation-state-scale blast radius, and vet accordingly.

Source: Two WA men charged following AFP-FBI-WAPF disruption of alleged global cybercrime, Australian Federal Police