Full Report
Two West Australian men have been charged following a joint investigation between the AFP and Western Australia Police Force (WAPF), working in parallel with the Federal Bureau of Investigation (FBI), into a sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses. It is estimated the malicious code potentially compromised more than 1000 organisations globally, enabling the theft of more than 500,000 credentials, and the exfiltration of at least 300 gigabytes of data. “These men are allegedly members of the cybercriminal group TeamPCP, whose malicious code potentially compromised more than a thousand organizations worldwide,” Assistant Director Leatherman said.
Analysis Summary
# Incident Report: Disruption of TeamPCP Global Software Supply Chain Attack
## Executive Summary
Two Western Australian men, allegedly members of the cybercriminal group "TeamPCP," were arrested following a joint investigation by the AFP, FBI, and WAPF. The syndicate executed a sophisticated supply chain attack by inserting malicious code into open-source software repositories, impacting over 1,000 organizations globally. The operation resulted in the theft of 500,000+ credentials and 300GB of data, with global remediation costs estimated in the hundreds of millions of dollars.
## Incident Details
- **Discovery Date:** April 2026
- **Incident Date:** Ongoing until August 26, 2026
- **Affected Organization:** 1,000+ global organizations (Government, Academia, Private Sector)
- **Sector:** Cross-sector (Supply Chain)
- **Geography:** Global impact; suspects based in Western Australia (Cottesloe and Mandurah)
## Timeline of Events
### Initial Access
- **Date/Time:** Pre-April 2026
- **Vector:** Software Supply Chain Compromise
- **Details:** The syndicate inserted malicious code into software available on open-source repositories. This code was then unwittingly integrated by third-party developers into broader enterprise systems.
### Lateral Movement
- **Details:** The malicious software components enabled the syndicate to infiltrate host organizations, allowing them to move from the application layer into the broader network environment to harvest sensitive data.
### Data Exfiltration/Impact
- **Details:** At least 300 gigabytes of data were exfiltrated. The attackers successfully harvested over 500,000 user credentials and authentication materials.
### Detection & Response
- **April 2026:** AFP and FBI received intelligence from multiple cyber threat assessment companies regarding the malicious open-source code.
- **August 26, 2026:** AFP and WAPF executed search warrants in Cottesloe, Hamilton Hill, and Mandurah.
- **August 27, 2026:** Two primary suspects (ages 21 and 23) appeared in Perth Magistrates Court.
## Attack Methodology
- **Initial Access:** Supply chain attack via poisoned open-source repositories.
- **Persistence:** Implementation of malicious code within "trusted" software components.
- **Privilege Escalation:** Not explicitly detailed, but involved unauthorized modification of data to commit serious offences.
- **Defense Evasion:** Use of legitimate open-source channels to bypass perimeter security.
- **Credential Access:** Harvesting of 500,000+ user credentials and authentication materials.
- **Discovery:** Identifying organizations using the compromised open-source components.
- **Lateral Movement:** Infiltration of computer systems via the infected software backdoor.
- **Collection:** Gathering of sensitive data including identities and organizational files.
- **Exfiltration:** Transfer of 300GB of data; payments received via cryptocurrency.
- **Impact:** Financial loss (remediation costs), data theft, and unauthorized data modification.
## Impact Assessment
- **Financial:** Global remediation costs estimated at hundreds of millions of dollars; suspects received illicit cryptocurrency payments.
- **Data Breach:** 300GB of data stolen; 500,000+ credentials compromised.
- **Operational:** Significant disruption to over 1,000 organizations across government and private sectors.
- **Reputational:** High impact on the perceived security of the open-source software ecosystem.
## Indicators of Compromise
- **Network indicators:** None listed in the public report (e.g., C2 IPs or domains).
- **File indicators:** Malicious code snippets inserted into open-source repositories (specific filenames not disclosed).
- **Behavioral indicators:** Unusual outbound traffic to unknown destinations from servers running specific open-source components; unauthorized account access using stolen credentials.
## Response Actions
- **Containment:** Coordinated international law enforcement disruption (AFP/FBI/WAPF).
- **Eradication:** Identification and removal of malicious code from the open-source repository.
- **Recovery:** Global remediation efforts by affected organizations to rotate credentials and scrub systems.
## Lessons Learned
- **Key Takeaways:** Even a small number of "trusted" open-source components can serve as a massive force multiplier for cybercriminals.
- **Systemic Vulnerability:** Lack of rigorous vetting for open-source dependencies in the development lifecycle allows for large-scale supply chain poisoning.
## Recommendations
- **Software Composition Analysis (SCA):** Implement tools to scan all open-source dependencies for known vulnerabilities and malicious code.
- **Zero Trust Architecture:** Do not inherently trust internal applications; monitor their behavior for unauthorized data access or outbound connections.
- **Credential Hygiene:** Use strong, unique passphrases and mandate Multi-Factor Authentication (MFA) to mitigate the impact of stolen credentials.
- **Vendor Risk Management:** Verify the security posture of third-party developers and the provenance of the code used in enterprise environments.