Australian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and others

Summarized from techcrunch.com


Australian police have arrested two individuals in Perth, accused of being members of the hacking group TeamPCP, which has been linked to high-profile cyberattacks against major technology companies. The two suspects face charges including hacking, money laundering, and other cybercrime offenses, with a court appearance scheduled for Thursday. According to the Australian Federal Police, the men are alleged to have conducted widespread breaches involving the compromise and tampering of popular open-source projects, with the intent to infect numerous computers, steal credentials and data, and extort victims for ransom.

The FBI’s cyber division chief, Brett Leatherman, stated that the alleged TeamPCP members are accused of hacking into over a thousand organizations. TeamPCP is described as a prolific cybercriminal gang known for targeting the software supply chain by maliciously modifying popular open-source software tools used by potentially thousands of companies. Once installed, the malicious code steals private keys and sensitive credentials, granting access to cloud storage systems and customer data. Authorities claim the hackers stole more than half a million credentials to facilitate further attacks on other companies. The group is implicated in attacks on the vulnerability scanner tool Trivy, affecting users such as LiteLLM and AI recruiting startup Mercor, as well as breaches of the European Commission’s cloud infrastructure and attempts to access platforms like GitHub and OpenAI. Australian officials initiated investigations in April 2026 following information from multiple cybersecurity companies and have seized a large quantity of allegedly stolen data, devices, and electronics from the suspects. Source