The Anatomy of a Supply Chain Collapse: How TeamPCP’s Reckless Cybercrime Spree Led to an International Sting

By Global Investigative Desk
Published: August 2026
In a coordinated international operation involving the Australian Federal Police (AFP), the Federal Bureau of Investigation (FBI), and the Western Australia Police Force, authorities have successfully apprehended two men believed to be the driving force behind TeamPCP. Recognized as one of the most prolific and disruptive data extortion syndicates in recent memory, the group is accused of executing the longest-running and most structurally damaging software supply chain attack spree in digital history.

According to official statements released by the AFP, the suspects—identified locally as 21-year-old Ruben Ian Thomson and 23-year-old Michael Gaebler, both hailing from the affluent coastal suburb of Cottesloe in Western Australia—were taken into custody during morning raids. The two men face a combined 14 serious cybercrime offenses. Their arrest marks a definitive turning point in a high-stakes, multi-agency manhunt that exposed the vulnerabilities sitting at the very foundation of the global software development ecosystem.
Main Facts: The Rise and Fall of TeamPCP
TeamPCP burst onto the international cybercrime landscape in late 2025, operating less like a traditional, highly regimented criminal cartel and more like a fluid federation of rogue threat actors. Rather than relying on ransomware encryption of traditional corporate databases, TeamPCP perfected the art of software supply chain poisoning. By compromising open-source repositories and development environments, they forced poisoned code downstream, affecting thousands of enterprise organizations worldwide.

The syndicate’s hallmark weapon was Shai-Hulud, a self-propagating worm designed to infiltrate corporate cloud architectures. By compromising developer credentials via targeted phishing campaigns on public repositories like GitHub and NPM, the group embedded malicious payloads into widely used software libraries. This created a parasitic cycle: developers downloaded trusted tools, unknowingly infected their own workstations, and inadvertently built malware into the very software they were developing for downstream enterprise clients.
The human element behind this massive technological disruption, however, was characterized by a profound lack of operational security (OPSEC). Driven by brash public taunts, internal hubris, and struggles with substance abuse, the leaders of TeamPCP left a digital paper trail so comprehensive that it allowed independent investigative journalists and threat intelligence firms to unmask them long before federal law enforcement made their move.

Chronology of an Escalating Campaign
The trajectory of TeamPCP’s operations highlights how rapidly modern threat actors can scale their impact using automated tools and artificial intelligence:
- Late 2025: TeamPCP emerges, introducing the Shai-Hulud worm and embedding malicious payloads into hundreds of open-source software packages to extort corporate victims.
- September 2025: Key members, operating under aliases like BulkDMT and Express, actively peddle stolen data—including 14 gigabytes harvested from South Africa’s State Information Technology Agency—while boasting about their exploits on underground forums like Breachforums and Darkforums.
- March 2026: TeamPCP executes its most audacious strike, compromising LiteLLM, an open-source AI gateway connecting users to over 100 large language models. Cloud security firm CloudSEK later estimates this breach harvested sensitive API and cloud service keys from more than 2,500 organizations, including major global technology firms.
- May 2026: TeamPCP claims credit for infiltrating over 3,800 code repositories at Microsoft-owned GitHub after a developer fell victim to a compromised browser extension. Concurrently, the group launches a twisted gamified recruitment drive—offering a $1,000 Monero prize to whoever could compromise the most download-heavy open-source packages using Shai-Hulud v3.0 code.
- June to July 2026: Security researchers map the digital footprints of key identities, linking forum aliases to real-world infrastructure in Perth, Australia. Concurrently, core organizers set up the "Cybercats" Matrix chat server, where cross-gang collaboration is openly discussed.
- August 2026: Joint international law enforcement sweeps execute raids in Western Australia, resulting in the arrest of Thomson and Gaebler. Both are denied bail and remanded in custody.
Supporting Data and the Digital Paper Trail
The undoing of TeamPCP serves as a masterclass in how poor operational security and digital oversharing can neutralize even the most technically sophisticated hackers. Security firms including Intel 471, SpyCloud, Flashpoint, and independent investigators systematically untangled the web of aliases used by the group’s central figure, Ruben Thomson.

The Alias Matrix
Thomson operated under a dizzying array of handles across various underground ecosystems:
- Darkforums & Breachstars: EllisD25, LSD, and BulkDMT (also known as the administrator of "DMT Host," a virtual private server rental operation).
- Breachforums: Express, registering initially with the email address
[email protected]. - HackerOne: In a staggering display of poor OPSEC, Thomson registered a bug bounty account in June 2025 under his real name, using the username Deadcatx3—an explicit moniker previously flagged by security researchers as a core TeamPCP alias.
- Corporate Incorporation: Australian business records reveal Thomson incorporated multiple local entities, including Secure Computing Solutions, Tensor Industries, and OPSEC Express—ironically naming a commercial enterprise after the very security discipline he utterly failed to practice.
The Human Element: Substance and Sympathy
Interviews conducted with Ellis (Thomson) via encrypted messaging platforms prior to his arrest revealed a deeply troubled individual. Claiming he netted a modest $20,000 total from his cybercrime activities, Thomson openly discussed his battles with severe methamphetamine, ketamine, and synthetic DMT addiction. His digital communications frequently alternated between boasting of high-tech enterprise compromises and lamenting his personal isolation and financial instability.

Fellow administrator Michael Gaebler, operating under the alias @pcpcasper, similarly compromised his anonymity. Through geotagged cat videos shared on Telegram and extensive message histories, investigators traced his affiliations to extreme political groups and localized Perth infrastructure, sealing the fate of the duo.
Official Responses and Industry Fallout
The arrest of the two Western Australian men drew sharp reactions from cybersecurity authorities and private sector intelligence groups worldwide.

In a joint media release, the Australian Federal Police underscored the borderless nature of modern cybercrime syndicates and praised the cross-continental cooperation that enabled the dismantling of the syndicate. "These arrests send a clear message that geographical boundaries do not shield cybercriminals from international law enforcement," an AFP spokesperson noted.
Industry analysts have been quick to point out the broader lessons of the TeamPCP saga. Charlie Eriksen, a security researcher at Aikido Security, highlighted that TeamPCP represents an entirely new breed of threat actor. "They are not a state actor, not quite organized cybercrime, and not purely ideological," Eriksen observed. "Their motivations mix money, disruption, attention, and ideology."

Furthermore, Eriksen noted that the accessibility of modern artificial intelligence and large language models has drastically compressed the "knowledge gap" for aspiring hackers. Threat actors can now scale operations rapidly without necessarily cultivating the deep operational discipline or institutional caution historically exhibited by elite APT (Advanced Persistent Threat) groups or professional cybercrime syndicates.
Long-Term Implications for Software Supply Chain Security
Paradoxically, security experts argue that TeamPCP may have inadvertently cured some of the structural negligence plaguing modern software development ecosystems. By weaponizing trusted repositories on an unprecedented scale, the group forced a reluctant tech industry to implement long-overdue safety rails.

In direct response to the chaos sown by the Shai-Hulud worm, Microsoft-owned GitHub instituted a mandatory three-day "cooldown" period for Dependabot in late July, buying critical time for security maintainers to vet and intercept compromised package updates before they propagate across enterprise pipelines. Similar cooldown mechanisms have since been adopted across Python and JavaScript packaging registries.
"TeamPCP achieved in the span of a few months what the supply chain security community has been trying to do for years," Eriksen remarked. "By aggressively compromising GitHub and exposing systemic vulnerabilities, they humiliated Microsoft and major tech giants into taking supply chain hygiene seriously."

As Ruben Thomson and Michael Gaebler sit behind bars awaiting their next court appearance on September 18, the digital ecosystem they disrupted continues to adapt. TeamPCP’s legacy will not be remembered for the millions they allegedly extorted, but as the chaotic catalyst that forced the global software industry to finally lock its front door.
