Australian Police Arrest Two Suspected TeamPCP Hackers Behind Attacks on OpenAI, Mercor, and More

Australian police have arrested two individuals in Perth, accusing them of being members of TeamPCP, a prolific hacking group linked to a series of high-profile cyberattacks against major technology companies in recent months. The two suspects face more than a dozen charges, including hacking, money laundering, and other cybercrime offenses, and are scheduled to appear in court later on Thursday. According to a statement from the Australian Federal Police (AFP), the men are accused of orchestrating widespread breaches that involved compromising and tampering with popular open-source projects. Their alleged goal was to infect a large number of computers to steal credentials and sensitive data, then extort victims for ransom payments. FBI Cyber Division Chief Brett Leatherman stated that the two alleged TeamPCP members are accused of hacking into over a thousand organizations as part of their operations. It remains unclear whether the U.S. Department of Justice will seek extradition, and an FBI spokesperson did not immediately respond to requests for comment from TechCrunch. TeamPCP is a notorious cybercriminal group known for multiple large-scale campaigns targeting the software supply chain. The gang would break into open-source tools widely used by thousands of companies, maliciously modifying the software to embed backdoors or credential-stealing code. Once installed on a developer's or company's system, the malicious code would pilfer private keys and other sensitive credentials, often granting access to cloud storage and customer data. Authorities report that the hackers stole more than half a million credentials to further infiltrate other organizations. The group has been blamed for a cyberattack on the widely used vulnerability scanner Trivy, which impacted companies relying on it, including LiteLLM and AI recruiting startup Mercor. TeamPCP is also suspected of breaching the European Commission's cloud infrastructure, as well as targeting other open-source projects and developer applications that provided access to tech giants like GitHub and OpenAI. The arrests, made in collaboration with the FBI and the Western Australian Police Force, mark a significant step in disrupting a global cybercrime network. As the investigation continues, industry experts emphasize the importance of robust supply chain security practices and vigilant monitoring of open-source dependencies.

via TechCrunch

Related