← Back to blog

TeamPCP Arrests: How Operational Security Failures Ended a Supply Chain Crime Spree

TeamPCP Arrests: How Operational Security Failures Ended a Supply Chain Crime Spree

ARRESTS: The Australian Federal Police, Federal Bureau of Investigation (FBI), and Western Australia Police Force have charged two alleged members of TeamPCP (tracked by GTIG as UNC6780) following a joint investigation into the group’s global supply chain attacks.

TeamPCP has been one of the most impactful threat actors of 2026. Their self-propagating Shai-Hulud worm poisoned hundreds of open source packages, and authorities estimate their campaigns compromised more than 1,000 organizations, exposed over 500,000 credentials, and stole at least 300 GB of data, with global remediation costs in the hundreds of millions.

But for all the impact, this group was identified several times over through their own operational security failures. As I told KrebsOnSecurity, TeamPCP is not a criminal group with a single operator. It is a peer community of individually skilled actors with one clear center of gravity. Today’s charges target two key participants in that community, but authorities have said the investigation is ongoing and further arrests have not been ruled out.

This disruption is also a model of public-private partnership. The AFP specifically credited information from multiple threat intelligence companies as crucial to the investigation. Sharing what we see with law enforcement works.

Two men, aged 21 and 23, now face a combined 14 charges with more likely to come. Actions have consequences, and they compound faster than most young threat actors expect.

If you want more of the story, I’ll be presenting “The Spice Must Not Flow: Disrupting TeamPCP’s Mini Shai-Hulud Campaign” at the final LABScon in September, going behind the scenes on how we frustrated their operations and unmasked key operators months before today’s arrests.


AFP media release: https://www.afp.gov.au/news-centre/media-release/two-wa-men-charged-following-afp-fbi-wapf-disruption-alleged-global

KrebsOnSecurity reporting: https://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in-australia/


Originally posted on LinkedIn