Australian Authorities Arrest Alleged TeamPCP Hackers in Supply-Chain Attack Crackdown
AFP charges two young men over developer supply chain attacks linked to TeamPCP; investigation ongoing

Key Takeaways
- Australian Federal Police have arrested and charged two individuals alleged to be members of the TeamPCP hacking group.
- TeamPCP is suspected of conducting supply chain attacks targeting Python packages and developer environments.
- The arrests are part of an ongoing investigation into developer supply chain security.
- The full extent of attacks, specific victims, and exploitation methods remain unconfirmed and under investigation.
Quick answers
- What happened?
- Australian Federal Police have arrested and charged two unnamed young men accused of belonging to TeamPCP, a hacking group implicated in supply-chain attacks targeting Python packages and developer environments. The operation marks a significant law enforcement action against the group, though the full scope of alleged attacks and victim impact remains under investigation.
- What should defenders do?
- Organizations should review Python package dependencies, verify package integrity, monitor development environments for indicators of compromise, and maintain up-to-date security controls for software supply chains.
Australian authorities have arrested and charged two young men accused of belonging to TeamPCP, a hacking group linked to a string of far-reaching developer supply chain attacks. The Australian Federal Police (AFP) announced the arrests, which target alleged members of the group held responsible for compromising Python packages and development environments. The operation aims to disrupt TeamPCP's activities and stem further supply-chain intrusions targeting the software development community. Details regarding the specific attacks, the number of victims, and the extent of the compromise are still emerging, with investigators noting that the full scope of damage and exploitation methods remain under active review. The arrests signal increased international focus on securing the software supply chain against threat actors targeting developer tools and dependencies.
Security Details
Alleged supply chain attacks via compromised Python packages and development tools; specific exploitation methods and victim details remain under investigation by Australian Federal Police.
Mitigation
Organizations should review Python package dependencies, verify package integrity, monitor development environments for indicators of compromise, and maintain up-to-date security controls for software supply chains.
Sources
BleepingComputer
Australia arrests alleged TeamPCP hackers behind supply-chain attacks
Aug 27, 2026 · 13:31
Original link
Related Security News

FBI Warns ShinyHunters Members Following Dutch Police Arrest of Alleged Leader
The FBI has issued warnings to members of the ShinyHunters extortion group, urging them to turn themselves in following the arrest of an alleged leader by Dutch police. The operation marks a coordinated law enforcement effort to disrupt the group's activities.

Dutch Police Confirm Arrest of 24-Year-Old in ShinyHunters Investigation
Dutch authorities have confirmed the arrest of a 24-year-old man from Amsterdam in connection with an investigation targeting the ShinyHunters hacking group. The operation forms part of broader law enforcement efforts to disrupt the threat actor's activities, though specific details regarding the evidence or the suspect's alleged role remain under investigation.



