Skip to content
Bellator Cyber Guard
News7 min readStandard

Australia, US Arrest Two Alleged TeamPCP Hackers

Australian and US authorities charged two alleged TeamPCP hackers linked to a data extortion and software supply chain cybercrime probe.

By Bellator Cyber Guard Security Team

Two Men Arrested Over Alleged TeamPCP Hacking Operations

Australian and United States law enforcement agencies say they have identified and charged two Western Australian men in connection with TeamPCP, a cybercrime group blamed for a series of network intrusions and data extortion campaigns. According to reporting corroborated across multiple outlets, the Australian Federal Police (AFP), Australia's federal law enforcement agency responsible for investigating serious and organized crime, arrested the men, ages 21 and 23, in Perth this week following a joint investigation with the U.S. Federal Bureau of Investigation (FBI). One of the men has been named in reporting as Ruben Thomson, who was arrested and charged this week over his alleged role with TeamPCP.

TeamPCP is described in the reporting as a cybercrime and data extortion group, meaning members allegedly breach corporate or organizational networks, steal data, and then threaten to publish or sell it unless the victim pays. Authorities have not publicly released a full list of victims, and as of this writing the men face charges rather than convictions, the specific allegations against them are still working through the Australian court system. Some reporting described the pair as alleged "masterminds" of a "sophisticated cybercrime syndicate," a characterization attributed to investigators and not yet tested in court.

A Possible Software Supply Chain Angle

At least one security researcher who tracks extortion groups linked TeamPCP's alleged activity to software supply chain compromise, a category of attack where criminals target the tools, code libraries, or vendors that other businesses depend on, rather than attacking a single organization directly. If accurate, that detail would make TeamPCP's alleged activity relevant well beyond any single victim, since a compromised software component or vendor relationship can expose every downstream customer that relies on it. This angle has not been confirmed in an official AFP or FBI statement referenced in current reporting, so readers should treat it as an unverified but credible lead rather than an established fact until authorities or court filings confirm it.

What is consistent across the available reporting is that this was a cross-border investigation: Australian police built the case with active assistance from the FBI, reflecting how data extortion crews increasingly operate across jurisdictions and target victims regardless of where the alleged operators are physically located. That international cooperation model, shared threat intelligence, coordinated evidence-gathering, and parallel charges, has become one of the primary tools law enforcement has for disrupting extortion groups that would otherwise operate with relative impunity from wherever their operators happen to live.

Key Takeaway

Two Western Australian men, ages 21 and 23, face charges over an alleged role in TeamPCP, a data extortion group investigated jointly by the AFP and FBI. The case remains an allegation, not a conviction, but it underscores that data extortion crews are increasingly pursued as organized, cross-border operations rather than isolated incidents.

What This Means For Your Business

Arrests like this one matter to Bellator Cyber Guard's readers, healthcare practices, tax and accounting firms, and small-business leaders, for two reasons. First, they confirm that data extortion remains an active criminal business model rather than a fading trend; groups get disrupted and are often replaced by successors who study what got the previous crew caught. Second, if the software supply chain link holds up, it's a reminder that your organization's exposure isn't limited to your own systems, it extends to every vendor, plugin, code library, and managed service provider you rely on.

  • Inventory your third-party dependencies. Know which vendors, software packages, and managed IT or billing providers have access to your systems or data, and confirm each one has a documented security posture.
  • Segment access and enforce least privilege. Limit what any single vendor account, employee login, or integration can reach, a compromise of one credential should not expose your entire patient, client, or financial database.
  • Maintain offline, tested backups. Extortion groups rely on victims having no clean recovery path; regularly tested, offline or immutable backups remove much of that leverage.
  • Require multi-factor authentication everywhere it's available, especially for remote access, email, and vendor portals that touch sensitive records, since most intrusions that lead to extortion still begin with a stolen or guessed credential.
  • Have a written incident response and breach-notification plan that names who you'd call, legal counsel, an incident response firm, and relevant regulators, before an incident happens, not during one. Healthcare practices should map this to HIPAA breach-notification obligations; tax professionals should reference the safeguards outlined in IRS Publication 4557.

Regardless of how the TeamPCP case resolves in court, the operational lesson holds: extortion crews target opportunity, not size. A documented, tested set of access controls and backups remains the most reliable defense available to small and mid-sized organizations today.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

People also look for

Keep exploring Security basics

Start with the fundamentals, understand the most likely risks, and choose the next improvement without getting lost in jargon.

Learn first. Decide when you are ready.

Keep learning—or apply this to your situation

Continue with a related guide, compare your options, or ask a specialist to help turn the advice into a practical next step.