Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
Overview
The Australian Federal Police have charged two young men, Louis Michael Gaebler and Ruben Ian Thomson, for their alleged involvement with TeamPCP, a cybercrime group responsible for significant supply chain attacks. Notably, this group compromised several open-source security tools, including Trivy and Checkmarx KICS, as well as the AI gateway LiteLLM in March 2026. The charges include a total of 14 offences, reflecting the severity of their actions in the cybersecurity realm. This incident raises concerns about the security of widely-used software tools and the potential impacts on organizations relying on these technologies for security assessments. As the case unfolds, it highlights the ongoing challenges posed by cybercriminals targeting supply chains.
Key Takeaways
- Affected Systems: Trivy, Checkmarx KICS, LiteLLM
- Timeline: Ongoing since March 2026
Original Article Summary
The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences over their alleged role in TeamPCP, the cybercrime group behind the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS and the AI gateway LiteLLM. Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, appeared in Perth Magistrates Court on August 27,
Impact
Trivy, Checkmarx KICS, LiteLLM
Exploitation Status
The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.
Timeline
Ongoing since March 2026
Remediation
Not specified
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.