Skip to main content

Australian Police Arrest Two Alleged TeamPCP Hackers Targeting OpenAI and Mercor

28 AUGUST 2026·2 MIN READ·3 SOURCES·Trusted source

Australian authorities in Perth have arrested two individuals accused of operating with the hacking collective TeamPCP. The suspects face more than a dozen cybercrime and money laundering charges for allegedly breaching over 1,000 organizations.

Australian Police Arrest Two Alleged TeamPCP Hackers Targeting OpenAI and Mercor

Key takeaways · 3

  • 01

    Two suspects were arrested in Perth and face cybercrime and money laundering charges.

  • 02

    TeamPCP allegedly hacked over 1,000 organizations by compromising open-source supply chains.

  • 03

    The attackers stole more than 500,000 credentials to access cloud storage and customer data.

The Arrests and Allegations

Australian police in Perth have arrested two people accused of being members of the hacking group TeamPCP. [1] The two individuals are facing more than a dozen charges related to hacking, money laundering, and other cybercrime offenses. [1] FBI cyber division chief Brett Leatherman stated that the alleged hackers are accused of compromising more than 1,000 organizations. [1] It remains unclear if the United States Justice Department will seek extradition for the suspects. [1]

Supply Chain Attacks

The suspects allegedly participated in campaigns that tampered with popular open-source projects to steal credentials and extort victims for ransom. [1] Authorities claim the hackers stole more than half a million credentials, which were used to access cloud storage systems and sensitive customer data. [1] These campaigns reportedly affected infrastructure connected to companies including Mercor, OpenAI, GitHub, and the European Commission. [2] The group was also blamed for compromising the vulnerability scanner tool Trivy. [1]

What it means

The arrests highlight the growing vulnerability of the software supply chain, particularly regarding open-source tools relied upon by major technology developers. By successfully poisoning widespread projects like the vulnerability scanner Trivy, attackers can bypass traditional enterprise perimeters to access private keys and cloud storage environments. This incident echoes similar recent software supply chain compromises, emphasizing that integrating third-party code carries significant credential-theft risks for companies as large as OpenAI and GitHub. What the sources don't address: Whether law enforcement has successfully recovered the stolen data or if the compromised credentials remain active threats in the wild.

The compromise of popular open-source software tools exposes severe vulnerabilities in the AI supply chain. This demonstrates that attackers are increasingly targeting foundational development infrastructure rather than individual enterprise perimeters.

Why it matters
Daily session

Turn this story into practical AI skill after launch.

Get the release link for daily sessions built around your role and industry.

Join the waitlist

How this developed

  1. 28 August 2026

    Australian Police Arrest Two Alleged TeamPCP Hackers Targeting OpenAI and Mercor

  2. 28 August 2026

    Event created from source cluster.

Sources

AI fluency, one session a day, built for your work.