Australian authorities have arrested and charged two young men accused of taking part in TeamPCP, a hacking group linked to a series of developer supply-chain attacks, according to BleepingComputer. The suspects, aged 21 and 23, were arrested on August 26, 2026, in Cottesloe and Mandurah in Western Australia. BleepingComputer reports that the case involves attacks on open-source software and developer platforms, where malicious code was injected into trusted software components. Developers then allegedly pulled those components into their own applications, extending the reach of the compromise into systems used by government, academic, and private-sector organizations. According to BleepingComputer, TeamPCP has been associated with attacks affecting Trivy, LiteLLM, Telnyx, SAP, and TanStack packages. The report also says the group has breached the European Commission, Mistral AI, OpenAI, and GitHub. The provided material does not detail each incident, but it frames the activity as part of a broader campaign against developer infrastructure and software supply chains. The scale alleged by law enforcement is significant. BleepingComputer, citing the Australian Federal Police, the FBI, and Western Australia Police, reports that malicious code distributed by TeamPCP may have compromised more than 1,000 organizations worldwide. Authorities also say the activity enabled theft of roughly 500,000 credentials and exfiltration of at least 300GB of data. The investigation began in April 2026 after the AFP and FBI received information from cybersecurity firms, according to the report. During the arrests, investigators seized electronic devices and other evidence for forensic analysis. Police also allege the two men received cryptocurrency payments for their involvement in TeamPCP operations, though the amount was not disclosed. BleepingComputer describes TeamPCP less as a formal organization than a loose collective of actors who frequent overlapping hacking forums, Discord servers, and Telegram channels. That distinction matters for enforcement: a loose network can make attribution and charging more complex, but it can also leave investigators with reused aliases, accounts, and other online traces. The two suspects face a combined 14 charges, including allegations related to possessing and supplying data for computer offenses and modifying data to facilitate serious crimes. The younger suspect also faces charges tied to allegedly dealing with at least $100,000 in criminal proceeds and failing to comply with an order requiring access to electronic data. BleepingComputer reports that the charges carry maximum penalties ranging from 3 to 20 years’ imprisonment per charge. The Australian Federal Police has not ruled out further arrests or charges while it examines seized evidence, according to BleepingComputer. For now, the case is an early but notable law-enforcement response to a class of attacks that targets the software components developers trust rather than only the end systems organizations defend. Who benefits: Law enforcement and incident-response teams benefit if seized devices and account traces help map TeamPCP-linked activity. Organizations already investigating affected software components may also gain clearer attribution and indicators as the case develops. Who's exposed: Organizations that used compromised open-source or developer-platform components are exposed to credential theft and data exfiltration risk. The provided reporting names several affected projects and organizations but does not identify the full list of potentially compromised victims.