{
  "id": 3755863,
  "title": "Australian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and others",
  "url": "https://urgent.news/2026/08/27/australian-police-arrest-two-over-teampcp-hacks-targeting-mercor",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-27T14:27:52.000Z",
  "source": {
    "name": "TechCrunch",
    "slug": "techcrunch",
    "url": "https://techcrunch.com/2026/08/27/australian-police-arrest-two-over-teampcp-hacks-targeting-mercor-openai-and-others/"
  },
  "original_language": "en",
  "account": "Australian authorities have apprehended two individuals in Perth, suspected members of the hacking group known as TeamPCP. The two have been charged with over a dozen cybercrime offenses, including hacking, money laundering, and other illicit activities. They are set to appear in court later on Thursday. According to the Australian Federal Police, the duo is accused of carrying out widespread breaches targeting popular open-source projects. The hackers aimed to infect numerous computers to steal credentials and data, subsequently demanding ransoms from victims. The FBI's cyber division chief, Brett Leatherman, revealed that the alleged members of TeamPCP are accused of hacking into over a thousand organizations as part of their attacks. It remains unclear whether the Justice Department intends to pursue extradition proceedings, and an FBI spokesperson declined to comment at the time of this report. TeamPCP is a notorious cybercriminal gang, infamous for several high-profile hacking campaigns targeting the software supply chain. The group infiltrates and maliciously alters widely-used open-source software tools, often compromising the private keys and sensitive credentials of thousands of companies and developers. The authorities reported that the hackers had stolen more than half a million credentials, facilitating further attacks on other companies. The hackers are believed to have breached the European Commission's cloud infrastructure, as well as numerous open-source projects and developer applications linked to tech giants like GitHub and OpenAI. Australian officials stated that their investigation commenced in April 2026 following tips from various cybersecurity firms. The identities of the arrested men have not been disclosed. However, independent cybersecurity journalist Brian Krebs exclusively reported that one of the arrested hackers is Ruben Thomson, known by the hacker handle Ellis. Krebs, who has been in contact with Ellis over the past few months, disclosed that Ellis identified himself as the leader of TeamPCP until March 2026. Krebs learned of Ellis' true identity due to errors made by the hacker, which inadvertently revealed his real name. During a press conference on Wednesday, Australian officials announced the arrests and mentioned the seizure of a large quantity of allegedly stolen data, as well as electronic devices from the hackers. They also announced their intention to notify affected parties of the attacks.",
  "summary": "The arrests come after a wave of cyberattacks earlier this year targeting tech companies that rely on high-profile and widely used open source software.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}