Australian authorities charged two Western Australian men on Aug. 26 following a joint investigation into the alleged TeamPCP cybercrime syndicate.

The Australian Federal Police filed a combined 14 charges against 21-year-old Ruben Ian Thomson and 23-year-old Louis Michael Gaebler. Both appeared before Perth Magistrates Court on Aug. 27, according to ABC.

The operation involved the AFP, the FBI and the Western Australia Police Force. Authorities executed warrants at properties in Cottesloe, Hamilton Hill and Mandurah.

Police allege the group compromised more than 1,000 organizations, obtained over 500,000 credentials and removed at least 300 gigabytes of data. The defendants have not been convicted, and the charges remain allegations.

A joint @FBI, @AusFedPolice and @WA_Police investigation has led to the arrest of two Western Australian men charged with allegedly hiding malicious code in open-source software, harvesting 500,000+ credentials and compromising 1,000+ organizations worldwide. A powerful example…

— U.S. Embassy Australia (@USEmbAustralia) August 31, 2026

TeamPCP allegedly targeted trusted software components

The joint investigation began in April after several cybersecurity companies supplied intelligence about malicious software distributed through an open-source repository, the AFP said in its official release.

Investigators allege TeamPCP inserted malicious code into legitimate software components used by other developers. Once incorporated into downstream systems, the modified code allegedly gave the group unauthorized access to organizations across government, academia and the private sector.

Software supply-chain attacks can spread beyond the organization hosting the original compromised code. A trusted component may be reused by hundreds of developers, allowing one modification to reach many unrelated systems.

Australian authorities estimated that responding organizations face remediation costs totaling hundreds of millions of dollars. That figure reflects an official estimate rather than a confirmed financial loss suffered by identified victims.

The AFP said infected software enabled the alleged theft of credentials, authentication materials and other sensitive information. However, authorities have not published a complete list of affected organizations or software packages.

Cryptocurrency payments remain under investigation

Police allege the two men were principal participants in the operation and received cryptocurrency for their roles. Authorities said the value of those payments remains under investigation.

The official release did not identify the cryptocurrencies involved. It also did not disclose wallet addresses, transaction hashes, mixers, exchanges or a confirmed laundering total.

Reports claiming that investigators seized large cryptocurrency balances or expensive property go beyond the details contained in the AFP announcement. Authorities said electronic devices and other items were seized, but they did not assign a digital-asset value to those items.

Thomson faces one Australian charge of dealing with money or property worth at least 100,000 Australian dollars that authorities allege represented criminal proceeds. The offence carries a maximum prison sentence of 20 years. That threshold describes the charge and does not establish the final amount involved.

Blockchain transactions can assist investigators when funds move through identifiable services or interact with regulated exchanges. As previously reported, Australian authorities forfeited nearly 25 Bitcoin and other assets tied to a 2013 exchange theft.

U.S. indictment creates a separate federal case

The U.S. Department of Justice separately unsealed a federal indictment against Thomson. Prosecutors charged him with conspiracy to violate the Computer Fraud and Abuse Act and obtaining information from a protected computer.

The American indictment concerns alleged TeamPCP attacks during spring 2026. Prosecutors claim malicious code scanned downstream systems, extracted sensitive information and maintained persistent access.

The Justice Department also alleges TeamPCP used stolen information to make ransom or extortion demands. Members allegedly offered not to publish victims’ data in exchange for payment. These claims have not been proven in court.

Each U.S. offence carries a maximum five-year prison term and a fine of up to $250,000, or twice the alleged gross gain or victim loss. Any sentence would be determined by a federal judge after a conviction.

The U.S. announcement names Thomson but does not announce a corresponding American indictment against Gaebler. Thomson remained in Australian custody when prosecutors disclosed the case.

U.S. agencies have previously targeted infrastructure allegedly used to convert cybercrime proceeds. In related coverage, the FBI seized nine cryptocurrency exchanges accused of laundering ransomware and investment-fraud proceeds.

Forensic examinations could produce further charges

The AFP said investigators are examining a large volume of seized data and electronic devices. That work may help authorities identify additional participants, victims and financial transfers.

Police have not ruled out further arrests or charges. They have also not announced whether the United States will seek Thomson’s extradition or wait for the Australian proceedings to advance.

The investigation’s next phase will involve digital forensics and the examination of cryptocurrency payment records. Prosecutors must separately prove each defendant’s identity, role, intent and connection to the alleged activity.

Potential victims should review software dependencies, rotate exposed credentials and examine authentication logs. Australian organizations can report incidents through Report Cyber, while individuals concerned about identity theft can contact IDCARE.

The case produced no verified cryptocurrency market reaction. It concerns the alleged use of digital assets for payments rather than a vulnerability in a blockchain or cryptocurrency protocol.