Overview
- Police in Perth arrested and charged two Western Australian men following search warrants executed on Wednesday, and investigators seized devices and a large volume of data now under forensic examination.
- Authorities say the suspects face a combined 14 offences including unauthorised modification of data, possession and supply of data for computer offences, and dealing with proceeds of crime with some counts carrying penalties up to 20 years in prison.
- Officials estimate the campaign potentially hit more than 1,000 organisations worldwide, stole over 500,000 credentials, and exfiltrated at least 300 gigabytes of data, producing remediation costs measured in the hundreds of millions of dollars.
- Investigators say TeamPCP injected malicious code into trusted open‑source projects and developer workflows — using compromised publishing credentials and self‑replicating worms such as Mini Shai‑Hulud to harvest CI/CD and cloud secrets — and cryptocurrency payments to the suspects are being traced.
- The arrests follow months of private‑sector reporting and international cooperation between the AFP, Western Australia Police Force and the FBI; forensic review, financial tracing and victim notifications are ongoing and further arrests or charges have not been ruled out.