WA men accused of targeting global businesses as part of ‘TeamPCP’ hacking syndicate
Two West Australian men are accused of being the “principal participants” in an international cybercriminal group that allegedly stole data from more than half a million users worldwide.
Louis Gaebler and Ruben Thomson appeared in Perth Magistrates Court on Thursday, charged over their alleged roles an international cybercrime syndicate that allegedly stole data from more than 1000 global organisations.
The men, aged 23 and 21, respectively, were arrested and charged on Wednesday after a four-month investigation by international agencies, following raids on homes in the Perth suburbs of Cottesloe, Hamilton Hill and the town of Mandurah throughout the day.
Police allege the two men were “principal participants” in the activities, and received payments in cryptocurrency to help cover their tracks.
The investigation was sparked in April, after a number of cybersecurity companies tipped off both the Australian Federal Police and the US Federal Bureau of Investigations about a potential malicious actor they had encountered.
The cybersecurity companies said the syndicate would allegedly insert malicious code into software available on an open-source repository – a space where code is stored and developed online – which was then unwittingly used by developers.
The malicious code would then infect and distribute across software in various organisations, including government systems, academia and private businesses.
Speaking to media on Thursday afternoon, FBI Assistant Law Enforcement Attaché Dave Andish alleged Thomson was the leader of the cybercriminal group TeamPCP, which was behind the malicious code that had potentially targeted thousands of organisation worldwide.
Andish said the searches on Thomson and Gaebler’s homes followed a “large-scale software supply chain attack” allegedly launched by TeamPCP in March.
“The group tampered with software updates for widely used development tools, hiding malicious code and routine downloads,” he said.
“Those updates installed malware that gave the group access to developer environments and other systems.”
Police alleged the hacking resulted in a theft of more than 500,000 credentials and was believed to have caused hundreds of millions of dollars in damage.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.smh.com.au — the content belongs to Sydney Morning Herald - National.