Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
- ID
- 18612
- Status
- summarized
- Published
- 27 Aug 2026, 7:56 PM
- Fetched
- 27 Aug 2026, 10:41 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/08/alleged-teampcp-hackers-charged-in.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 6.5
- Created
- 27 Aug 2026, 10:42 PM
- Tags
- Audience
- developersai_agent_userssaas_founders
What happened
Australian Federal Police charged two Western Australian men, Louis Michael Gaebler (23) and Ruben Ian Thomson (21), with 14 offences over their alleged role in TeamPCP, the group behind the March 2026 supply-chain compromise of open-source security scanners Trivy and Checkmarx KICS and the AI gateway LiteLLM. The FBI's July 2 advisory warns that over 1,000 organizations may be affected and urges rotating all CI/CD secrets, publishing tokens, and cloud credentials exposed during the compromise window, as exfiltrated data remains a persistent risk.
Why it matters
If your team runs LiteLLM as an AI gateway or uses Trivy/Checkmarx KICS in CI pipelines and pulled updates around March 2026, you should rotate every CI/CD secret, publishing token, and cloud credential that was accessible during that window—the FBI explicitly states affiliated threat actors will weaponize exfiltrated credentials long after the initial compromise.
Discussion angle
How many teams in the community actually pin and verify the integrity of dependencies like LiteLLM and Trivy in their CI pipelines, and what's the practical checklist for rotating secrets after a confirmed supply-chain exposure window?