Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
Australian Federal Police charges two men with 14 offences over TeamPCP supply chain backdoors in Trivy, Checkmarx KICS, and LiteLLM affecting 1,000+ organizations.
The Australian Federal Police charged two Western Australian men, aged 21 and 23, with 14 offences for their alleged principal roles in TeamPCP's March 2026 supply chain attacks; they appeared in Perth Magistrates Court on August 27, 2026. The group stole publishing credentials from trusted open-source projects and pushed poisoned releases across five ecosystems - GitHub Actions, Docker Hub, npm, PyPI, and OpenVSX - with LiteLLM's unpinned Trivy install enabling token theft and backdoored LiteLLM releases. The FBI said the malicious code potentially compromised more than 1,000 organizations, enabled theft of over 500,000 credentials, and exfiltrated at least 300 GB of data. Oligo Security linked the group's infrastructure to activity back to 2020, previously tracked as TA-NATALSTATUS and IronErn.
Georgia man charged for robbing NBA, NFL players through stolen Apple account details
Georgia man Kwamaine Jerell Ford charged with phishing NBA and NFL players' Apple accounts, making over 2,000 fraudulent transactions, and sex trafficking counts.
Kwamaine Jerell Ford, 34, was arrested and pleaded not guilty to dozens of counts including wire fraud, computer fraud, aggravated identity theft, access device fraud, and sex trafficking. He posed as an adult film actress offering explicit videos, then as Apple customer support to harvest usernames, passwords, and MFA codes from professional athletes, gaining access to their credit and debit cards and making more than 2,000 transactions including fund transfers and DoorDash orders. Prosecutors say he ran the scheme while on probation for a similar 2019 phishing offense in which he spent nearly $325,000 of stolen funds, and also coerced a woman into sex with players, filmed encounters without consent, and hacked one athlete's home security cameras. He was held without bail.
Risky Bulletin: Two TeamPCP members arrested in Australia
Australian Federal Police arrested two alleged TeamPCP members behind supply-chain worm attacks that stole over 500,000 credentials from compromised open-source libraries.
The AFP arrested alleged TeamPCP leader Ruben Thomson, 21, and Louis Gaebler, 23, near Perth; both were charged and remain in custody. The group inserted a self-spreading credential-stealing worm into open-source projects including Trivy, KICS, LiteLLM, and Telnyx, harvesting more than 500,000 credentials used for network access, ransomware, extortion, and sales. About 78,000 tokens and secrets from nearly 2,200 organizations leaked online last month, and the FBI supported the investigation that began in April.
Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly
US prosecutors charged Indian national Jay Goswami as a money mule who collected $7.5 million from nine elderly scam victims, now facing extradition from Canada.
US prosecutors charged 21-year-old Indian national Jay Sunilbharthi Goswami with wire fraud and money laundering for working as a money mule for India-based scammers. The scammers posed as law enforcement or government officials by phone and email, convincing at least nine elderly victims in New York and New Jersey to hand over $7,559,185 in cash, gold bars, and gift cards. Goswami collected the money and shipped it to India, allegedly earning about $90,000 while on a student visa at Fairleigh Dickinson University. After fleeing to Canada across the Peace Bridge, he was arrested at Toronto's airport and is awaiting extradition to the US.