Australian authorities have charged two men from Western Australia after a joint investigation into the alleged TeamPCP cybercrime syndicate, in a case that also involves the FBI and U.S. prosecutors. The charges were announced after warrants were carried out at properties in Cottesloe, Hamilton Hill and Mandurah.

Police allege the group compromised more than 1,000 organizations, obtained over 500,000 credentials and removed at least 300 gigabytes of data by placing malicious code inside software components used by other developers. The men have been charged, but the allegations have not been proven in court.

Probe began after industry intelligence

According to the Australian Federal Police, the investigation started in April after several cybersecurity companies provided intelligence about malicious software being distributed through an open-source repository. The operation brought together the AFP, the FBI and the Western Australia Police Force.

Investigators allege TeamPCP tampered with legitimate open-source components that were later integrated into downstream systems. Authorities say that once the altered code was adopted, it gave the group unauthorized access to organizations in government, academia and the private sector.

Claims of widespread access and heavy cleanup costs

Police say the infected software was used to steal credentials, authentication materials and other sensitive information. Authorities have not released a full list of affected organizations or identified all of the software packages involved.

Australian officials estimate the cost of remediation for impacted organizations could reach hundreds of millions of dollars. That figure is an official estimate tied to response and cleanup efforts, rather than a confirmed tally of proven victim losses.

Crypto-linked allegations and separate U.S. case

Authorities allege the two men were principal participants in the operation and received cryptocurrency in connection with their roles. Police said the value of those payments is still being investigated, and the official announcements did not identify the tokens involved or provide wallet addresses, transaction records, exchanges or a confirmed laundering amount.

One of the accused, Thomson, also faces an Australian charge of dealing with money or property worth at least A$100,000 that authorities allege represented criminal proceeds. The charge carries a maximum sentence of 20 years, although the threshold cited in the charge does not establish a final amount.

In the United States, the Justice Department has separately unsealed an indictment against Thomson, accusing him of conspiracy to violate the Computer Fraud and Abuse Act and obtaining information from a protected computer. U.S. prosecutors say the alleged TeamPCP attacks took place during spring 2026 and involved code that scanned downstream systems, extracted information and maintained persistent access. They also allege stolen data was used in ransom or extortion demands, claims that likewise remain unproven.

What comes next

The AFP said investigators are now reviewing a large volume of seized data and electronic devices. That forensic work could help authorities identify more participants, victims and financial transfers, and police have not ruled out additional arrests or charges.

Authorities also have not said whether the United States will seek Thomson’s extradition or wait for the Australian case to progress first. For now, the next confirmed phase is further digital forensics, including examination of alleged cryptocurrency payment records, while prosecutors in each jurisdiction work to prove the defendants’ identities, roles and intent.

Source: crypto.news