Australia ransomware and cyber extortion policy

The TeamPCP Arrests Show Australia's Cyber Strategy Working Where Its Mandatory Reporting Law Cannot Reach

Two Perth men accused of running a global supply-chain hacking syndicate expose the limits of ransomware-payment reporting law and the case for cross-border enforcement.

TeamPCP by the Numbers People of Internet Research · Australia 1,000+ Organisations compromised Global organisations allegedly hit… 500,000+ Credentials stolen Corporate credentials allegedly ha… 72 hours Ransomware payment reporting window Deadline for reporting entities to… AU$3M+ Reporting turnover threshold Annual turnover above which busine… peopleofinternet.com
TeamPCP by the Numbers People of Internet Research · Australia 1,000+ Organisations compromised 500,000+ Credentials stolen 72 hours Ransomware payment reportin… AU$3M+ Reporting turnover thresho… peopleofinternet.com

Key Takeaways

A domestic syndicate with a global blast radius

On 26 August 2026, the Australian Federal Police, the Western Australia Police Force and the FBI charged two Perth men — Ruben Ian Thomson, 21, of Cottesloe, and Louis Michael Gaebler, 23, of Mandurah — with a combined 14 offences over their alleged leadership of TeamPCP, a syndicate accused of embedding malicious code inside widely used open-source developer tools (AFP media release). Investigators say the group compromised more than 1,000 organisations worldwide, exfiltrated at least 300 gigabytes of data and harvested over 500,000 corporate credentials from compromised CI/CD pipelines, with global remediation costs estimated in the hundreds of millions of dollars (AFP; ABC News). Search warrants executed at three WA properties yielded roughly 100 terabytes of seized data. Both men were refused bail; a magistrate cited concerns Thomson could tamper with evidence.

The alleged method is the part that should worry every CISO reading this: TeamPCP didn't phish individual victims one at a time. According to reporting on the case, the group poisoned packages tied to tools like Aqua Security's Trivy, Checkmarx's KICS and the PyPI package LiteLLM, then used a self-propagating worm to automate credential theft across package registries at scale — funnelling stolen infrastructure secrets and cloud keys onward to ransomware and extortion operators (SecurityWeek). One compromise, distributed through trusted software supply chains, became a force multiplier against a thousand-plus downstream victims who never chose to work with TeamPCP at all.

Why the reporting law doesn't touch this

Australia's principal legislative response to ransomware, the Cyber Security Act 2024, requires businesses turning over more than A$3 million a year — plus critical infrastructure operators regardless of size — to report any ransomware or cyber extortion payment to the Australian Signals Directorate within 72 hours of paying, with civil penalties of up to 60 penalty units (A$19,800) for non-compliance (Cyber Security Act 2024, Part 3, s.27; MinterEllison). That law has a real justification: government cannot design a national ransomware response, or credibly claim the extortion economy is shrinking, if it cannot see how many organisations are paying and how much is flowing to criminal wallets. Visibility is a legitimate precondition for policy.

But TeamPCP's alleged operation sits upstream of that law entirely. The victims here are the thousand-plus organisations whose CI/CD pipelines were quietly harvested — many of whom may not yet know they were touched, let alone have made an extortion payment that triggers a 72-hour reporting clock. A disclosure regime built around the moment of payment cannot detect, prevent, or unwind a supply-chain compromise that operates through trusted infrastructure long before any ransom note appears. The AFP-FBI case for TeamPCP wasn't built from mandatory payment reports; it was built from a joint investigation that began in April 2026 after multiple cyber threat assessment firms flagged the malicious packages.

The case for tighter supply-chain rules — and why prosecution beats it here

The strongest argument for going further than reporting is real: open-source registries like PyPI and npm have essentially no gatekeeping, and a single maintainer account takeover can propagate to tens of thousands of downstream projects before anyone notices. Proposals for mandatory software bills of materials, stricter package-registry identity verification, and liability exposure for registries that fail basic scanning are not fringe ideas — the EU's Cyber Resilience Act already moves in this direction for products with digital elements. Reasonable people can argue Australia should legislate something similar rather than rely on voluntary hygiene from an ecosystem it does not control.

But the TeamPCP case is itself the argument against reaching for that lever first. What actually disrupted this syndicate was not a new compliance obligation on the open-source ecosystem — it was old-fashioned, resource-intensive, cross-border law enforcement: a joint AFP-FBI-WAPF taskforce, four months of investigation, and coordinated raids across three addresses. AFP Commander Graeme Marshall's framing — that "cybercrime syndicates are becoming increasingly organised and often operate like professional businesses" — is an argument for funding and empowering exactly that kind of taskforce work, not for imposing new registry-side mandates that raise the cost of publishing open-source software for the overwhelming majority of maintainers who are not TeamPCP. Regulation aimed at registries punishes volume; investigation aimed at named individuals punishes the actual conduct.

What should follow from here

The sensible next step is not a new Australian statute but scrutiny of enforcement capacity: whether the AFP's cybercrime units have the sustained funding to run more four-month, cross-agency investigations like this one, and whether the Cyber Security Act's 72-hour reporting data is actually being used to spot syndicate-level patterns — like a cluster of extortion payments tracing back to the same compromised package — rather than just accumulating in an ASD database. Software supply-chain security also improves fastest through targeted measures already underway, such as registry-level anomaly detection and faster maintainer identity checks at PyPI and npm, rather than blanket liability rules that would slow legitimate open-source publishing far more than they would slow the next TeamPCP. Two men facing 20-year maximum sentences is a better advertisement for Australia's current approach than any new reporting form would be.

Sources & Citations

  1. AFP: Two WA men charged following AFP-FBI-WAPF disruption of alleged global cybercrime syndicate
  2. Cyber Security Act 2024 (Cth), Federal Register of Legislation
  3. ABC News: Two Perth hackers charged after major AFP, FBI investigation
  4. MinterEllison: Mandatory ransomware payment reporting obligations in force
  5. SecurityWeek: Australia Arrests 2 Alleged TeamPCP Hackers