The Fall of TeamPCP.
On August 27, 2026, Australian and US authorities charged two Western Australian men with running the campaign this site has spent months tracking. Here's what we know, how they were found, and what's still open.
Two men, fourteen charges
On August 27, 2026, the Australian Federal Police, the FBI, and the Western Australia Police Force announced the arrest of two Western Australian men - a 21-year-old from Cottesloe and a 23-year-old from Mandurah - in connection with a “sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.” FBI Assistant Director Brett Leatherman put it plainly: “These men are allegedly members of the cybercriminal group TeamPCP.”
Between them, the AFP filed 14 charges. The 21-year-old faces eight: one count of possessing data with intent to commit a computer offence, four counts of unauthorised modification of data with intent to commit a serious offence, one count of supplying data with intent, one count of failing to comply with a section 3LA order, and one count of dealing with proceeds of crime exceeding $100,000 - that last charge alone carries a maximum 20-year sentence. The 23-year-old faces six charges from the same set, minus the proceeds-of-crime and non-compliance counts - a charge profile consistent with the first man holding the more central, financially exposed role. Both were denied bail. Investigators say the case began in April 2026.
ABC News Australia later reported a striking, so-far single-sourced detail: 100 terabytes already extracted from one of the searched addresses, “with more data expected.”
Two independent investigations, one name
Neither the AFP nor the FBI named the two men in their official statement. Both identities surfaced instead through independent journalism and threat-intel research - and notably, two separate investigations converged on the same answer without coordinating.
Brian Krebs (KrebsOnSecurity) had learned the 21-year-old's real identity back in June 2026 and had been communicating with him since over Signal, under the name “Ellis.” Krebs's own reporting traces a chain from reused email addresses (shitstickpp@gmail.com, surfinup8@gmail.com) across cybercrime forums, a Perth IP address tied to a family QNAP device, passive DNS records connecting that device to the Thomson family, a family Facebook profile, and a GitHub/HackerOne account publicly using the handle Deadcatx3.
Flare's Emerging Threats Team ran a separate deanonymization exercise, published the same day, starting from the same anchor alias - Deadcatx3 - and pivoting through a Hugging Face account (username “RT”), a TikTok video, and a Steam account with a VAC ban dated September 13, 2016. That exact ban date turns up independently in Krebs's own reporting too - two unrelated investigations landing on the identical piece of evidence is about as strong a corroboration signal as open-source investigation gets. Flare's chain also surfaced a domain, masscan.cloud, later confirmed as the command-and-control domain used during May's Mini Shai-Hulud worm infection.
Both chains name Ruben Ian Thomson, 21, of Cottesloe, Western Australia. ABC News Australia independently confirmed the name in its own same-day coverage - a third, unrelated confirmation. The alias cluster this site has tracked since the beginning - PCPcat, ShellForce, DeadCatx3, Persy_PCP - all converge on one person, along with a name we hadn't placed until now: T00001B, the spokesperson handle used in the earliest known on-record TeamPCP interview, given to Forbes on March 26, 2026 - five weeks before the Inside Darknet interview with the TeamPCP leader.
The second man, 23-year-old Louis Michael Gaebler, is linked to the X account @pcpcasper. Krebs's own sourcing on this identification was hedged (“thought to be”), resting substantially on a single unnamed source; ABC News Australia's independent, unhedged naming of both men in full is what moves this identification from tentative to confident.
“This was shown to us by a good partner... they have been teaching us a lot of about git exploitation.”
- the TeamPCP leader, May 9 2026, describing the original Aqua/Trivy access. We now know who said this. We still don't know who they were talking about.
What the agencies said
A name is one thing. Officials confirming it out loud is another - and once Thomson and Gaebler were in custody, three agencies were happy to go on record.
- AFP Commander Graeme Marshall: “It is rare to have cyber criminals of this status domestically.” “The men are internationally significant cybercrime threat actors.”
- FBI Assistant Legal Attaché Dave Andish: described the syndicate as “highly organised.”
- WA Police Force Acting Commander Peter Foley: “It shows the prevalence of cybercrime in our community and that cybercriminals live amongst us.”
- Prosecutor (per ABC News): described the pair as “masterminds,” with further charges considered likely.
The scale figures in the AFP's own release - 1,000+ organizations, 500,000+ harvested credentials, 300+ GB exfiltrated, remediation costs in the hundreds of millions - match the operator's own self-reported numbers from the May 9 interview almost exactly. That's most likely because the figures being cited are the same public reporting everyone else has been working from, not an independent law-enforcement measurement.
“I left in March”
The charges, the numbers, the officials' quotes - that's the clean version. Thomson's own account of himself complicates it.
In his Signal conversations with Krebs, Thomson claimed he stopped doing cybercrime for TeamPCP in March 2026, and that at least one other person took over the group's leadership after that. We're treating this claim with real skepticism rather than repeating it as fact. It arrived after his arrest, from someone with every incentive to minimize his own legal exposure - and March 2026 conveniently predates the entire April-through-June wave this site has spent the most space on: Mini Shai-Hulud, the AntV mass-republish, the Nx Console compromise that led into GitHub's own internal breach, and the June 1 Miasma compromise. If true, it would mean the person interviewed by Inside Darknet on May 9 either isn't Thomson, or Thomson is misrepresenting his own timeline. We have no independent way to adjudicate that.
Krebs adds one important caveat: from his Signal conversations and from the Cybercats chatter around Thomson, he came away thinking Thomson may really have stepped back from day-to-day leadership earlier in 2026, even if that does not mean he had stopped committing crimes or stopped being part of the ecosystem. In Krebs's read, Thomson looked less like someone still calmly directing every operation by the end, and more like someone spiraling, intermittently absent, and aware that his operational-security mistakes had caught up with him.
That matters less as mitigation than as explanation. In the Risky Business interview, Krebs describes Thomson as despondent, struggling with drug use, and motivated less by money or conventional cybercrime status than by distraction, community, and the rush of making something happen. Wilson notes that Thomson claimed to have made only about $20,000 from his TeamPCP involvement - a strangely small figure next to the scale of damage. None of that softens the harm. It does help explain why the group often looked unlike a disciplined ransomware crew: reckless, loud, technically dangerous, and weirdly indifferent to its own exposure.
One detail worth noting: George Prepakis (@kernelstub), who administered the Cybercats chat server TeamPCP used and spoke with Thomson by video call shortly before he turned himself in, posted a farewell message the same day describing it as a voluntary surrender - not simply a raid. “TeamPCP turned himself in,” he wrote, adding a screenshot from the call. Whether that changes how “left in March” should be read - preparation for exactly this moment, or an unrelated claim - isn't something we can settle from the outside.

The rest of the story keeps moving
Two men were charged. The ecosystem around them wasn't arrested with them.
Box turtle (@xploitrsturtle2), the public-facing xploitrs operator, was not one of the two men arrested. His own account confirmed this directly the following day: “To clear the air, yes they were arrested... miss you, #teamPCP” - written entirely as an outside party, not a participant.

George Prepakis (@kernelstub), who administers the infrastructure TeamPCP used for internal coordination, explicitly disclaims involvement in cybercrime himself and was not charged.
Krebs also surfaced a second, later ShinyHunters wrinkle. The earlier story was that ShinyHunters scammed TeamPCP through the Vect operator chat and used TeamPCP-sourced credentials in at least one misattributed breach. In the Risky Business interview, Krebs says ShinyHunters later went further: they compromised TeamPCP itself, accessed internal conversations and stolen material, and shared some of it with law enforcement and researchers. According to Krebs, the access path began when a TeamPCP-linked actor known as “Pricks” invited a ShinyHunters member into the group.
Separately, and unaffected by any of this: the TeamPCP-derived Miasma operators - the distinct group that built its own operational toolkit on top of TeamPCP's open-sourced code and ran the June 1 Red Hat compromise, the June 5 Microsoft 73-repo takedown, and the Hades PyPI wave - are a separate operation with no known connection to these arrests. See the full story and the cast page for that thread.
Whether TeamPCP itself continues to operate under new leadership - as Thomson himself claims - is unverified. Krebs's reporting names several other individuals as still active within the broader Cybercats ecosystem, none of whom have been charged as of this writing.
Sources
On the record throughout: the AFP's own media release, independent investigations from Brian Krebs and Flare's Emerging Threats Team, ABC News Australia, and TeamPCP's own March interview with Forbes.
AFP media releaseKrebs on SecurityFlare (deanonymization)ABC News AustraliaForbes (Mar 26 interview)Risky Biz / Krebs interviewTeamPCP's story. Allegedly.