๐Ÿ“… Friday, 4 September 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
Dua Pemuda Australia Curi 500.000 Kredensial Lewat Kode Terbuka - Kini Berhadapan dengan FBI dan Ancaman Ekstradisi

Two Young Australians Steal 500,000 Credentials via Open-Source Code - Now Face FBI and Extradition Threat

Two Western Australian men, Ruben Ian Thomson (21) and Louis Michael Gaebler (23), appeared in Perth Court on August 27, 2026, to face 14 combined charges. A day earlier, the Australian Federal Police (AFP) charged them based on a joint investigation with the FBI into the operations of the TeamPCP cybercrime syndicate. Authorities allege the group breached more than 1,000 organizations and stole 500,000 login credentials worldwide.

The syndicate did not directly hack their targets’ servers. Instead, they deployed supply-chain attack tactics by inserting malicious code into open-source software components. When other developers used those components to build applications, access pathways to their systems opened automatically. This infection method spread across government sectors, academic institutions, and private companies, siphoning off at least 300 gigabytes of data.

Stolen Data Exchanged for Crypto

The United States Department of Justice (DOJ) stated that TeamPCP used the stash of stolen data for extortion. They contacted victims demanding ransoms, promising not to publish internal information if payments were made. In return for their participation in the group, both defendants received payments in crypto assets. The exact figure of their illicit earnings remains under investigation.

The losses suffered by victims far exceeded the ransom amounts. Police estimate remediation costs to repair systems across affected organizations reached hundreds of millions of Australian dollars. The investigation has been underway since April 2026, beginning when several cybersecurity firms provided intelligence regarding malware activity in open-source repositories.

Extradition Threat and Hundreds of Thousands in Fines

Legal proceedings for Thomson have now expanded beyond Australian borders. The DOJ unsealed a special federal indictment against the 21-year-old for conspiracy to violate the Computer Fraud and Abuse Act. He is also charged with unauthorized harvesting of information from protected computers. Each charge carries a potential penalty of five years in prison plus a maximum fine of $250,000.

When the DOJ announced the indictment, Thomson remained in Australian police custody, and no official decision has been made regarding potential extradition to the United States. Despite involving crypto flows as compensation for the hackers, the incident did not trigger any price reaction in digital asset markets. Their criminal activity was purely an application code exploit, not a vulnerability in blockchain network systems.

TeamPCP’s attack pattern highlights a critical vulnerability in the modern software industry. When developers rely on third-party code without strict verification, a single small flaw can expose thousands of organizations to multimillion-dollar extortion.

Reported by crypto.news.

Read also: Polygon Patches Critical Flaws via Two Secret Hard Forks - POL Token Up 44% in Past Month


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share