Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Friday tech news graphic — AFP charges two Perth men over TeamPCP supply chain cyberattacks

Two Perth Hackers Charged Over Global Supply Chain Attacks

The AFP and FBI have charged two Western Australian men over their alleged roles in TeamPCP, a cybercrime syndicate whose supply chain attacks compromised more than 1,000 organisations worldwide. The men — aged 21 and 23, from Cottesloe and Mandurah — appeared in Perth Magistrates Court on Wednesday facing a combined 14 charges including data intrusion, identity crime, and dealing in cryptocurrency proceeds worth at least $100,000.

What they allegedly did

TeamPCP inserted malicious code into trusted open-source software packages — tools like Trivy (a widely used vulnerability scanner) and LiteLLM (an AI gateway). Developers then unknowingly pulled that compromised code into their own systems, giving the syndicate backdoor access to government, academic, and private-sector networks across the globe. The AFP estimates the group stole more than 500,000 credentials and exfiltrated at least 300GB of data, with global remediation costs in the hundreds of millions.

Why this matters for your business

Supply chain attacks are a particular problem for small and mid-sized businesses. Larger organisations have security teams that audit software dependencies and monitor for tampered packages. Most SMBs don’t — they trust the software ecosystem to do that work for them. When that trust is broken, the breach often goes undetected for weeks. These aren’t theoretical risks. The tools TeamPCP allegedly compromised sit inside automated build pipelines used by thousands of businesses, including Australian ones.

What to do

Check with your IT provider that your endpoint detection and response (EDR) tools are active and current. If you’re still relying on traditional antivirus alone, it won’t catch this kind of attack. Make sure your team knows not to install unapproved software or browser extensions — that’s often how compromised packages find their way in. And if you don’t have visibility into what software your systems are actually running, that’s the gap to close first.

Need help reviewing your security posture? Talk to All IT about cybersecurity or get in touch.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →

Posted in Strategic