INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Australian Police Charge Two Over TeamPCP Credential Theft
| 2026-08-27 14:09 CRITICAL MEDIUM
Executive Summary
AI-generated
The Australian police have charged two men from Western Australia over a global cybercrime operation that allegedly hid malicious code in open-source software and used it to steal data from thousands of organisations. The FBI confirmed the involvement of the US agency, with charges brought against the suspects following joint investigations between the AFP and Western Australia Police Force into a sophisticated cybercrime syndicate working in parallel with the Federal Bureau of Investigation.
Technical Mitigations AI-generated
* Implement secure coding practices and use static analysis tools to detect potential vulnerabilities in open-source code.
* Use version control systems like Git with proper access controls and monitoring for suspicious activity.
* Regularly update and patch dependencies, libraries, and frameworks used in enterprise CI/CD pipelines and cloud infrastructure workflows.
* Conduct regular security audits and penetration testing on software applications and supply chains to identify potential entry points for malicious actors.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
TeamPCPTeamPCP
SANDCLOCKSANDCLOCKMini Shai-HuludMini Shai-HuludCanisterWormCanisterWorm
Target & Sectors
FIVE_EYES
FIVE_EYES
technologytechnology
Incident Timeline
March 2026
The Australian Federal Police charged two Western Australian men with TeamPCP credential theft.
Click on any entity below to view its context and source!
attribution
The Australian Federal Police
The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences over their alleged role in
TeamPCP
, the cybercrime group behind the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS and the AI gateway LiteLLM.
general_metric
14 offences
The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences over their alleged role in
TeamPCP
, the cybercrime group behind the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS and the AI gateway LiteLLM.
threat_actor
TeamPCP
The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences over their alleged role in
TeamPCP
, the cybercrime group behind the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS and the AI gateway LiteLLM.
April, 2026
The Australian Federal Police (AFP) and the FBI launched investigations into two individuals who allegedly stole credentials for TeamPCP users.
Click on any entity below to view its context and source!
attribution
AFP
“Parallel investigations started in April, 2026, after the AFP and FBI received information from multiple cyber threat assessment companies regarding a syndicate that allegedly inserted malicious code into software available on an open-source repository, which was then unwittingly used by other developers.” continues AFP.
attribution
FBI
“Parallel investigations started in April, 2026, after the AFP and FBI received information from multiple cyber threat assessment companies regarding a syndicate that allegedly inserted malicious code into software available on an open-source repository, which was then unwittingly used by other developers.” continues AFP.
May 12, 2026
The group used the Mini Shai-Hulud worm framework to open-source its code on GitHub.
Click on any entity below to view its context and source!
malware
Mini Shai-Hulud
The group open-sourced the worm framework used in
the Mini Shai-Hulud campaign
to GitHub on May 12, 2026.
organisation
GitHub
The group open-sourced the worm framework used in
the Mini Shai-Hulud campaign
to GitHub on May 12, 2026.
July 2
The Federal Bureau of Investigation (FBI) issued a July 2 advisory to affected organizations.
Click on any entity below to view its context and source!
attribution
the Federal Bureau of Investigation (FBI
The Federal Bureau of Investigation (FBI) said in a July 2 advisory that organizations impacted by the campaign should treat exfiltrated data and credentials as a persistent risk, since affiliated threat actors are "likely to weaponize them long after the initial compromise."
August 4, 2026
Threat actors used npm to compromise keyv and cacheable packages.
August 5
TeamPCP linked infrastructure was traced back to 2020 and tied to activity previously tracked as TA-NATALSTATUS through overlapping domains, malware deployment paths, staging techniques, and backend infrastructure.
Click on any entity below to view its context and source!
threat_actor
TeamPCP
TeamPCP-linked infrastructure has been
traced back to 2020
, Oligo Security said in an August 5 report, tying the group to activity previously tracked as TA-NATALSTATUS and IronErn through overlapping domains, malware deployment paths, staging techniques, and backend infrastructure.
organisation
Oligo Security
TeamPCP-linked infrastructure has been
traced back to 2020
, Oligo Security said in an August 5 report, tying the group to activity previously tracked as TA-NATALSTATUS and IronErn through overlapping domains, malware deployment paths, staging techniques, and backend infrastructure.
organisation
TA-NATALSTATUS
TeamPCP-linked infrastructure has been
traced back to 2020
, Oligo Security said in an August 5 report, tying the group to activity previously tracked as TA-NATALSTATUS and IronErn through overlapping domains, malware deployment paths, staging techniques, and backend infrastructure.
organisation
IronErn
TeamPCP-linked infrastructure has been
traced back to 2020
, Oligo Security said in an August 5 report, tying the group to activity previously tracked as TA-NATALSTATUS and IronErn through overlapping domains, malware deployment paths, staging techniques, and backend infrastructure.
26 August 2026
The Australian Federal Police executed search warrants in Perth on 26 August 2026.
Click on any entity below to view its context and source!
target_region
Australia
The Australian Federal Police, the Western Australia Police Force and the FBI executed search warrants in Perth on 26 August 2026 and arrested a 21-year-old from Cottesloe and a 23-year-old from Mandurah.
attribution
The Australian Federal Police
The Australian Federal Police, the Western Australia Police Force and the FBI executed search warrants in Perth on 26 August 2026 and arrested a 21-year-old from Cottesloe and a 23-year-old from Mandurah.
attribution
the Western Australia Police Force
The Australian Federal Police, the Western Australia Police Force and the FBI executed search warrants in Perth on 26 August 2026 and arrested a 21-year-old from Cottesloe and a 23-year-old from Mandurah.
attribution
FBI
The Australian Federal Police, the Western Australia Police Force and the FBI executed search warrants in Perth on 26 August 2026 and arrested a 21-year-old from Cottesloe and a 23-year-old from Mandurah.
2026/08/26
The Australian Federal Police (AFP) executed search warrants in Perth with assistance from the FBI.
Click on any entity below to view its context and source!
attribution
AFP
“The AFP charged the men yesterday (26 August, 2026) with a combined total of 14 offences after executing search warrants in Perth with WAPF, and the assistance of the FBI.”
attribution
FBI
“The AFP charged the men yesterday (26 August, 2026) with a combined total of 14 offences after executing search warrants in Perth with WAPF, and the assistance of the FBI.”
general_metric
14 offences
“The AFP charged the men yesterday (26 August, 2026) with a combined total of 14 offences after executing search warrants in Perth with WAPF, and the assistance of the FBI.”
26 August, 2026
The Australian Federal Police (AFP) executed search warrants in Perth with assistance from the FBI.
Click on any entity below to view its context and source!
attribution
AFP
“The AFP charged the men yesterday (26 August, 2026) with a combined total of 14 offences after executing search warrants in Perth with WAPF, and the assistance of the FBI.”
attribution
FBI
“The AFP charged the men yesterday (26 August, 2026) with a combined total of 14 offences after executing search warrants in Perth with WAPF, and the assistance of the FBI.”
general_metric
14 offences
“The AFP charged the men yesterday (26 August, 2026) with a combined total of 14 offences after executing search warrants in Perth with WAPF, and the assistance of the FBI.”
August 27, 2026
Threat actors used stolen credentials to gain unauthorized access to electronic devices in Perth, Australia.
Click on any entity below to view its context and source!
target_region
Australia
Louis Michael Gaebler
, 23, and
Ruben Ian Thomson
, 21, appeared in Perth Magistrates Court on August 27, 2026, a day after the AFP and the Western Australia Police Force (WAPF) executed search warrants at properties in Cottesloe, Hamilton Hill, and Mandurah and seized electronic devices for forensic analysis.
attribution
AFP
Louis Michael Gaebler
, 23, and
Ruben Ian Thomson
, 21, appeared in Perth Magistrates Court on August 27, 2026, a day after the AFP and the Western Australia Police Force (WAPF) executed search warrants at properties in Cottesloe, Hamilton Hill, and Mandurah and seized electronic devices for forensic analysis.
attribution
the Western Australia Police Force
Louis Michael Gaebler
, 23, and
Ruben Ian Thomson
, 21, appeared in Perth Magistrates Court on August 27, 2026, a day after the AFP and the Western Australia Police Force (WAPF) executed search warrants at properties in Cottesloe, Hamilton Hill, and Mandurah and seized electronic devices for forensic analysis.
attribution
Perth Magistrates Court
Louis Michael Gaebler
, 23, and
Ruben Ian Thomson
, 21, appeared in Perth Magistrates Court on August 27, 2026, a day after the AFP and the Western Australia Police Force (WAPF) executed search warrants at properties in Cottesloe, Hamilton Hill, and Mandurah and seized electronic devices for forensic analysis.
general_metric
23 Louis Michael Gaebler
Louis Michael Gaebler
, 23, and
Ruben Ian Thomson
, 21, appeared in Perth Magistrates Court on August 27, 2026, a day after the AFP and the Western Australia Police Force (WAPF) executed search warrants at properties in Cottesloe, Hamilton Hill, and Mandurah and seized electronic devices for forensic analysis.
August 27
The Australian Police charged two individuals for TeamPCP credential theft.
Click on any entity below to view its context and source!
organisation
Hacker News
The Hacker News confirmed via PyPI on August 27 that the two malicious LiteLLM builds no longer appear in the package's release history, and that both still return HTTP 200 from PyPI's content delivery network at their direct package URLs five months after removal from the index.
general_metric
200 HTTP
The Hacker News confirmed via PyPI on August 27 that the two malicious LiteLLM builds no longer appear in the package's release history, and that both still return HTTP 200 from PyPI's content delivery network at their direct package URLs five months after removal from the index.
2026/08/27
Two men from Western Australia were charged with various cybercrime offenses related to the TeamPCP credential theft operation.
Click on any entity below to view its context and source!
data_breach
500,000 credentials
Australian Police Charge Two Over TeamPCP Credential Theft
Australian police charged two men linked to TeamPCP over malware hidden in open-source code that stole 500,000+ credentials from 1,000+ organizations.
The AFP said the malicious code potentially compromised more than 1,000 organizations globally, enabled the theft of more than 500,000 credentials, and led to the exfiltration of at least 300 gigabytes of data.
threat_actor
TeamPCP
Australian Police Charge Two Over TeamPCP Credential Theft
Australian police charged two men linked to TeamPCP over malware hidden in open-source code that stole 500,000+ credentials from 1,000+ organizations.
Australian Police Charge Two Over TeamPCP Credential Theft.
Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks.
FBI Cyber Division Assistant Director Brett E. Leatherman said in
a joint media release
that the two men are allegedly members of TeamPCP, whose malicious code "potentially compromised more than a thousand organizations worldwide.
CloudSEK said credential theft is not proof that a company was successfully compromised, and the confirmed victim count is the 16 organizations TeamPCP published on its leak site as of late March.
victims
1,000 organizations
Australian Police Charge Two Over TeamPCP Credential Theft
Australian police charged two men linked to TeamPCP over malware hidden in open-source code that stole 500,000+ credentials from 1,000+ organizations.
The AFP said the malicious code potentially compromised more than 1,000 organizations globally, enabled the theft of more than 500,000 credentials, and led to the exfiltration of at least 300 gigabytes of data.
organisation
Hackers Charged
Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks.
organisation
Major Supply Chain Attacks
Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks.
data_breach
300 gigabytes
The AFP said the malicious code potentially compromised more than 1,000 organizations globally, enabled the theft of more than 500,000 credentials, and led to the exfiltration of at least 300 gigabytes of data.
organisation
AFP
The AFP said the malicious code potentially compromised more than 1,000 organizations globally, enabled the theft of more than 500,000 credentials, and led to the exfiltration of at least 300 gigabytes of data.
victims
16 organizations
CloudSEK said credential theft is not proof that a company was successfully compromised, and the confirmed victim count is the 16 organizations TeamPCP published on its leak site as of late March.
organisation
PyPI
The campaign spanned five distribution ecosystems, GitHub Actions, Docker Hub, npm, PyPI, and OpenVSX.
organisation
GitHub Actions
The campaign spanned five distribution ecosystems, GitHub Actions, Docker Hub, npm, PyPI, and OpenVSX.
organisation
CI
It advised rotating all continuous integration and continuous delivery (CI/CD) secrets, publishing tokens, and cloud credentials accessible during the exposure windows.
infrastructure
Windows
It advised rotating all continuous integration and continuous delivery (CI/CD) secrets, publishing tokens, and cloud credentials accessible during the exposure windows.
financial
100,000 order
"
The Cottesloe man, 21, was charged with one count of possessing data with intent to commit a computer offence, four counts of unauthorized modification of data with intent to commit a serious offence, one count of supplying data with intent to commit a computer offence, one count of failing to comply with a section 3LA order, and one count of dealing with proceeds of crime worth $100,000 or more.
organisation
CloudSEK
"
CloudSEK and Hudson Rock published
the August exposure figures
for the same campaign, with CloudSEK putting reconstructed exposure at more than 2,500 organizations and roughly 434,000 CI/CD pipelines, and Hudson Rock attributing 118,829 CI runner dumps to 2,488 corporate domains from a 153GB archive of the attackers' own exfiltrated data.
victims
2,500 organizations
"
CloudSEK and Hudson Rock published
the August exposure figures
for the same campaign, with CloudSEK putting reconstructed exposure at more than 2,500 organizations and roughly 434,000 CI/CD pipelines, and Hudson Rock attributing 118,829 CI runner dumps to 2,488 corporate domains from a 153GB archive of the attackers' own exfiltrated data.
infrastructure
434,000 CD pipelines
"
CloudSEK and Hudson Rock published
the August exposure figures
for the same campaign, with CloudSEK putting reconstructed exposure at more than 2,500 organizations and roughly 434,000 CI/CD pipelines, and Hudson Rock attributing 118,829 CI runner dumps to 2,488 corporate domains from a 153GB archive of the attackers' own exfiltrated data.
infrastructure
2,488 corporate domains
"
CloudSEK and Hudson Rock published
the August exposure figures
for the same campaign, with CloudSEK putting reconstructed exposure at more than 2,500 organizations and roughly 434,000 CI/CD pipelines, and Hudson Rock attributing 118,829 CI runner dumps to 2,488 corporate domains from a 153GB archive of the attackers' own exfiltrated data.
data_breach
153 GB
"
CloudSEK and Hudson Rock published
the August exposure figures
for the same campaign, with CloudSEK putting reconstructed exposure at more than 2,500 organizations and roughly 434,000 CI/CD pipelines, and Hudson Rock attributing 118,829 CI runner dumps to 2,488 corporate domains from a 153GB archive of the attackers' own exfiltrated data.
organisation
StepSecurity
StepSecurity said its analysis of the CloudSEK dataset found GitLab led the affected platforms with 1,064 organizations, ahead of GitHub Actions on 618, Azure DevOps on 233, Jenkins on 105, Bitbucket Pipelines on 94, and CircleCI on 15.
organisation
GitLab
StepSecurity said its analysis of the CloudSEK dataset found GitLab led the affected platforms with 1,064 organizations, ahead of GitHub Actions on 618, Azure DevOps on 233, Jenkins on 105, Bitbucket Pipelines on 94, and CircleCI on 15.
organisation
DevOps
StepSecurity said its analysis of the CloudSEK dataset found GitLab led the affected platforms with 1,064 organizations, ahead of GitHub Actions on 618, Azure DevOps on 233, Jenkins on 105, Bitbucket Pipelines on 94, and CircleCI on 15.
organisation
Bitbucket Pipelines
StepSecurity said its analysis of the CloudSEK dataset found GitLab led the affected platforms with 1,064 organizations, ahead of GitHub Actions on 618, Azure DevOps on 233, Jenkins on 105, Bitbucket Pipelines on 94, and CircleCI on 15.
victims
1,064 organizations
StepSecurity said its analysis of the CloudSEK dataset found GitLab led the affected platforms with 1,064 organizations, ahead of GitHub Actions on 618, Azure DevOps on 233, Jenkins on 105, Bitbucket Pipelines on 94, and CircleCI on 15.
organisation
Oligo
Whether that continuity reflects a rebrand, a shared operator set, or close collaboration between historically related actors "cannot be determined with 100% certainty," Oligo said.
organisation
Socket
Socket said the self-identifying markers that would tie the sample to a named campaign were not recovered.
August 2026
The Australian Federal Police and the Western Australia Police Force worked with the FBI to charge two individuals, who were principal participants in TeamPCP, a syndicate that inserted malicious code into software hosted on public repositories.
Click on any entity below to view its context and source!
data_breach
500,000 credentials
Investigators estimate the malicious code potentially compromised more than 1,000 organisations worldwide, enabling the theft of over 500,000 credentials and the exfiltration of at least 300 gigabytes of data.
data_breach
300 gigabytes
Investigators estimate the malicious code potentially compromised more than 1,000 organisations worldwide, enabling the theft of over 500,000 credentials and the exfiltration of at least 300 gigabytes of data.
threat_actor
TeamPCP
Police say the pair were principal participants in a syndicate known as
TeamPCP
, which allegedly inserted malicious code into software hosted on public repositories and then let other developers pull it in without knowing.
TeamPCP is
behind multiple supply chain attacks
, in the past, they targeted PyPI packages and NPM repositories, and most recently the “Mini Shai-Hulud” campaign also caught two OpenAI employees.
TeamPCP’s method was straightforward and effective: inject malicious code into legitimate software packages, push the trojanized versions through normal distribution channels, and wait for CI/CD pipelines to pull them in automatically.
“These men are allegedly members of the cybercriminal group TeamPCP, whose malicious code potentially compromised more than a thousand organizations worldwide,” Assistant Director Leatherman said.
organisation
PyPI
TeamPCP is
behind multiple supply chain attacks
, in the past, they targeted PyPI packages and NPM repositories, and most recently the “Mini Shai-Hulud” campaign also caught two OpenAI employees.
organisation
OpenAI
TeamPCP is
behind multiple supply chain attacks
, in the past, they targeted PyPI packages and NPM repositories, and most recently the “Mini Shai-Hulud” campaign also caught two OpenAI employees.
organisation
KICS
The confirmed list of modified tools includes
Trivy
, a widely used container vulnerability scanner; KICS, a static analysis tool for infrastructure-as-code;
LiteLLM
, a popular library for routing requests across AI model APIs; and the Telnyx Python SDK.
organisation
the Telnyx
The confirmed list of modified tools includes
Trivy
, a widely used container vulnerability scanner; KICS, a static analysis tool for infrastructure-as-code;
LiteLLM
, a popular library for routing requests across AI model APIs; and the Telnyx Python SDK.
organisation
CI
They’re commonly integrated into enterprise CI/CD pipelines, cloud infrastructure workflows, and security scanning processes.
organisation
API
CanisterWorm
harvested cloud access tokens, credentials, and API keys for AWS, GCP, and Azure.
organisation
AWS
CanisterWorm
harvested cloud access tokens, credentials, and API keys for AWS, GCP, and Azure.
organisation
GCP
CanisterWorm
harvested cloud access tokens, credentials, and API keys for AWS, GCP, and Azure.
organisation
Kubernetes ServiceAccount
SANDCLOCK
extracted AWS credentials, Kubernetes ServiceAccount tokens, local environment variables, and cryptocurrency wallet data.
financial
100,000 order
The 21-year-old faces several charges, including changing data without authorization, possessing and supplying data for computer crimes, failing to comply with a production order, and handling at least A$100,000 in criminal proceeds.
Tactical Metrics
Metrics
data_breach
500,000
Credentials
Click for context!
Investigators estimate the malicious code potentially compromised more than 1,000 organisations worldwide, enabling the theft of over 500,000 credentials and the exfiltration of at least 300 gigabytes of data.
Australian Police Charge Two Over TeamPCP Credential Theft
Australian police charged two men linked to TeamPCP over malware hidden in open-source code that stole 500,000+ credentials from 1,000+ organizations.
The AFP said the malicious code potentially compromised more than 1,000 organizations globally, enabled the theft of more than 500,000 credentials, and led to the exfiltration of at least 300 gigabytes of data.
Metrics
data_breach
300
Gigabytes
Investigators estimate the malicious code potentially compromised more than 1,000 organisations worldwide, enabling the theft of over 500,000 credentials and the exfiltration of at least 300 gigabytes of data.
The AFP said the malicious code potentially compromised more than 1,000 organizations globally, enabled the theft of more than 500,000 credentials, and led to the exfiltration of at least 300 gigabytes of data.
Metrics
victims
1,000
Organizations
Australian Police Charge Two Over TeamPCP Credential Theft
Australian police charged two men linked to TeamPCP over malware hidden in open-source code that stole 500,000+ credentials from 1,000+ organizations.
The AFP said the malicious code potentially compromised more than 1,000 organizations globally, enabled the theft of more than 500,000 credentials, and led to the exfiltration of at least 300 gigabytes of data.
Metrics
financial
100,000
Order
The 21-year-old faces several charges, including changing data without authorization, possessing and supplying data for computer crimes, failing to comply with a production order, and handling at least A$100,000 in criminal proceeds.
"
The Cottesloe man, 21, was charged with one count of possessing data with intent to commit a computer offence, four counts of unauthorized modification of data with intent to commit a serious offence, one count of supplying data with intent to c…
Metrics
infrastructure
Windows
Affected Product
It advised rotating all continuous integration and continuous delivery (CI/CD) secrets, publishing tokens, and cloud credentials accessible during the exposure windows.
Metrics
victims
2,500
Organizations
…ck published
the August exposure figures
for the same campaign, with CloudSEK putting reconstructed exposure at more than 2,500 organizations and roughly 434,000 CI/CD pipelines, and Hudson Rock attributing 118,829 CI runner dumps to 2,488 corpor…
Metrics
infrastructure
434,000
Cd Pipelines
"
CloudSEK and Hudson Rock published
the August exposure figures
for the same campaign, with CloudSEK putting reconstructed exposure at more than 2,500 organizations and roughly 434,000 CI/CD pipelines, and Hudson Rock attributing 118,829 CI run…
Metrics
infrastructure
2,488
Corporate Domains
…loudSEK putting reconstructed exposure at more than 2,500 organizations and roughly 434,000 CI/CD pipelines, and Hudson Rock attributing 118,829 CI runner dumps to 2,488 corporate domains from a 153GB archive of the attackers' own exfiltrated data.
Metrics
data_breach
153
Gb
"
CloudSEK and Hudson Rock published
the August exposure figures
for the same campaign, with CloudSEK putting reconstructed exposure at more than 2,500 organizations and roughly 434,000 CI/CD pipelines, and Hudson Rock attributing 118,829 CI run…
Metrics
victims
16
Organizations
CloudSEK said credential theft is not proof that a company was successfully compromised, and the confirmed victim count is the 16 organizations TeamPCP published on its leak site as of late March.
Metrics
victims
1,064
Organizations
StepSecurity said its analysis of the CloudSEK dataset found GitLab led the affected platforms with 1,064 organizations, ahead of GitHub Actions on 618, Azure DevOps on 233, Jenkins on 105, Bitbucket Pipelines on 94, and CircleCI on 15.
Intelligence Sources
Security Affairs
2026-08-27
Australian Police Charge Two Over TeamPCP Credential Theft
Security Affairs
The Hacker News
2026-08-27
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-28T06:00
Comprehensive Tactical Telemetry
Highly Correlated Entities
25x
organisation
Identified Entity
PyPI
entity
17x
timeline
Temporal Reference
26 August 2026
date
10x
attribution
Attributing Entity
AFP
authority
4x
victims
Organizations
1,000
organizations
3x
malware
Malware Payload
Mini Shai-Hulud
tool
2x
industry
Targeted Sector
Government
sector
2x
tactic
MITRE ATT&CK Technique
T1059.006 - Python
technique
Contextual Telemetry
Context Block
18 METRICS
source region
Origin Country
Australia
country
target region
Target Country
Australia
country
tactic
Cyber Operation Type
Exfiltration
tactic
general metric
Organisations
1,000
organisations
data breach
Credentials
500,000
credentials
data breach
Gigabytes
300
gigabytes
general metric
Offences
14
offences
threat actor
APT Group
TeamPCP
actor
financial
Order
100,000
order
general metric
Louis Michael Gaebler
23
louis michael gaebler
infrastructure
Affected Product
Windows
software
general metric
Crimes Act
1,914
crimes act
infrastructure
Cd Pipelines
434,000
cd pipelines
general metric
Ci Runner Dumps
118,829
ci runner dumps
infrastructure
Corporate Domains
2,488
corporate domains
data breach
Gb
153
gb
general metric
Http
200
http
general metric
%
100
%
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.