The West Australian·4 min read·medium

Joint AFP, FBI investigation nabs two WA men allegedly at top of global cybercrime syndicate

H
Hannah Cross
Joint AFP, FBI investigation nabs two WA men allegedly at top of global cybercrime syndicate
AI Summary

Two Australian men have been arrested following a joint FBI and AFP investigation into a global cybercrime syndicate known as TeamPCP. The group is accused of planting malicious code in open-source software to steal sensitive data from over 1,000 organizations.

Why it matters

The case underscores the growing threat of sophisticated cybercrime syndicates targeting global infrastructure and the effectiveness of international law enforcement cooperation.

Dive DeeperCreate a free account to unlock

Two young WA men have been described as the alleged “masterminds” behind a highly sophisticated global cybercrime syndicate. The incredible revelations emerged in Perth Magistrates Court on Thursday after Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, were arrested on Wednesday night — the culmination of a months’ long joint cybercrimes investigation between the Australian Federal Police and the Federal Bureau of Investigation. AFP, FBI and WA Police officers raided three properties in Cottesloe, Hamilton Hill and Mandurah on Wednesday, where they seized several devices for forensic analysis. The men are accused of being key players in TeamPCP, a cybercriminal group responsible for developing and planting malicious code into open-source software that allegedly led to the compromise of more than 1000 organisations worldwide. Mr Thomson — the alleged ringleader of the group — allegedly engaged in malicious cyberactivity for financial gain, Commonwealth prosecutor Ms Naidu told the court. Among a raft of hacking charges, he also faces a significant cryptocurrency money laundering charge to the tune of more than $100,000. He is also accused of refusing police access to one of his devices. The court was told Mr Thomson and Mr Gaebler used the malware, dubbed “TeamPCP Cloud Stealer”, to allegedly impersonate legitimate users and gain access to restricted data. The infected software was allegedly distributed to computer systems across government, academia and the private sector — allowing the syndicate to allegedly infiltrate those organisations to steal sensitive data. Ms Naidu said they could allegedly access and modify a range of systems at a rapid pace, sometimes “as quickly as less than an hour”. At least 300 gigabytes of data and more than 500,000 user credentials were allegedly lifted from organisations — the financial impact of which is estimated to be hundreds of millions of dollars. Police remained at the properties into Thursday afternoon, with terabytes of data still being obtained and reviewed. Defence lawyer Nick Scerri, acting on behalf of Paul Holmes, attempted to make a bail application for Mr Thomson. Ms Naidu opposed bail, saying the investigating agencies considered both men “key threat actors in the cybercrime environment” worldwide. Deputy Chief Magistrate Elizabeth Woods ruled in favour of the Commonwealth, saying it would be near impossible to ensure the 21-year-old would not get his hands on a device. “The issue is being able to tamper with the evidence by using any sort of device available to him,” Ms Woods said. “Unless he’s device free, which is highly unlikely in the outside world, there is a risk.” She said the investigation was in its infancy and highly complex. “If they’re still at the house and still doing investigations, the breadth of this is unknown,” Ms Woods said. “This is not appropriate and I have no intention of giving him bail.” Mr Scerri withdrew the bail application, and Mr Thomson was remanded in custody until September 18. Mr Thomson’s mother said nothing to reporters as she left court. Mr Gaebler also briefly appeared in Perth Magistrates Court facing six of his own serious cybercrime charges. He did not apply for bail and was remanded in custody until September 18. The arrests were the culmination of a four-month investigation, which began in April after both federal agencies received tips about the syndicate from multiple several cyber threat assessment companies. At a press conference on Thursday, AFP Commander Graeme Marshall said it was “rare to have cyber criminals of this status domestically”. “These two, we will allege, are internationally significant cyber threat actors. That is a rare occurrence in Australia to have them in our jurisdiction,” Cdr Marshall said. FBI Deputy Legal Attaché David Andish told reporters Mr Thomson was “the alleged leader of the cybercriminal group known as TeamPCP”. “The group tampered with software updates for widely used development tools, hiding malicious code in routine downloads,” Mr Andish said. “This arrest sends a clear message: hiding behind a screen is no shield from the rule of law.” Cdr Marshall said as they review the growing cache of seized devices and data, more alleged victims are likely to emerge. Further arrests have not been ruled out. “As we review that data, which will take some time, we’re likely to identify further victims,” he said. “When that occurs, we will reach out domestically here in Australia to any victims, and through our counterparts internationally to notify offshore victims as they’re identified.” Police will also allege the pair’s involvement with the syndicate extended to data intrusion and identity crime.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologybusiness
Political Bias
Center
LeftLean LCenterLean RRight
Confidence: 90%

The article reports on criminal charges and police activity using standard journalistic reporting.

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in