Australian Police Arrest Two Over Hacks on OpenAI, Mercor Linked to TeamPCP
Australian police arrested two people in Perth over TeamPCP-linked hacks on OpenAI, Mercor and other tech firms, charging them with cybercrime offenses.
The two men are expected to appear in court later Thursday. The arrests follow an investigation that began in April 2026 after Australian officials received information from multiple cybersecurity companies. It remains unclear whether the U.S. Justice Department plans to seek extradition; an FBI spokesperson did not immediately respond to requests for comment.
Brett Leatherman, the FBI's cyber division chief, said the two alleged TeamPCP members are accused of hacking into more than a thousand organizations. The authorities say the hackers stole more than half a million credentials to expand their attacks into other companies.
TeamPCP is known for targeting the software supply chain. The hackers would gain access to widely used open-source tools and modify them maliciously, according to the AFP. One attack involved Trivy, a popular vulnerability scanner, affecting companies that depended on it, including LiteLLM and AI recruiting startup Mercor. The hackers are also suspected of breaching the European Commission's cloud infrastructure and targeting other open-source projects and developer apps that provided access to tech giants such as GitHub and OpenAI.
At a press conference on Wednesday, Australian officials announced the arrests and said they had also seized a large quantity of allegedly stolen data, as well as devices and other electronics. They said they plan to notify victims of the attacks.
Police have not named the two arrested men. However, independent cybersecurity journalist Brian Krebs reported Thursday that one of them is Ruben Thomson, who uses the hacker handle “Ellis.” According to Krebs, Thomson said he was the leader of TeamPCP until March 2026, and Thomson made mistakes that allowed Krebs to discover his real identity.