Australian authorities arrested two Western Australia men on Wednesday, August 26, over their alleged roles in TeamPCP, the cybercrime group that injected credential-stealing code into Aqua Security's Trivy scanner, Checkmarx KICS and LiteLLM in March. The AFP says that code potentially compromised more than 1,000 organizations worldwide.
Police didn't name the pair; Australian media identified them as Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23. Between them they face 14 charges, including four counts each of unauthorized modification of data with intent to commit a serious offence. Only Thomson faces a proceeds-of-crime count over $100,000 and a password-refusal charge.
The AFP estimates the code enabled theft of more than 500,000 credentials and at least 300GB of data, with global cleanup costs in the hundreds of millions. CERT-EU tied the European Commission's cloud breach to the poisoned Trivy release. Flare assesses with high confidence that Thomson led TeamPCP.
Both men appeared in Perth Magistrates Court on Thursday. Thomson withdrew a bail application after the magistrate signalled she would refuse it, and both remain in custody until September 18.
Source: CyberScoop