Article content
Intelligence naming the individuals behind the aliases, and mapping the infrastructure and victims, went to the Australian Federal Police (AFP) and Western Australia Police Force (WAPF) and the Federal Bureau of Investigation (FBI) in March and April 2026.
THIS CONTENT IS RESERVED FOR SUBSCRIBERS ONLY
Subscribe now to read the latest news in your city and across Canada.
- Exclusive articles from Barbara Shecter, Joe O'Connor, Gabriel Friedman, and others.
- Daily content from Financial Times, the world's leading global business publication.
- Unlimited online access to read articles from Financial Post, National Post and 15 news sites across Canada with one account.
- National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.
- Daily puzzles, including the New York Times Crossword.
SUBSCRIBE TO UNLOCK MORE ARTICLES
Subscribe now to read the latest news in your city and across Canada.
- Exclusive articles from Barbara Shecter, Joe O'Connor, Gabriel Friedman and others.
- Daily content from Financial Times, the world's leading global business publication.
- Unlimited online access to read articles from Financial Post, National Post and 15 news sites across Canada with one account.
- National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.
- Daily puzzles, including the New York Times Crossword.
REGISTER / SIGN IN TO UNLOCK MORE ARTICLES
Create an account or sign in to continue with your reading experience.
- Access articles from across Canada with one account.
- Share your thoughts and join the conversation in the comments.
- Enjoy additional articles per month.
- Get email updates from your favourite authors.
THIS ARTICLE IS FREE TO READ REGISTER TO UNLOCK.
Create an account or sign in to continue with your reading experience.
- Access articles from across Canada with one account
- Share your thoughts and join the conversation in the comments
- Enjoy additional articles per month
- Get email updates from your favourite authors
Sign In or Create an Account
or
Article content
Tel Aviv, Israel, Aug. 27, 2026 (GLOBE NEWSWIRE) — TEL AVIV, Israel, Aug. 27, 2026. KELA’s Cyber Intelligence Center today published its findings, previously shared with law enforcement agencies, including AFP, WAPF and the FBI.
Article content
Article content
Article content
In March 2026, KELA briefed the leading law enforcement and federal agencies sharing detailed reports that unmasked the identities of alleged TeamPCP members and exposed their infrastructure and victims. Investigation support and sharing intelligence continued in collaboration throughout the operation and matched the intelligence KELA customers could access in real-time. KELA confirms one of the arrested alleged criminals, Ruben Thomson, was named in their TeamPCP – Threat Actor Profile report in April 2026, supplied to law enforcement at the time in reports and briefings.
Article content
By signing up you consent to receive the above newsletter from Postmedia Network Inc.
Article content
KELA’s research reveals the group’s activities from Telegram data brokering to a credential-chaining cascade continued running five months on, as Australian police charged the two men over the campaign.
Article content
TeamPCP, a financially motivated group tracked by Google as UNC6780, began as a Telegram stolen-data broker before turning on the security and developer tooling that organizations trust to check their own code. Between March 19 and 24, 2026, it ran four waves, starting with a compromised service account tied to Aqua Security’s Trivy vulnerability scanner, where malicious code was force-pushed across the project’s version tags. Initial access was possible because a credential rotation following a February 2026 breach had been left incomplete. Later waves reached Checkmarx KICS and AST GitHub Actions, OpenVSX and LiteLLM. The compromise is tracked as
CVE-2026-33634, added to CISA’s Known Exploited Vulnerabilities catalog on March 26, 2026. The group also partnered with the Vect ransomware operation, supplying stolen credentials for initial access while Vect supplied encryption and extortion infrastructure.
Article content
Article content
The AFP alleges the campaign potentially compromised more than 1,000 organizations globally, enabled the theft of more than 500,000 credentials, and led to the exfiltration of at least 300 gigabytes of data, with global remediation costs in the hundreds of millions of dollars.
Article content
KELA’s research also documents the criminal ecosystem behind the code. The group’s main platform was a Telegram channel active from November 2025 to March 2026, where the administrator brokered stolen data and promoted CipherForce, TeamPCP’s own operation for publishing breach information. Over the same period the group launched a sister channel under the ShellForce name, ran a stealer log search bot, and stood up Tor-based infrastructure before migrating to bulletproof hosting.
Article content
The AFP has stated that its investigations began in April 2026 after it and the FBI received information from multiple cyber threat assessment companies, and that this industry reporting was crucial to investigators. KELA was one of the companies that reported on TeamPCP to those agencies. The matter is now before the court.
Article content
A finished threat intelligence report is available upon request by KELA, and the organization is sharing further findings in a webinar on Monday August 31st 2026.
Article content
Article content
Article content
Article content

Article content
Article content
Article content

1 hour ago
2
English (US)