Two Western Australian men have been charged following a joint investigation by the Australian Federal Police, Western Australia Police Force, and the FBI into an alleged cybercrime syndicate. They are accused of using malicious code hidden in open-source software to compromise organizations worldwide.
Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, were arrested in Perth after investigators raided properties in Cottesloe, Hamilton Hill and Mandurah. The two men face a combined 14 charges, with Australian authorities saying further arrests and charges remain possible.
Investigators allege the men were involved with TeamPCP, a highly organized cybercrime syndicate involved in data intrusion, identity crime and cryptocurrency-related money laundering. FBI officials have described Thomson as the group’s alleged leader.
READ: Two Malayali women killed in California, friend detained (August 30, 2026)
The investigation began in April after the AFP and FBI received information about the alleged syndicate. Police allege the group inserted malicious code into legitimate open-source software, which developers later downloaded and used without knowing the software had been compromised.
The infected software allegedly gave the syndicate access to computer systems across government, academic and private-sector organizations. Authorities estimate that more than 1,000 organizations worldwide may have been compromised.
The alleged operation also resulted in the theft or harvesting of more than 500,000 user credentials and authentication materials, according to investigators. The stolen information could allow attackers to impersonate legitimate users, bypass security controls and gain unauthorized access to networks and cloud environments.
AFP Commander Graham Marshall said the alleged activity caused significant financial losses and operational disruption, with remediation costs estimated in the hundreds of millions of dollars. He described the two men as “internationally significant cybercrime threat actors.”
FBI Deputy Law Enforcement Attaché Daud Andish said the arrests demonstrated that cybercriminals could not rely on anonymity online to avoid prosecution. “This arrest sends a clear message: hiding behind a screen is no shield from the rule of law,” Andish said.
He also highlighted the importance of cooperation between U.S. and Australian authorities in pursuing cybercrime that crosses national borders.
READ: Three teenagers arrested for allegedly destroying Flock cameras in South Carolina (August 27, 2026)
The investigation underscores the growing risks associated with software supply-chain attacks, in which attackers compromise trusted software or development tools rather than directly targeting each victim. Because open-source software is widely shared and incorporated into other applications, malicious code can potentially spread across a large number of organizations.
Authorities seized electronic devices during the Australian raids. Police said they had already extracted about 100 terabytes of data from devices taken from one address and expected to recover significantly more information as the investigation continues.
Thomson’s bail application was withdrawn after a magistrate raised concerns about potential evidence tampering. Gaebler did not apply for bail and was remanded in custody until his next court appearance scheduled for September 18.
The case highlights the increasingly international nature of cybercrime and the importance of cooperation between U.S. and Australian law enforcement agencies as investigators attempt to disrupt criminal networks operating across borders.
The FBI has made combating cybercrime a major priority under President Donald Trump’s administration, with the agency emphasizing partnerships with foreign law enforcement agencies to protect American businesses and consumers from increasingly sophisticated online threats.


