KELA research leads to alleged TeamPCP Members Arrested

Skip to Content News Archives Economy Energy Oil & Gas Renewables Electric Vehicles Mining Commodities Agriculture Real Estate Mortgages Mortgage Rates Finance Banking Insurance Fintech Cryptocurrency Work Wealth Smart Money Wealth Management Investor Personal Finance Family Finance Retirement Taxes High Net Worth FP Comment Executive Women Puzzmo Newsletters Financial Times Business Essentials More Innovation Information Technology FP500 Podcasts Small Business Lives Told Tails Told Shopping Financial Post Store Obituaries Place a Notice Advertising Advertising With Us Advertising Solutions Postmedia Ad Manager Sponsorship Requests Classifieds Place a Classifieds ad Working Profile Settings My Subscriptions My Offers Newsletters Customer Service FAQ News Economy Energy Mining Real Estate Finance Work Wealth Investor FP Comment Executive Women Puzzmo Newsletters Financial Times Business Essentials This advertisement has not loaded yet, but your article continues below.HomeGlobeNewswireThis section is The content in this section is supplied by GlobeNewswire for the purposes of distributing press releases on behalf of its clients. Postmedia has not reviewed the content. by GlobeNewswire KELA research leads to alleged TeamPCP Members ArrestedAuthor of the article:Intelligence naming the individuals behind the aliases, and mapping the infrastructure and victims, went to the Australian Federal Police (AFP) and Western Australia Police Force (WAPF) and the Federal Bureau of Investigation (FBI) in March and April 2026.THIS CONTENT IS RESERVED FOR SUBSCRIBERS ONLYSubscribe now to read the latest news in your city and across Canada.Exclusive articles from Barbara Shecter, Joe O'Connor, Gabriel Friedman, and others.Daily content from Financial Times, the world's leading global business publication.Unlimited online access to read articles from Financial Post, National Post and 15 news sites across Canada with one account.National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.Daily puzzles, including the New York Times Crossword.SUBSCRIBE TO UNLOCK MORE ARTICLESSubscribe now to read the latest news in your city and across Canada.Exclusive articles from Barbara Shecter, Joe O'Connor, Gabriel Friedman and others.Daily content from Financial Times, the world's leading global business publication.Unlimited online access to read articles from Financial Post, National Post and 15 news sites across Canada with one account.National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.Daily puzzles, including the New York Times Crossword.REGISTER / SIGN IN TO UNLOCK MORE ARTICLESCreate an account or sign in to continue with your reading experience.Access articles from across Canada with one account.Share your thoughts and join the conversation in the comments.Enjoy additional articles per month.Get email updates from your favourite authors.THIS ARTICLE IS FREE TO READ REGISTER TO UNLOCK.Create an account or sign in to continue with your reading experience.Access articles from across Canada with one accountShare your thoughts and join the conversation in the commentsEnjoy additional articles per monthGet email updates from your favourite authorsSign In or Create an AccountTel Aviv, Israel, Aug. 27, 2026 (GLOBE NEWSWIRE) — TEL AVIV, Israel, Aug. 27, 2026. KELA’s Cyber Intelligence Center today published its findings, previously shared with law enforcement agencies, including AFP, WAPF and the FBI.In March 2026, KELA briefed the leading law enforcement and federal agencies sharing detailed reports that unmasked the identities of alleged TeamPCP members and exposed their infrastructure and victims. Investigation support and sharing intelligence continued in collaboration throughout the operation and matched the intelligence KELA customers could access in real-time. KELA confirms one of the arrested alleged criminals, Ruben Thomson, was named in their TeamPCP – Threat Actor Profile report in April 2026, supplied to law enforcement at the time in reports and briefings.Get the latest headlines, breaking news and columns.By signing up you consent to receive the above newsletter from Postmedia Network Inc.A welcome email is on its way. If you don't see it, please check your junk folder.The next issue of Top Stories will soon be in your inbox.We encountered an issue signing you up. Please try againKELA’s research reveals the group’s activities from Telegram data brokering to a credential-chaining cascade continued running five months on, as Australian police charged the two men over the campaign.TeamPCP, a financially motivated group tracked by Google as UNC6780, began as a Telegram stolen-data broker before turning on the security and developer tooling that organizations trust to check their own code. Between March 19 and 24, 2026, it ran four waves, starting with a compromised service account tied to Aqua Security’s Trivy vulnerability scanner, where malicious code was force-pushed across the project’s version tags. Initial access was possible because a credential rotation following a February 2026 breach had been left incomplete. Later waves reached Checkmarx KICS and AST GitHub Actions, OpenVSX and LiteLLM. The compromise is tracked as CVE-2026-33634, added to CISA’s Known Exploited Vulnerabilities catalog on March 26, 2026. The group also partnered with the Vect ransomware operation, supplying stolen credentials for initial access while Vect supplied encryption and extortion infrastructure.The AFP alleges the campaign potentially compromised more than 1,000 organizations globally, enabled the theft of more than 500,000 credentials, and led to the exfiltration of at least 300 gigabytes of data, with global remediation costs in the hundreds of millions of dollars.KELA’s research also documents the criminal ecosystem behind the code. The group’s main platform was a Telegram channel active from November 2025 to March 2026, where the administrator brokered stolen data and promoted CipherForce, TeamPCP’s own operation for publishing breach information. Over the same period the group launched a sister channel under the ShellForce name, ran a stealer log search bot, and stood up Tor-based infrastructure before migrating to bulletproof hosting.The AFP has stated that its investigations began in April 2026 after it and the FBI received information from multiple cyber threat assessment companies, and that this industry reporting was crucial to investigators. KELA was one of the companies that reported on TeamPCP to those agencies. The matter is now before the court.A finished threat intelligence report is available upon request by KELA, and the organization is sharing further findings in a webinar on Monday August 31st 2026.Ben Kapon Kela Research and Strategy +972-52-6100006 benk@ke-la.com This advertisement has not loaded yet.Notice for the Postmedia NetworkThis website uses cookies to personalize your content (including ads), and allows us to analyze our traffic. Read more about cookies here. By continuing to use our site, you agree to our Terms of Use and Privacy Policy.

Original Source

Read the full article at Financialpost →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.