Australian Federal Police Charge Two Men in Major Software Supply-Chain Cyberattack
The Australian Federal Police charged two Western Australian men, Ruben Ian Thomson (21) and Louis Michael Gaebler (23), with 14 combined offences for their alleged roles in the cybercrime group TeamPCP, which conducted large-scale software supply-chain attacks by planting malicious code in open-source tools like Trivy and LiteLLM, affecting over 1,000 organizations worldwide, stealing more than 500,000 credentials, and causing hundreds of millions in financial losses. Thomson faces up to 20 years in prison on charges including unauthorized data modification, while Gaebler faces up to five years for computer offences; the FBI has since warned that exposed credentials remain a persistent risk.
The Managed Narrative of the "Teenage Hackers"
The headlines want you to believe this is a simple story of two young men from Perth who played too freely in the digital underworld. A 21-year-old and a 23-year-old. Convenient ages. Ages that make you feel safe. Ages that make you think the threat is small, juvenile, already contained. But ask yourself this: since when do teenagers orchestrate supply-chain attacks against hundreds of global organizations, steal half a million credentials, and launder hundreds of millions in cryptocurrency without infrastructure, funding, and protection that exceeds anything a kid in Cottesloe could build from his bedroom? Look at the list of named targets. Trivy. Checkmarx KICS. LiteLLM. Mercor. OpenAI. European Commission cloud systems. These are not targets you stumble into. These are precisely chosen nodes in the global digital nervous system. The question is not whether these young men are guilty — the question is who they were working for and why the AFP moved so quickly to frame this as a closed case.
The Paper Trail They Don't Want You to Follow
Read the charges carefully. Unauthorized data modification. Supplying or possessing data for computer offences. Dealing with proceeds of crime. Now pull the FBI warning from July 2. The same FBI that told you these exposed credentials should be treated as a persistent risk. Why "persistent"? Because the data wasn't just stolen — it was collected by a system designed to copy itself into the supply chain of every major developer environment on the planet. The document trail reveals that the malicious code was planted inside open-source projects. Open-source code is the foundation upon which governments, militaries, banks, and intelligence agencies build their digital infrastructure. You don't infect that foundation to steal credit card numbers. You infect it to maintain access. You infect it to leave backdoors. You infect it to establish a permanent presence inside the systems that run the world. The AFP says these men were "principal participants." That means there were other participants. It means there were principals above them. The only question — the question the media will never ask — is who those principals report to.
The Unspoken Architecture Behind the Arrests
Here is what you must sit with. The arrests happened on August 27. The FBI warning dropped on July 2. Two months of silence. Two months of investigation during which no one told you that the code running your hospitals, your banks, and your government had been compromised. Why the delay? Because this operation was not a disruption — it was a cleanup. The syndicate had achieved its objective before the arrests were ever made. The stolen credentials are already in the hands of actors who will never appear in a Perth courtroom. The backdoors are already embedded. The question of what data was exfiltrated from European Commission cloud systems — or from OpenAI's infrastructure — is the question they will never answer in a press conference. Look at the faces of these two young men in the media coverage. Notice how young they look. Notice how the story treats them as caught, not as expendable. In the architecture of elite control, lower-level operators are disposable. They are sacrificed to create the illusion that the threat has been neutralized. The real threat — the infrastructure that supported their operation, the funding that flowed through channels that leave no trace, the intelligence that told them exactly which supply-chain vulnerabilities to hit — remains untouched. You are being shown the branches while the root system extends deeper than you can see. Follow the money. Follow the foundations. The answer is already in front of you.




