United States Attorney's Office for the Northern District of California

08/27/2026 | Press release | Distributed by Public on 08/27/2026 16:28

Australian Man Indicted For “TeamPCP” Cyberattacks On Software Supply Chain

SAN FRANCISCO - A federal grand jury has indicted Ruben Ian Thomson on charges of conspiracy to commit Computer Fraud and Abuse Act violations and obtaining information from a protected computer related to cyberattacks conducted in the Spring of 2026 under the moniker "TeamPCP." Thomson was arrested yesterday by the Australian Federal Police with the assistance of the Federal Bureau of Investigation (FBI), and he is currently in the custody of the Australian authorities.

According to the indictment filed on August 25 and unsealed yesterday, Thomson, 21, a national of Australia and South Africa, is alleged to have conspired with others to exploit trusted software supply chain security tools, and inject malicious software code into these companies' tools. The exploitation of the computer systems of these companies then cascaded, affecting the companies' downstream customers that utilized these tools. Specifically, the malicious code would scan downstream customers' computer environments for sensitive data to steal. If sensitive data was identified, the malicious code attempted to exfiltrate that data to other infrastructure controlled by Thomson and/or his coconspirators. The malicious code also enabled them to maintain persistent access in the company's computer environment. Following the exfiltration of data from the computer systems of the company, Thomson and/or his coconspirators extorted ransom payments in exchange for a promise to not publicly release the data exfiltrated from the company.

United States Attorney Craig H. Missakian and FBI San Francisco Special Agent-in-Charge Scott Schelble of the FBI's San Francisco Division made the announcement.

An indictment merely alleges that crimes have been committed, and the defendant is presumed innocent until proven guilty beyond a reasonable doubt. If convicted, the defendant faces a maximum sentence of 5 years in prison and a fine of $250,000, or twice the gross gain or twice the gross loss from the conduct for each violation of 18 U.S.C. § 371 (Conspiracy) and 18 U.S.C. §§ 1030(a)(2)(C), (c)(2)(B), and 2 (Obtaining Information from a Protected Computer; Aiding and Abetting). Any sentence following conviction would be imposed by the court after consideration of the U.S. Sentencing Guidelines and the federal statute governing the imposition of a sentence, 18 U.S.C. § 3553.

The prosecution is being handled by the National Security, Cyber & Special Prosecutions Section of the U.S. Attorney's Office for the Northern District of California. Assistant U.S. Attorney Daniel N. Kassabian is prosecuting the case with the assistance of Helen Yee and Kristie Yee. The prosecution is the result of an investigation by the Federal Bureau of Investigation San Francisco and Las Vegas Field Offices.

United States Attorney's Office for the Northern District of California published this content on August 27, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on August 27, 2026 at 22:28 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]