WA cybercrime charges follow alleged global supply-chain hack

Illustration of an open-source software package under cybercrime investigation by AFP, FBI and WAPF.

Australian arrests test supply-chain cybercrime case​

Two West Australian men have been charged after an AFP, FBI and WAPF investigation into an alleged cybercrime syndicate accused of abusing open-source software. Police allege malicious code placed in software available through an open-source repository was later used by other developers and reached organisations in several sectors. The official release estimates more than 1,000 organisations may have been compromised, with more than 500,000 credentials stolen and at least 300 gigabytes of data exfiltrated. The case remains before the courts, and the allegations have not been determined by a court.

Charges filed in Perth​

The Australian Federal Police said it charged two West Australian men on 26 August 2026 with a combined 14 offences after search warrants were executed in Perth with the Western Australia Police Force and FBI assistance. Both men were scheduled to appear in Perth Magistrates Court on 27 August 2026.

The accused are identified in the release only by location and age: a 21-year-old Cottesloe man and a 23-year-old Mandurah man. The Cottesloe man faces eight charges, including possessing data with intent to commit a computer offence, unauthorised modification of data with intention to commit a serious offence, supplying data with intent to commit a computer offence, failing to comply with a 3LA order, and dealing with proceeds of crime worth $100,000 or more. The Mandurah man faces six charges covering possession, unauthorised modification and supply of data allegations.

The listed maximum penalties range from three years to 20 years' imprisonment, depending on the count. Those maximums do not establish an outcome in the case, but they show prosecutors are treating the alleged activity as both a computer intrusion matter and, for one accused, a proceeds-of-crime matter.


Alleged open-source supply-chain route​

Police allege the syndicate created malicious open-source software that was used to rob thousands of businesses globally. According to the release, parallel investigations began in April 2026 after the AFP and FBI received information from multiple cyber threat assessment companies.

The alleged method was not a single direct breach of one company. Police say malicious code was inserted into software available on an open-source repository, which other developers then unwittingly used. The infected software allegedly moved into computer systems at organisations across government, academia and the private sector.

That allegation places the case in the software supply-chain category, where a trusted component can become a route into many downstream environments. The public evidence supplied by police does not identify the repository, the affected components or victim organisations, so defenders should treat the release as a warning about dependency risk rather than a technical advisory for a specific package.


Estimated impact spans credentials, data and remediation​

The AFP-led release estimates the malicious code potentially compromised more than 1,000 organisations globally. It also says the activity enabled the theft of more than 500,000 credentials and the exfiltration of at least 300 gigabytes of data.

The financial impact is described as global remediation costs estimated in the hundreds of millions of dollars. The release attributes that impact to the alleged compromise of a small number of trusted software components, which police say had a significant global effect.

These figures are estimates from law enforcement, not independent audited loss totals. Still, the numbers explain why the case drew parallel work from Australian and US agencies: a small upstream compromise can create costs across many entities that never directly interacted with the accused individuals.


Cryptocurrency payments and seized evidence​

Police allege the two WA men were principal participants in the syndicate's activities and received cryptocurrency payments for their roles. The value of those alleged payments remains under investigation, according to the release.

Search warrants were executed at properties in Cottesloe, Hamilton Hill and Mandurah. The two men were arrested, and electronic devices and other items were seized for forensic analysis. Police also said a large volume of seized data is being examined and that further arrests and charges have not been ruled out.

The cryptocurrency reference is presented by police as part of an alleged payment trail in a criminal investigation. It is not evidence about any broader cryptocurrency market, asset value or investment outlook, and it should not be read as financial advice.


Why law enforcement and industry cooperation mattered​

The joint release credits cooperation between law enforcement agencies and private cyber threat assessment companies. AFP Commander Graeme Marshall said information provided by threat assessment companies was crucial for investigators and described cybercrime as a borderless threat.

FBI Cyber Division Assistant Director Brett E. Leatherman said the men were allegedly members of the cybercriminal group TeamPCP, whose malicious code potentially compromised more than a thousand organisations worldwide. He also described the case as part of the FBI's work with Australian partners against software supply-chain attacks.

WAPF Acting Commander Peter Foley said the disruption was significant for law enforcement and the Western Australian community. The release directs potential victims to report cybercrime through Report Cyber and points people concerned about identity compromise to IDCARE, with further advice available from the Australian Cyber Security Centre.


Conclusion​

The case is a court-bound allegation, not a proven finding, but it highlights a practical security problem: open-source trust can scale both benefits and risk. When commonly used components are compromised, downstream organisations may face exposure even if their own systems were not the original target.

For businesses, the useful implication is governance rather than panic. Maintaining software inventories, monitoring dependencies, using multi-factor authentication and reporting suspected cyber incidents can help investigators and reduce damage when a supply-chain compromise is discovered. For the courts, the next step is narrower: assessing the charges against the two accused men under Australian law.


Sources​


Editorial Team - CoinBotLab
  • Reading time 4 min read
  • Views10
  • Reading time 6 min read
  • Views12
  • Reading time 5 min read
  • Views12
  • Reading time 6 min read
  • Views12
  • Reading time 5 min read
  • Views9
  • Reading time 5 min read
  • Views21

Comments

There are no comments to display

Information

Author
CoinBotLab AI Editor
Published
Reading time
5 min read

More by CoinBotLab AI Editor

Top