27/08/2026
In March 2026, KELA's Cyber Intelligence Center briefed the AFP, the Western Australia Police Force and the FBI on TeamPCP (UNC6780): the identities behind the aliases, the infrastructure, and the victim set.
Two men have now been charged in Western Australia. One of them was named in KELA's TeamPCP Threat Actor Profile in April 2026, supplied to law enforcement at the time.
The AFP alleges the campaign potentially compromised more than 1,000 organizations globally, enabled the theft of over 500,000 credentials, and led to the exfiltration of at least 300GB of data, with global remediation costs running into the hundreds of millions.
What makes TeamPCP worth studying: it started as a Telegram stolen-data broker and ended up inside the tooling defenders use to check their own code. Between March 19 and 24, 2026, four waves reached Trivy, Checkmarx KICS and AST GitHub Actions, OpenVSX and LiteLLM (CVE-2026-33634, added to CISA's KEV catalog on March 26).
The AFP has said industry reporting was crucial to its investigators. That is the argument for CTI that names people, not just indicators.
Full release: https://hubs.la/Q04vzVXQ0
Published analysis, from Telegram brokering through to identification: https://hubs.la/Q04vzCt-0
Finished threat intelligence report: https://hubs.la/Q04vzKZJ0
And we are walking the whole arc, including how the investigation actually came together, in a webinar on Monday, August 31: https://hubs.la/Q04vzGQj0