KELA research leads to alleged TeamPCP Members Arrested

via GlobeNewswire
ⓘ This article is third-party content and does not represent the views of this site. We make no guarantees regarding its accuracy or completeness.

Tel Aviv, Israel, Aug. 27, 2026 (GLOBE NEWSWIRE) -- TEL AVIV, Israel, Aug. 27, 2026. KELA's Cyber Intelligence Center today published its findings, previously shared with law enforcement agencies, including AFP, WAPF and the FBI.

In March 2026, KELA briefed the leading law enforcement and federal agencies sharing detailed reports that unmasked the identities of alleged TeamPCP members and exposed their infrastructure and victims.  Investigation support and sharing intelligence continued in collaboration throughout the operation and matched the intelligence KELA customers could access in real-time.  KELA confirms one of the arrested alleged criminals, Ruben Thomson, was named in their TeamPCP – Threat Actor Profile report in April 2026, supplied to law enforcement at the time in reports and briefings.

KELA’s research reveals the group's activities from Telegram data brokering to a credential-chaining cascade continued running five months on, as Australian police charged the two men over the campaign.

TeamPCP, a financially motivated group tracked by Google as UNC6780, began as a Telegram stolen-data broker before turning on the security and developer tooling that organizations trust to check their own code. Between March 19 and 24, 2026, it ran four waves, starting with a compromised service account tied to Aqua Security's Trivy vulnerability scanner, where malicious code was force-pushed across the project's version tags. Initial access was possible because a credential rotation following a February 2026 breach had been left incomplete. Later waves reached Checkmarx KICS and AST GitHub Actions, OpenVSX and LiteLLM. The compromise is tracked as CVE-2026-33634, added to CISA's Known Exploited Vulnerabilities catalog on March 26, 2026. The group also partnered with the Vect ransomware operation, supplying stolen credentials for initial access while Vect supplied encryption and extortion infrastructure.

The AFP alleges the campaign potentially compromised more than 1,000 organizations globally, enabled the theft of more than 500,000 credentials, and led to the exfiltration of at least 300 gigabytes of data, with global remediation costs in the hundreds of millions of dollars.

KELA's research also documents the criminal ecosystem behind the code. The group's main platform was a Telegram channel active from November 2025 to March 2026, where the administrator brokered stolen data and promoted CipherForce, TeamPCP's own operation for publishing breach information. Over the same period the group launched a sister channel under the ShellForce name, ran a stealer log search bot, and stood up Tor-based infrastructure before migrating to bulletproof hosting.

The AFP has stated that its investigations began in April 2026 after it and the FBI received information from multiple cyber threat assessment companies, and that this industry reporting was crucial to investigators. KELA was one of the companies that reported on TeamPCP to those agencies. The matter is now before the court.

A finished threat intelligence report is available upon request by KELA, and the organization is sharing further findings in a webinar on Monday August 31st 2026.


Ben Kapon
Kela Research and Strategy
+972-52-6100006
benk@ke-la.com
Report this content

If you believe this article contains misleading, harmful, or spam content, please let us know.

Report this article