Drooid Logo
Back to story perspectives

Full Breakdown

International Law Enforcement Disrupts Two Sophisticated Cybercrime Syndicates

8/27/2026, 9:37:27 PM

Coordinated Operations Target TeamPCP and QTFY

Australian authorities, working with the U.S. Federal Bureau of Investigation (FBI), arrested two Western Australians and charged them with 14 offences after a joint probe linked them to the supply-chain attack group TeamPCP. In a separate U.S. operation, the FBI’s San Diego field office seized three domains used by the China-linked hacking platform QTFY, which authorities say enabled attacks on government agencies and critical infrastructure worldwide.

Background & Context

TeamPCP is alleged to have inserted malicious code into open-source repositories, allowing the code to be incorporated unknowingly into the systems of more than a thousand organisations. The compromised software enabled the theft of over 500,000 user credentials and the exfiltration of at least 300 GB of data.

QTFY is described by U.S. officials as a network of tools—QScan and QTRouter—used by actors linked to the People’s Republic of China to hide attack origins, infiltrate IoT devices, and route traffic through a botnet. The group allegedly sold access to its infrastructure to Chinese state agencies.

Key Figures & Groups

  • Ruben Ian Thomson — 21, alleged leader of TeamPCP.
  • Louis Michael Gaebler — 23, alleged member of TeamPCP.
  • Australian Federal Police (AFP) — lead Australian investigative agency.
  • Western Australia Police (WAPF) — state partner in the raids.
  • FBI — U.S. federal partner in both investigations.
  • FBI Director Kash Patel — commented on QTFY’s tools.
  • Special Agent Brett Lally — provided details on QTFY’s botnet.
  • Assistant Director Brett E. Leatherman — identified the arrested men as TeamPCP members.

Timeline

  • April 2026 – AFP and FBI receive tip-offs about a supply-chain attack syndicate.
  • 26 August – Search warrants executed at properties in Cottesloe, Hamilton Hill and Mandurah.
  • 27 August – Appearance before Perth Magistrates Court.
  • 18 September – Next court appearance for Gaebler.
  • Wednesday (date unspecified) – FBI announces seizure of three QTFY-linked domains.

Data & Statistics

  • 14 offences charged against the two Australian suspects.
  • Over 1,000 organisations potentially compromised by TeamPCP.
  • More than 500,000 credentials stolen and at least 300 GB of data exfiltrated.
  • Three domains seized that were hard-coded into QTFY’s malware.

Official Statements & Responses

Assistant Director Brett E. Leatherman noted that information from multiple threat-assessment companies proved crucial to the investigation.

Conflicting Reports & Gaps

Law enforcement has not confirmed the exact number of individuals, businesses or countries affected by TeamPCP’s supply-chain attack. An AFP prosecutor acknowledged that some victim organisations are Australian but could not specify the total scope. While the FBI attributes QTFY’s infrastructure to Chinese state actors, the precise financial flows and identities of all individuals involved remain unverified.

What’s Next

The two Australian suspects will appear before Perth Magistrates Court on 27 August, with a further hearing for Gaebler on 18 September. Police have extracted 100 TB of data and will continue forensic analysis, which could lead to additional arrests. In the United States, the FBI’s seizure of QTFY domains is expected to disrupt the group’s operations, though no charges have been announced. Ongoing international cooperation suggests further coordinated actions against transnational cybercrime groups.