# Australia Charges Alleged TeamPCP Members in One of the Country's Largest Supply Chain Cases


Two Australian nationals are facing federal charges over their alleged roles in a series of supply chain attacks attributed to a group tracked as TeamPCP — a case that marks a rare public prosecution in a country that has historically preferred quiet takedowns over courtroom spectacle.


The Australian Federal Police allege the suspects used compromised managed service provider (MSP) infrastructure to pivot into dozens of downstream business networks, harvesting credentials, staging ransomware, and in some cases maintaining persistent access for months before detection. The AFP worked alongside the Australian Signals Directorate and coordinated with international partners, according to charging documents.


---


## How You Hit a Thousand Companies by Compromising One


Supply chain attacks through MSPs are not new — the playbook dates at least to the 2017 NotPetya campaign and reached a particularly ugly peak with the Kaseya VSA breach in 2021. What makes TeamPCP notable isn't the technique but the target density.


MSPs are inherently high-leverage targets. A single compromised RMM (remote monitoring and management) platform can give an attacker authenticated access to the full client portfolio — often with admin-level permissions that took individual businesses years to lock down through their own internal policies. Attackers don't need to re-compromise each victim. They inherit the trust.


The AFP alleges TeamPCP exploited exactly this structure, using vendor-level credentials to move laterally across client environments without triggering traditional perimeter defenses. Several victims reportedly didn't learn of the intrusion until law enforcement notified them — not their own security tools.


---


## The Victims Didn't See It Coming


That's the part that should make every CISO uncomfortable. In supply chain compromises routed through MSP infrastructure, the victim organization's security posture is largely irrelevant. You can have a mature EDR deployment, segmented networks, and a fully-staffed SOC — and still get owned through the vendor account your IT provider uses to patch your servers at 2 a.m. on Sundays.


This isn't a theoretical risk. The 2020 SolarWinds campaign burned organizations that were, by most standards, security-conscious. The Kaseya attack hit MSPs with MFA deployed. The attack surface isn't inside your perimeter — it's in the trust relationships you've built outside it.


In the TeamPCP case, prosecutors allege the group specifically sought out MSPs serving sectors with high-value data but relatively lean in-house security: professional services firms, accounting practices, small medical groups, and regional government bodies. A deliberate targeting strategy, not opportunism.


---


## What the Charges Actually Say


The AFP has charged the two individuals with unauthorized modification of data, unauthorized access to computer systems, and conspiracy — standard Australian cybercrime statute charges under the Criminal Code Act 1995. The maximum penalties are significant: unauthorized access with intent to commit a serious offense carries up to 10 years.


Notably, the charges don't yet include ransomware deployment as a distinct count, suggesting either that prosecutors are building to it or that the criminal activity in scope was primarily data exfiltration rather than encryption-for-ransom. The distinction matters: exfiltration-focused attackers often maintain access longer and are harder to detect because they don't announce themselves with a ransom note.


The AFP has not publicly confirmed whether TeamPCP had connections to known international threat groups or operated as an independent criminal enterprise. That ambiguity — domestic actors vs. a locally-based arm of a larger organization — will likely dominate the early stages of the prosecution.


---


## Australia's Rare Willingness to Name Names


For context: Australia isn't known for high-profile cybercrime prosecutions at home. The AFP has historically collaborated on international operations (Operation Cronos targeting LockBit, Operation Endgame) without necessarily generating domestic cases. This prosecution suggests the AFP gathered enough domestic evidence to pursue charges locally — often harder than it sounds when attackers route through infrastructure across multiple jurisdictions.


The Australian government's 2023 cyber strategy explicitly called for more aggressive active cyber operations and prosecutions, and the Albanese government has followed through with increased ASD resources. If TeamPCP is a test case for that posture, it signals a meaningful shift: Australia intends to prosecute, not just disrupt.


---


## HackWire Analysis


The TeamPCP case lands at a moment when MSP security has never been more scrutinized — and still not scrutinized enough.


The managed service provider sector has a structural problem that no amount of vendor marketing resolves: the same centralized access model that makes MSPs operationally efficient makes them catastrophic when compromised. And the downstream victims — the hundreds of small businesses, law firms, and local government bodies that rely on MSPs precisely because they *can't* afford dedicated security teams — have no visibility into whether their provider's environment is hardened.


This is what other coverage is missing in the TeamPCP story: the supply chain risk here isn't exotic. It's baked into the business model. Every SMB that outsources IT to a managed provider is making a calculated bet that the provider's security hygiene is better than their own. Sometimes it is. Often, as TeamPCP allegedly demonstrated, it isn't.


The AFP charges are a meaningful signal, but prosecution alone doesn't fix the market. Australia's ACSC has previously issued guidance on MSP security, but guidance is voluntary. The more durable fix — mandatory security standards for MSPs handling sensitive sectors, similar to what CISA has begun pushing in the US — remains politically underdone in most markets.


For defenders: if you use an MSP, you need to treat them like any other third-party with privileged access. That means reviewing their SOC 2 reports or equivalent, confirming MFA on all vendor-side accounts that touch your environment, and asking directly: what happens when your RMM is compromised? If your MSP can't answer that question fluently, you already know the answer.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)