Um ein optimales Surferlebnis zu gewährleisten, aktivieren Sie bitte JavaScript in Ihrem Webbrowser. Ohne JavaScript sind viele Website-Funktionen nicht verfügbar.


Gesamtzahl der Tests:
485,773,462
737,046
130,956

Zwei mutmaßliche TeamPCP-Hacker in Australien festgenommen

3. September 2026

Read also: authorities disrupt the Sality botnet; a Russian national charged over a malware phishing campaign; and more.

Aufrufe:1.5k Lesezeit:4 Min.

Zwei mutmaßliche TeamPCP-Hacker in Australien festgenommen

Australia arrests two alleged TeamPCP hackers

Australian police have arrested two men in Perth over their alleged involvement in the TeamPCP cybercrime group linked to attacks on software supply chains around the world.

Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, were arrested following an investigation conducted by Australian and US authorities. Thomson is accused of leading the group and faces several hacking and money-laundering charges. Gaebler faces charges related to computer hacking.

US authorities have charged Ruben Thomson with conspiracy to commit Computer Fraud and Abuse Act violations and obtaining information from a protected computer. He faces up to 5 years in prison and a fine of $250,000 if found guilty.

Authorities say TeamPCP targeted software tools and package registries, including Trivy, KICS and LiteLLM. The group allegedly stole more than 500,000 corporate credentials from compromised software development systems.

Australian police also say the group stole at least 300 GB of data from more than 1,000 organizations worldwide. The stolen information reportedly included cloud access keys and other sensitive infrastructure credentials.

Police have seized devices from both suspects and are investigating the amount of money they may have made from the alleged crimes.

A German man convicted after a cyber-attack on a Rosneft subsidiary

A 31-year-old man has been given a suspended sentence of one year and four months for his role in a cyber-attack on Rosneft Deutschland GmbH. A Berlin district court found him guilty of data espionage in two cases and computer sabotage. Authorities said he copied around 20 terabytes of company data and deleted other data during several attacks in March 2022. The stolen information was stored on a server in Romania but was never published.

The attack caused millions of euros in damage. Rosneft Deutschland had to take its systems offline and carry out a forensic investigation, which cost about €9.756 million. The company also suffered around €2.6 million in economic losses, including problems with transport logistics. The man said he carried out the attack as part of the Anonymous hacker collective. He claimed the group received a file containing passwords through a public chat server. He apologized in court and said he is no longer involved with Anonymous.

The court said the attackers did not intend to shut down the company but had recklessly accepted the risk of causing serious disruption. The verdict is not yet legally binding, and the man may also face a civil claim for damages.

A Russian national charged over a malware phishing campaign

US authorities have indicted a Russian national accused of running a phishing campaign that targeted about 80,000 freelancers between 2016 and 2017.

Searzhudin Tamirlanovich Aktulaev, 40, was arrested in Cyprus in May 2025 and later extradited to the United States. Prosecutors allege that he used 255 fake accounts on a freelance employment platform to send messages containing malicious Microsoft Excel files.

When opened, the files instructed users to enable macros, which then installed malware called TVRAT (aka TVSPY or TeamSpy) and DarkVNC. The malware allowed attackers to remotely control infected computers and steal login details and other personal information.

About half of the affected computers were reportedly located in the US. Prosecutors say the stolen data was later used for fraud and other criminal activity. Aktulaev is currently in federal custody and is scheduled to appear before a US District Judge on October 5.

ImmuniWeb Newsletter

Erhalten Sie Cybercrime Weekly, Einladungen zu unseren Events und Webinaren in Ihrem Posteingang:


Vertraulich und privat Ihre Daten bleiben privat und vertraulich.

An international police op disrupts the Sality botnet

An international law enforcement operation supported by Europol has disrupted the Sality peer-to-peer botnet that has infected computers around the world for more than 20 years.

The operation took place on August 31, 2026, and was led by US authorities. Officials said Sality had given criminals access to as many as one million infected computers at its peak. More than 11 million unique IP addresses have been linked to the botnet.

Authorities from the United States, Bulgaria, Hungary and Romania took part in the operation, with support from Europol and private sector partners. Police used the sinkholing technique to cut off the botnet’s communications and disrupt its control system.

Sality has been active since 2003 and has been used to spread malware, steal cryptocurrency and support cyber-attacks. Many of the infected computer owners were unaware that their devices had become part of the criminal network.

US and European authorities also seized several domains linked to Sality as part of the operation.

ImmuniWeb kann Ihnen helfen, Datenpannen zu verhindern und regulatorische Anforderungen zu erfüllen.

A fraudster jailed for SMS blaster fraud

A 43-year-old UK citizen has been sentenced to three years and eight months in prison after using sophisticated technology to send fraudulent text messages to members of the public.

Mohammed Faiyaz Iqba was arrested on 24 May 2024 while sitting in a van at the Trafford Shopping Centre car park. Police had linked the vehicle to a large number of scam SMS messages being sent nearby.

Officers found several mobile phones and an SMS “blaster” hidden inside specially built compartments in the van. The equipment acted as a fake mobile antenna, allowing messages to bypass normal network security and reach nearby phones.

The messages, including fake Royal Mail texts, were designed to trick people into giving away payment and personal information. Police also found 7,859 compromised payment card details on Iqbal’s phones. A search of his home uncovered more banking information and three fake UK driving licenses, which were used to create impersonation bank accounts.

Iqbal pleaded guilty at his first hearing on 9 March 2026. He was sentenced to three years and eight months in prison. The judge set a five-year and six-month sentence, which was reduced by one third because of his guilty plea.

Another UK citizen, Milan Ibrahim, 68, has been sentenced to 6.5 years in prison for running an illegal IPTV business that made nearly £1 million (€1.14 million) in three years. He illegally streamed copyrighted content from companies including the BBC, ITV, Sky and the Premier League. Police seized and shut down all 80 servers used in the operation. Ibrahim will also face proceedings to recover his criminal profits.

Was kommt als Nächstes?

Sprechen Sie mit einem Experten