News
Global Headlines
500,000 credentials stolen: Two Australians charged in massive global cybercrime case

Just Earth News | @justearthnews | 28 Aug 2026, 04:22 am Print

500,000 credentials stolen: Two Australians charged in massive global cybercrime case Cyber Security

Two Australians charged over 500,000 stolen credentials in cybersecurity network bust.

Two men from Western Australia have been charged following a joint investigation by the Australian Federal Police (AFP) and Western Australia Police Force (WAPF), conducted in parallel with the US Federal Bureau of Investigation (FBI), into a sophisticated cybercrime syndicate that allegedly developed malicious open-source software used to target thousands of organisations worldwide.

The AFP charged the two men with a combined 14 offences on August 26, 2026, after executing search warrants in Perth with WAPF and assistance from the FBI, according to a statement issued by the AFP.

The men, aged 21 and 23, are scheduled to appear before the Perth Magistrates Court on August 27.

Police allege the men were part of a highly organised cybercrime syndicate involved in large-scale offences, including data intrusion, identity crime and cryptocurrency-based money laundering.

The parallel investigations began in April 2026 after the AFP and FBI received information from multiple cyber threat assessment companies about a syndicate that allegedly inserted malicious code into software available through an open-source repository.

The infected software was allegedly downloaded and used unknowingly by developers before being distributed across computer systems belonging to organisations in the government, academic and private sectors.

According to police, the malicious software enabled the syndicate to infiltrate targeted organisations and steal sensitive information, including user credentials and authentication materials.

Investigators estimate that the malicious code may have compromised more than 1,000 organisations globally, resulting in the theft of more than 500,000 credentials and the exfiltration of at least 300 gigabytes of data.

Police said the compromise of a small number of trusted software components had a significant global impact, with financial losses so far including remediation costs estimated to run into hundreds of millions of dollars.

Investigators from the AFP, FBI and WAPF allegedly linked the two Western Australian men to the syndicate.

Search warrants were executed on August 26 at properties in Cottesloe, Hamilton Hill and Mandurah. The two men were arrested, while electronic devices and other items were seized for forensic examination.

Police allege the men were principal participants in the syndicate's activities and received cryptocurrency payments for their roles. The value of the alleged payments remains under investigation.

Charges against 21-year-old Cottesloe man

The 21-year-old Cottesloe man was charged with:

  • One count of possessing data with intent to commit a computer offence, contrary to section 478.3(1) of the Criminal Code (Cth), carrying a maximum penalty of three years' imprisonment.
  • Four counts of unauthorised modification of data with intent to commit a serious offence, contrary to sections 477.1 and 372.1 of the Criminal Code (Cth), each carrying a maximum penalty of five years' imprisonment.
  • One count of supplying data with intent to commit a computer offence, contrary to section 478.4(1) of the Criminal Code (Cth), carrying a maximum penalty of three years' imprisonment.
  • One count of failing to comply with a 3LA order, contrary to section 3LA of the Crimes Act 1914 (Cth), carrying a maximum penalty of 10 years' imprisonment.
  • One count of dealing with proceeds of crime, money or property worth $100,000 or more, contrary to section 400.4(1) of the Criminal Code (Cth), carrying a maximum penalty of 20 years' imprisonment.

Charges against 23-year-old Mandurah man

The 23-year-old Mandurah man was charged with:

  • One count of possessing data with intent to commit a computer offence, contrary to section 478.3(1) of the Criminal Code (Cth), carrying a maximum penalty of three years' imprisonment.
  • Four counts of unauthorised modification of data with intent to commit a serious offence, contrary to sections 477.1 and 372.1 of the Criminal Code (Cth), each carrying a maximum penalty of five years' imprisonment.
  • One count of supplying data with intent to commit a computer offence, contrary to section 478.4(1) of the Criminal Code (Cth), carrying a maximum penalty of three years' imprisonment.

A large volume of seized data is undergoing forensic examination, and the investigation remains ongoing. Police said further arrests and charges have not been ruled out.

AFP Commander Graeme Marshall said the agency remained committed to working with domestic and international partners to identify, disrupt and dismantle criminal syndicates operating cybercrime networks on a global scale.

“Cybercrime knows no borders and is a growing threat globally,” Marshall said, adding that cooperation and intelligence-sharing between law enforcement agencies were critical to disrupting cybercriminal networks.

He said information provided by cyber threat assessment companies had proved crucial to the investigation.

FBI Cyber Division Assistant Director Brett E. Leatherman said the arrests demonstrated the FBI's international reach and the strength of its partnerships with overseas law enforcement agencies.

“These men are allegedly members of the cybercriminal group TeamPCP, whose malicious code potentially compromised more than a thousand organizations worldwide,” Leatherman said.

“We are proud to work with the Australian Federal Police and the Western Australia Police Force to impose cost on criminal actors and combat the growing threat of software supply-chain attacks.”

WAPF Acting Commander Peter Foley described the disruption as a significant development for law enforcement and the Western Australian community.

“It shows the prevalence of cybercrime in our community and that cybercriminals live amongst us,” Foley said.

Police urged businesses and individuals to report cybercrime regardless of the scale of the incident, saying early reporting and cooperation can help investigators identify offenders, support victims and mitigate the wider impact of cybercrime.

Authorities also urged organisations and individuals to ensure their cybersecurity measures and computing infrastructure remain up to date.