Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos
Two men have been arrested and charged with a combined 14 counts in connection with TeamPCP, a group linked to software supply-chain attacks that caused disruption over several months. Private researchers helped crack the case by connecting a suspect to leaked passwords and an old gaming profile.
Why this matters: Private researchers found these suspects before law enforcement did, using a leaked password and a decade-old gaming handle. That is notable on its own. Supply-chain attacks are serious because they do not just hit one target — they hide inside software that thousands of organizations trust and install. If the people delivering your tools are compromised, everything downstream is too. Arrests are a good outcome here. But the months of chaos before them are the part worth sitting with.
Who should care: Cybersecurity · Privacy officers · Administrators
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.