TeamPCP, the crew blamed for the Shai-Hulud worm and for poisoned open source tools such as Trivy, KICS and LiteLLM, lost its alleged leader to an arrest in Perth in August 2026. The public record already names him, the forum personas reporters tied to him and seven email addresses. We ran the seven addresses and four of the aliases on September 18, 2026, the day of the defendants' second court date. One Gmail address that KrebsOnSecurity tied to a forum account called "Sheep Stealing" returns 24 results, more than any other address in our study of 136 public-record addresses from 49 cybercrime cases. The address the record ties to the BreachForums persona returned no registrations in our lookup.
Nothing here unmasks anyone. Australian police, a US grand jury and several newsrooms did the naming. Both men are charged, not convicted, and are presumed innocent.
Where the TeamPCP case stands
The Australian Federal Police arrested two Western Australian men on Wednesday, August 26, 2026, after a joint investigation with Western Australia Police and the FBI. ABC News named them as Ruben Ian Thomson, 21, of Cottesloe, and Louis Michael Gaebler, 23. The Record reported that Gaebler lives in Mandurah and that police allege both were "principal participants" in the syndicate, paid in cryptocurrency.
A day later the US Attorney's Office for the Northern District of California announced a federal indictment against Thomson, filed on August 25 and unsealed on August 26.
| Jurisdiction | Defendant | Charges | Last reported status (August 27 hearing) |
|---|---|---|---|
| Australia (Perth Magistrates Court) | Ruben Ian Thomson, 21 | 8 offenses, including four counts of unauthorized modification of data with intent to commit a serious offense, possessing and supplying data to commit a computer offense, failing to comply with an order to hand over device passwords, and dealing with proceeds of crime worth $100,000 or more | Bail application withdrawn after the magistrate said she would not grant it; in custody |
| Australia (Perth Magistrates Court) | Louis Michael Gaebler, 23 | 6 related offenses | No bail application; in custody |
| United States (N.D. California) | Ruben Ian Thomson | Conspiracy, and obtaining information from a protected computer | Indicted; DOJ says he is in the custody of Australian authorities |
The Record reports a combined theoretical maximum of 82 years, 56 for Thomson and 26 for Gaebler, while noting that sentences often run concurrently. The DOJ release lists a maximum of five years per US count. Police allege the campaign compromised more than 1,000 organizations, exposed more than 500,000 credentials and led to the theft of at least 300 gigabytes of data. The Hacker News carries the full Australian charge list.
What happened on September 18? ABC reported that both men were remanded in custody until that date. As of September 23 we could find no published report of the outcome, and the DOJ release says nothing about extradition. We will update this section when a primary source reports it.
How the alleged TeamPCP leader was identified
TeamPCP is blamed for the Shai-Hulud worm and a long run of poisoned open source packages. Malpedia's actor entry describes supply chain attacks on Trivy, KICS and LiteLLM. The attribution work was published by Brian Krebs in "Two Alleged 'TeamPCP' Hackers Arrested in Australia" on August 27. His chain, compressed:
- Krebs reports that @pcpcats, the self-described TeamPCP spokesperson, used the forum names EllisD25/LSD on DarkForums, BulkDMT on Breachstars and Express on BreachForums. All of them advertised the same Tox or Session contact ID.
- Intel 471 found that Express registered on BreachForums with [email protected].
- SpyCloud found the same address registering a 2022 RaidForums account, ChristmasSnow, accessed almost entirely from Perth internet providers.
- Passive DNS on one of those Perth connections pointed to a household file server, and breach data plus a reused password connected that household to [email protected] and [email protected].
- [email protected] registered "Yolosolo17" on the Altenen forum in 2018 and the domain rubenthomson.com.
- [email protected] was tied to RaidForums and Hackforums accounts, a Microsoft account in the name Ruben Thomson, an Upwork profile and a 2026 X account called "Gone Fishing".
- Australia's business register lists companies tied to Ruben Thomson, including one named OPSEC Express, the same word as the BreachForums persona.
- In June 2025 someone using the name Ruben Thomson registered on HackerOne as Deadcatx3, a handle several security firms had flagged as a TeamPCP alias.
It is careful, well-sourced work drawing on Intel 471, SpyCloud, Constella, DomainTools and Epieos. For the broader pattern, see how hackers get caught.
What the seven public emails return
An email lookup checks whether an address is registered on about 175 services and returns profile details where they are public. Here is each address Krebs tied to Thomson, with the number of results the lookup returned.
| Address | How the record ties it | Results returned |
|---|---|---|
| [email protected] | "Sheep Stealing" and other forum accounts; Microsoft account in his name | 24 |
| [email protected] | Used from the same connection as the forum addresses (SpyCloud) | 12 |
| [email protected] | Altenen "Yolosolo17"; registrant of rubenthomson.com | 11 |
| [email protected] | Linked by a reused password | 8 |
| [email protected] | Reused password across accounts (Constella) | 7 |
| [email protected] | Airbnb profile for "Ruben" (Epieos) | 2 |
| [email protected] | BreachForums "Express" registration | 0 |

The registrations on [email protected] read like a working developer's life: Codecademy, Coursera, Replit, JetBrains, Treehouse, Hugging Face and Hack The Box on the learning and coding side; Adobe, Behance and Figma for design; Freelancer, Gumroad, Patreon and GoDaddy for selling and hosting; then Spotify, Duolingo, Grammarly, Pinterest, Tumblr, Chess.com, Firefox, Microsoft and X. Two of those line up with the record directly. Krebs reported a Microsoft account in the name Ruben Thomson and an X account on this address, and both services confirm a registration. Hack The Box, which also appears for [email protected], fits what the person Krebs interviewed as the TeamPCP leader said about growing up on capture the flag contests.
At the other end, the lookup found no registrations for [email protected], the address Intel 471 tied to the BreachForums "Express" account and SpyCloud tied to the RaidForums "ChristmasSnow" account. The record describes it only in those forum contexts, and our result is consistent with an address kept for forum use. A zero means nothing turned up in this lookup, not that no account exists. We look at that split across more cases in can a burner email be traced.
What the aliases return
A username search checks a handle across about 760 platforms. We ran the four aliases the record prints: deadcatx3, pcpcats, EllisD25 and Express.
deadcatx3: 21 exact-match results.
| Platform | Created | What it shows |
|---|---|---|
| HackerOne | June 2025 (per Krebs) | Display name "ruben thomson", exactly as Krebs reported |
| Malpedia | Actor entry listing DeadCatx3 as a TeamPCP synonym | |
| Hugging Face | July 5, 2025 | Presence and a creation date; nothing we attribute |
| X | May 11, 2024 | Self-reported location outside Perth |
| Other platforms | Presence only; no dates or names we attribute (the MySpace profile carries an unrelated name) |
The HackerOne result is the only identity-grade hit, and it is already public. The search reproduces it on a live profile. The X location is outside Perth, which does not match a Perth resident. Older accounts under the handle exist, but we leave them out: a handle's early history says nothing about who uses it now. Our guide to threat actor attribution with OSINT sets out that evidence ladder in full.
pcpcats: 8 exact-match results, including Telegram, GitHub, Threads and Instagram. The Instagram account was created in August 2024 and carries a name and location that fit nothing in the record. Krebs reports the @pcpcats X profile is banned. A famous name attracts copycats, so none of these results is attributed.
EllisD25: 45 exact-match results. The named profiles belong to unrelated people in several countries, with accounts going back to 2006. The rest show only the handle. Nothing in these results points to Perth, and a first name plus two digits is a handle many people pick.
Express: 316 exact-match results. A dictionary word hides its owner in a crowd, and none of these results says anything about this case. The Scattered Spider handle map shows the same effect across a whole crew.
What the TeamPCP footprint teaches
First, in this record, the persona and the alleged person behind it used different mailboxes. The lookup found nothing for the forum registration address, while the addresses used for coursework, design tools and music turn up widely, and one of them sits under a Microsoft account in the name Ruben Thomson, according to Krebs. The forum address started the trail only because forums logged it; the name came from the everyday side.
Second, a coined handle is a fingerprint and a common one is noise. deadcatx3 produced 21 results and the name Krebs had already reported. Express produced 316 results and nothing.
Third, the record anchors and the search illustrates. The HackerOne display name matters because the public record had already tied the handle to the name. On an unattributed handle, it would be a lead, never a conclusion.
FAQ
What is TeamPCP?
A cybercrime and data extortion group that emerged in late 2025, blamed for the Shai-Hulud worm and for supply chain compromises of Trivy, KICS and LiteLLM, according to Krebs and Malpedia. Its alleged leader was arrested in Perth in August 2026.
Who was arrested in the TeamPCP case?
Ruben Ian Thomson, 21, of Cottesloe, alleged by the FBI to be the group's leader, and Louis Michael Gaebler, 23, of Mandurah. Both were arrested in Western Australia on August 26, 2026 and face a combined 14 Australian charges. Thomson is also indicted in the Northern District of California. Both are presumed innocent.
What happened at the September 18 hearing?
Both men were remanded in custody to a September 18 appearance in Perth. As of September 23, 2026, no outcome had been published that we could find. We will add the result here once it is reported.
What is Deadcatx3?
A handle that security firms and Malpedia list as a TeamPCP alias. Krebs reported that a HackerOne account under that name was registered in June 2025 by someone using the name Ruben Thomson. A username search today still shows that display name.
To see how far your own everyday mailbox travels, run a free search on OSINTsearch: every platform, bios, display names and creation dates, with CSV, JSON or PDF export on paid plans when you need a report.



