Perth arrests reveal the supply chain blind spot in Australian cyber cover

The alleged attack raises questions over whether Australian cyber policies respond when a breach originates in third-party software or systems

Perth arrests reveal the supply chain blind spot in Australian cyber cover

Cyber

By Roxanne Libatique

A software supply chain attack allegedly orchestrated by two suburban Perth men has compromised more than 1,000 organisations globally, stolen over 500,000 credentials, exfiltrated at least 300 gigabytes of data, and generated remediation costs estimated in the hundreds of millions of dollars. For Australian insurance brokers, the case is a practical illustration of a systemic risk that market participants say is already arriving on policies that were not built to hold it.

The arrests

Ruben Ian Thomson, 21, of Cottesloe, and Louis Michael Gaebler, 23, of Mandurah, were charged on August 26, 2026, following a joint investigation by the Australian Federal Police (AFP), the Western Australia Police Force (WAPF), and the FBI that began in April 2026. Police executed search warrants at properties in Cottesloe, Hamilton Hill, and Mandurah, seizing electronic devices and other items for forensic analysis.

According to the AFP’s official media release, investigators were tipped off by multiple cyber threat assessment companies about a syndicate that allegedly inserted malicious code into software on an open-source repository, which was subsequently used – unknowingly – by other developers. Police allege infected software was distributed into computer systems across government, academic, and private sector organisations worldwide, enabling the syndicate to steal user credentials, authentication materials, and sensitive data.

FBI cyber division assistant director Brett E. Leatherman confirmed the arrests in a joint statement. “These men are allegedly members of the cybercriminal group TeamPCP, whose malicious code potentially compromised more than a thousand organizations worldwide. We are proud to work with the Australian Federal Police and the Western Australia Police Force to impose cost on criminal actors and combat the growing threat of software supply-chain attacks,” Leatherman said.

AFP commander Graeme Marshall said the case illustrated how cybercriminals had professionalised their operations. “Cybercrime syndicates are becoming increasingly organised and often operate like professional businesses, but our investigators are relentless in tracking down criminals who attempt to exploit digital anonymity to attack our community. The AFP’s partnerships extend to private companies as well and industry bodies are part of the solutions to cybercrime,” Marshall said.

Thomson faces a combined total of eight charges, including possession of data with intent to commit a computer offence, four counts of unauthorised modification of data with intent to commit a serious offence, supplying data with intent to commit a computer offence, failing to comply with a 3LA order – which carries a maximum penalty of 10 years’ imprisonment – and dealing with proceeds of crime worth $100,000 or more, which carries a maximum penalty of 20 years’ imprisonment. Gaebler faces six charges covering the same categories minus the 3LA and proceeds counts. Both appeared before the Perth Magistrates Court on August 27, 2026. The investigation remains ongoing and further arrests and charges have not been ruled out.

What the market is already saying

Supply chain compromises are not a theoretical concern for Australian underwriters. Vicky Sheridan, senior claims specialist - cyber at AXA XL in Australia, pointed to exactly this exposure in Insurance Business Australia’s 2026 5-Star Cyber Report. “We’re also seeing growing exposure to cyber risks arising from third-party technology providers,” Sheridan said, citing a compromise of the Canvas learning management system that disrupted more than 9,000 educational institutions globally.

Sheridan added: “Such incidents underscore the extent to which localised disruptions can trigger cascading effects across interdependent organisations, with the potential to generate material operational, financial, and reputational impacts.” She said AXA XL had responded by developing a cyber catastrophe management framework. “It’s being built specifically to ensure we’re prepared not only for increases in claim volumes but also for systemic cyber events capable of impacting large parts of the digital ecosystem simultaneously,” she said.

Kieran Doyle, partner and head of cyber, data, and technology at Wotton Kearney, who provided independent analysis for the same report, noted a recent increase in claims activity. “The past few months have brought an increase in activity beginning with an influx of ransomware, with incident numbers running above the yearly average,” Doyle said. On non-ransomware incidents – including employee data theft and privacy breaches – he added: “The risk was always there but perhaps went undetected until now.”

The coverage gap brokers cannot defer

The mechanism of the alleged TeamPCP attack – a single compromise point cascading across 1,000-plus organisations – sits directly in coverage territory that Australian policy language has not been uniformly tested against. The way key terms such as “computer system” are defined in policy wordings may determine whether incidents involving cloud platforms or third-party vendors are covered. Some policies expressly include third-party networks within the definition of the insured’s computer system; others do not, and coverage gaps arise where policies do not clearly extend to outsourced or off-premises infrastructure. That distinction, documented in MinterEllison’s Perspectives on Cyber Risk report, is not incidental to supply chain attacks – it is the central coverage question they raise.

Insurers define “widespread events” or “catastrophes” in ways that limit aggregate exposure during coordinated attacks. If a single attack affects hundreds of policyholders simultaneously – as in a supply chain attack – coverage can be restricted, according to Digital Chiefs. The February 2026 youX incident provides the closest local precedent: a single vendor compromise generated notification obligations across approximately 800 broker firms and more than 90 lenders.

Market data frames the financial stakes

The Australian Signals Directorate’s (ASD) Annual Cyber Threat Report 2024-25 identifies the IT supply chain as a structural vulnerability, noting that an organisation’s supply chain can often be its weakest link and that malicious actors exploit trusted relationships between vendors and customers to steal information or deliver malware. Critical infrastructure accounted for 13% of all incidents responded to by the ASD’s Australian Cyber Security Centre (ACSC) in FY2024-25, up 2% from the previous year.

The cost trajectory reinforces the exposure. The ASD report found the average self-reported cost of cybercrime to large Australian businesses reached $202,700 per report in FY2024-25, a 219% year-on-year increase, while medium businesses averaged $97,200, up 55%. The Office of the Australian Information Commissioner (OAIC) recorded 1,205 data breach notifications in Australia in the 2025 calendar year – the highest total since mandatory reporting began in 2018, an 8% rise from 2024 – with 716 of those attributed directly to malicious or criminal attacks.

Questions for the renewal conversation

The incident also highlights the importance of understanding how statutory reporting obligations interact with cyber policy conditions. Australia’s Cyber Security Act 2024 introduced mandatory reporting requirements following certain ransomware payments. Organisations affected by an undetected software supply-chain compromise may also need to consider how delayed discovery interacts with policy requirements around notification, cooperation, and incident response, depending on the wording. The alleged use of cryptocurrency for payments adds a further complication for post-claim subrogation. The AFP confirmed the value of payments made to the accused is still under investigation.

Brokers should examine whether clients’ policies respond to losses originating in third-party software components the client did not control, whether systemic risk clauses limit or exclude coverage where the same attack affects multiple policyholders simultaneously, and whether the ASD’s verified cost benchmarks – $97,200 for medium businesses and $202,700 for large businesses per incident, before remediation – are reflected in the coverage limits currently placed.

As Sheridan observed in the context of third-party incidents, the potential to generate material operational, financial, and reputational impacts is not confined to the organisation where a breach originates. The TeamPCP case – with losses estimated in the hundreds of millions of dollars, more than 1,000 affected organisations, and at least 300 gigabytes of exfiltrated data – is a test of whether that understanding is embedded in the policies Australian brokers are placing.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!