The Australian Federal Police and the FBI arrested two men, aged 21 and 23, for their alleged leadership of the TeamPCP cybercrime group.

The group reportedly orchestrated a global software supply-chain attack by inserting malicious code into popular open-source developer tools. This campaign compromised more than 1,000 organizations worldwide.

The breach led to the theft of over 500,000 credentials. Total remediation costs for the affected entities are estimated in the hundreds of millions of dollars.

Downstream victims of the attack include Microsoft’s GitHub, OpenAI, and the European Commission.