← Back to Timeline
Podcast Transcript

Risky Business Features: Brian Krebs on TeamPCP Arrests

August 28, 2026 · ~29 min · risky.biz/RBFEATURES37

Speakers

00:05 - 1:27
James Wilson (Introduction)

Hey everyone, I'm James Wilson and welcome to this Team PCP focused episode of Risky Business Features. Today we are chatting with veteran cybersecurity journalist Brian Krebs of krebsonsecurity.com. Yesterday two men were arrested in Perth here in Australia over their alleged links to the Team PCP supply chain attacks. And so who better to join the show to talk about this than Brian Krebs? He's been investigating Team PCP since late last year. And in this interview he'll explain how he connected various online identities to the Team PCP hacks. And from there how he then connected those online identities to some real-world identities.

Now folks, it's very important to remember that everything we're talking about here is alleged, not proven. Just because someone is charged with a crime, it does not mean they actually committed it. So do keep that in mind.

So in this episode we're going to talk about Brian's contacts with Team PCP members, how the group was formed, and how Brian connected a bunch of dots together to figure out who these people might be. I'm going to drop you in here into the interview where Brian talks about the early conversations he had with Team PCP's self-styled spokesperson Ellis, who in the end turned out to be much more than just the group's mouthpiece. Enjoy.

1:29 - 3:23
Brian Krebs

Right, at the time we were chatting I was asking him a lot of questions about what he had gotten out of his participation with Team PCP and what he thought was good about it and if he would have done anything differently given another opportunity. Those kind of open-ended questions.

And he was pretty open about his motivations which he claimed were just a distraction from some of the things that he's been trying to get away from for a long time like drugs and just a scene that's just not good for him. Of course he didn't really manage to escape the clutches of the drugs as far as I could tell.

But at one point he started talking about what he wanted, how he wanted to end things. He didn't want... he wanted to go out on his own terms. And at that point he got really solemn and very kind of sullen about his life and at that point pretty much everything he said to me sounded like something you'd see in a suicide note, you know. Yeah and it was pretty dark and he was really unhappy with his life.

I didn't share with him by the way that I knew who he was in real life. At one point I asked him what would you say if I told you I knew who you were, but I never told him that. But I think he understood that he'd made a certain number of operational security mistakes that were going to catch up with him. And he was really kind of despondent about that.

3:23 - 4:22
James Wilson

Yeah. And important to remember here that we're talking about an individual that you identified at the time you knew him as Ellis. There's signals and reason to believe that they may be one of these people that have been picked up by the Australian Federal Police yesterday in Perth, but of course all of this is alleged involvements per the press release from the police.

But it's just super interesting that this actor to me has never felt like your more traditional hardened cybercrime member. Even some of the things you noted here in terms of they claimed that they only made about $20,000 out of their involvement with Team PCP. That just seems like a phenomenally small amount given the scale of what they're involved in. Like what's your sense of the character of the person that you met in this Signal chat versus the people you've met that have maybe different qualities?

4:23 - 7:06
Brian Krebs

Yeah, I didn't get a sense that there was any appreciation they had for the scale of the damage or the disruption that they were causing. I think Reuben was motivated by a desire to make things happen and to see what happened when they pushed things and saw how far they could push things. And really I think that was the bulk of his motivation beyond something he came back to a lot which was the camaraderie and the community that he found there.

And for me I come back to a few themes from this. And one is something that Reuben brought up a number of times in our conversations because it came up so often in his conversations with other members and in their public chats on the Matrix chats. And that was the theme of how many people in their group were struggling with serious narcotics abuse issues.

And so the abuse of hard drugs and pretty mind-altering drugs is not necessarily a strange thing for cybercriminals. In fact it's really common. But with this group especially I think you have almost like a devil-may-care attitude about not only protecting their own identity, but what the consequences of their actions may be.

So in that respect they're not that strange of a beast but they are different in a sense. I think that they were never any of them... it doesn't seem the Team PCP group, those core guys, I don't know that they were ever focused on the kinds of things that you see English-speaking threat actors getting really excited about which is status within the community or making a lot of money or proving that they achieved a certain success by whatever measurement the community of English-speaking cybercriminals tends to focus on as a metric for success. So I don't think that they were ever focused on that.

7:07 - 7:29
James Wilson

You mentioned an individual there Reuben which I'm assuming is referring to Reuben Thompson. Now that was one of the two people that were arrested in Perth yesterday. The police didn't release the names of them, but since then various media outlets have confirmed that one individual was Reuben Thompson. The other one was I believe a gentleman named Louis Gaebler. Is that right? Those are the two people that have come out in the media.

7:29 - 7:30
Brian Krebs

That's correct.

7:31 - 8:21
James Wilson

Yeah. So we'll talk about how you draw the connection between the person you were talking to as Ellis, their relation, the things that give you reason to believe that that is Reuben Thompson. And all the things you mentioned there about drug use is something that they told you in that Signal chat.

But you also talked about the fact this community, this group, and when I was reading your article that you've now published there's an interesting formation here of this group coming together and it centers around this Matrix chat group that was started by someone called Prepakis Georgios. So let's start there. Who is Prepakis Georgios? Who did this form? Who did it attract? And what was the function of this Matrix chat group initially?

8:22 - 11:15
Brian Krebs

So Prepakis Georgios, I don't know if that's the correct pronunciation of his name. He uses Twitter profile handle kernelstub. And this is a guy who's been pretty active in the malware research scene for several years. He's competed and done quite well in pwn2own and those kind of hacking competitions and bug bounties. So he's an accomplished security researcher that kind of just doesn't have a filter really. I mean like the guy just seems to turn out exploit code and new discoveries and vulnerabilities all the time.

And he doesn't seem to get too caught up in how those bugs are handled or who handles them. He just kind of drops them. And sometimes it's on LinkedIn a couple of weeks ago, a little less than a couple of weeks ago. He was posting something right before we went on like a two-week vacation. He's like hey I'm just posting this Apache RCE or something like that. Code execution vulnerability in a really widely used piece of software and he's like send me some comments or tell me what you think. Meanwhile threat actors are free to use this. And I'm going on vacation, bye.

Yeah so he set up this Matrix server dubbed the Cybercats. And I don't know if he created it for the Team PCP and friends or if he created it and then they just showed up. But I have to think that the people on the server created their own corresponding accounts, very similar names that were on these Matrix chats as names on Twitter accounts. And they've been talking about what they're chatting about in these Matrix chats on Twitter as well. And kernelstub is no exception there.

So I have to think that maybe this was set up for them. In any case, they've been using this Matrix server to chat pretty openly for the past two and a half months or so at least. And it's been interesting to be in there because it's a mix of what you would expect, right? A bunch of journalists lurking and security researchers and threat actors and they are some pretty interesting cats I should say in that chat.

11:16 - 12:04
James Wilson

Which, and this is where maybe it's good to spell out a little bit of the timeline here because there's a couple of question marks I still have around this. Because you were chatting with this individual Ellis even just up to a couple of weeks ago, from July onwards. But when you were first talking to them they'd said that they had wrapped up their involvement with Team PCP in March which would be before all the big things sort of kicked off, right? LiteLLM was not till late in March. Then there was Trivy. Then there was the GitHub compromise.

And this Matrix server you mentioned was active over the last couple of months. So how do we understand, I guess we start with this individual Ellis. Do you think they were originally founder or the leader of Team PCP? Did they really step back in March?

12:05 - 12:34
Brian Krebs

Yeah I think Reuben was kind of in on the ground floor as it were with this group and when they started some of their supply chain in late last year I think he was definitely a driving force with this group. And I tend to believe him maybe, he was pretty straight with me I think in our chats. I never got the sense that he was lying to me.

12:34 - 12:44
James Wilson

When did the Matrix chat actually get created and talk to me about some of the other actors that we saw in there? Because I think there was also C-Sec, which is Fulcrum Sec, PCP Casper.

12:44 - 13:05
Brian Krebs

Yeah there's about 32 image files that are open on my Mac right now. And I don't know which one of them has it, but somewhere there's a screenshot of kernelstub inviting these guys. I don't know when it was created. But the other question you had was who else was on it...

13:05 - 13:08
James Wilson

Yeah yeah there was some other actors in there, right?

13:08 - 15:39
Brian Krebs

Yeah. And so some of this has been difficult to tease apart. It's not always clear. First of all Reuben was constantly using different nicknames. Or changing his nickname. So it wasn't always clear what he was involved with. But I think he was being truthful when he said he stepped away from the day-to-day stuff earlier this year, only because it's clear from looking at the other members on the chat constantly asking like where the heck is Team PCP? Oh yeah I heard he was sleeping something off, you know whatever.

So I mean you can't run a cybercrime organization if you're just completely zonked out all the time, which he was. So I'm not going to say he wasn't involved in cybercrime and doing illegal stuff. I think he was up until he got arrested. But I don't think he was like pulling the strings or anything at that point.

But it was interesting because some of these guys had similar nicknames. Like there was another guy on the Matrix chat, PCP... not PCP Cat, PCP Casper. See I'm mixing them up. And he had a Twitter account where he talked about a lot of the same things. This individual who's apparently one of the people that was arrested in the last 24 hours was... at some point I started really digging into them and I thought look at this. They've got I don't know what it was. It was just many thousands of messages over the last two years on Telegram.

And I mean they were going off at every opportunity they could to talk about the Nazis and how great they were and the national Nazi party there in Australia. And I was just kind of blown away by how easy it was to figure out where this guy's hometown was just by looking at the stuff he was posting. So that didn't surprise me at all that he's one of the individuals arrested because along with Reuben, neither of them had any OPSEC as far as I can tell.

15:40 - 16:04
James Wilson

That's a good segue into the OPSEC part of here because when I read your teardown of the various aliases that you found, the first link to dual residents in South Africa and Australia, then tracing that Australia link... talk me through how this thread unravels. Where did you start pulling and where did it take you down the rabbit hole?

16:06 - 18:22
Brian Krebs

I started pulling just as I usually do on the forum names. The usual stuff, just whatever they happened to post as identifying information. And then in addition to that any kind of details they share about their personal life or their challenges or whatever they're interested in, all those things can be useful. But at some point I ran into a wall in my research and I thought well I think it's this guy, but I mean I can't hang anything on. This is weak sauce, right?

And I thought there's got to be something I'm missing here. And I think I went back and forth a couple times. And then I thought oh gosh, historic DNS. I mean I forgot I hadn't done any historic DNS lookups on any of the IP addresses that were tied to the forum nicknames that I knew he had used. And you could see he had used them if you were able to connect one handle change to another which wasn't that hard in his case.

So until I started doing that passive DNS I was just kind of feeling like I was 70% there, but yeah after that, after I was able to detect that one of the IPs that he used to access one of the cybercrime forums traced back to a family that had one of these home email and internet domain attached to the entire family's email addresses and everything.

So they had been at these IP addresses for over three years in some cases. And just pivoting on that once I figured the last name of the person I was looking at it became just a matter of time after that. Just pulling on threads and chasing down more stuff.

18:22 - 19:16
James Wilson

That's where it seems this really exploded for you. You found that family domain name from various sources like Facebook etc. You're able to find other family members. This is when you sort of draw this connection back to an individual called Reuben which you assume is Reuben Thompson, one of the people that was arrested yesterday alleged to be involved with Team PCP.

But I found it interesting just the depths that you go to in terms of it's not just the cybercrime forums. You're looking at things like Airbnb accounts which I found interesting. You found an Airbnb account again linked to an individual named Reuben Thompson. And he actually described himself as a web developer who went to school at University of Western Australia. And that's when you sort of drew the connection back to Ellis, right? Because he says in the Airbnb profile that his friends know him as Ellis. Was that a bit of an aha moment?

19:17 - 19:58
Brian Krebs

Oh it absolutely was. And I couldn't believe it and then I thought well all right what about this domain that is tied to the entire family's email addresses, because they all had domains. And I started looking into that and found just a ridiculous number of forum accounts associated with the passwords and the IP addresses used to access those accounts. So that is just... it was a staggering amount of information and as soon as we got the passive DNS stuff the rest of it took care of itself.

19:58 - 20:04
James Wilson

I was imagining that was a bit of a personally exciting moment of like oh you know dots finally line up.

20:05 - 20:51
Brian Krebs

It was because at that point I thought well we should kind of check to see what is this domain? What is this family domain? Is it a business? And sure enough it was tied to a business. But then I found yeah it's not only tied to a business, but it's tied to at least three different businesses that are in this kid's name including one called OPSEC Express, which when I found that I think I laughed for about five minutes straight. I thought that was the funniest thing I'd ever heard because Express was one of the nicknames he'd used on the forums. And I thought well if you're going to sell a service that ostensibly tries to teach people how not to get caught for their crimes, maybe don't use your forum nickname as your company name.

20:52 - 21:16
James Wilson

Yeah I mean it really feels like there are just so many OPSEC failures here. On the scale of OPSEC failures that you see is this like one of the most ridiculous, egregious, complete and utter fails of OPSEC? Or were there some measures where he tried to conceal his identity? How does this rank amongst the OPSEC fails that you've seen?

21:17 - 22:27
Brian Krebs

Yeah it's up there. I honestly think that he just stopped caring about the consequences or his own OPSEC or anything like that almost from the very beginning. Because if you're going to do that kind of thing it's not super difficult. Well let's just put it this way. It's a lot easier to do if you don't recycle your identity. Just start over. But that's really difficult for people in this community to do especially if they're relatively unknown. And they feel like they've gained some kind of currency in that community.

So I think to some degree he can say he wasn't part of the calm and he wasn't part of that community. But he absolutely was. And he was on these communities selling services to people in those communities. So I would say it wasn't that much of an aberration.

22:30 - 23:33
James Wilson

And so again I'm being careful here to make sure that we're very transparent that what we're talking about here is your observations of an individual that you've been observing that various signals lead us to believe there is a plausible link to this individual Reuben Thompson who was arrested yesterday alleged to be member of Team PCP. And we'll let the legal process sort out all of that in due course.

But one thing that we can talk to in concrete is you mentioned that this individual seems to have had very little regard for the consequences of their actions. But outside of the negative consequences of their actions there's actually been some positive outcomes of this in terms of they really did make the industry kind of wake up to the dumpster fire that we've all known the package registry system is for a long time. But they kind of lit the dumpster fire and said look it's on fire. You better go and put it out. So what can you say about the lasting good that's transpired out of this?

23:34 - 24:53
Brian Krebs

Yeah I can't argue with that at all. I think it's important to point out something I actually mentioned in the story, with Charlie Erikson from Aikido Security was talking about when he was discussing Team PCP. And it feels on target. And that is, say what you will about the havoc that the Team PCP caused and countless code pipelines and the endless credentials that they stole from half of the Fortune 500.

But they really did move, they did a lot to move the needle on supply chain security, at least as it relates to how most programmers and code maintainers etc. interact with platforms like NPM and GitHub. So in that sense their actions and repeated success at just pwning GitHub and the entire community over and over again I think really did push Microsoft to do the right thing. And you've seen the same kind of shifts with the introduction of cooldown periods in NPM and other public code repositories.

24:54 - 25:34
James Wilson

Yeah I mean it's good steps that I don't think would have been taken or given the prioritization if it weren't for these successive campaigns. But on the flip side alongside that lasting good there is still a lingering threat of this stockpile of creds, you know. Where is it? Who's got it?

And so to wrap up Brian, we'll let the legal process play out now for these two individuals that have been arrested yesterday in Perth. But what's your sense of what becomes now of Team PCP supply chain attacks? I'm sure it would be foolish to say we've seen the end of this, but I wonder if you have any sense of where this goes from here.

25:36 - 28:47
Brian Krebs

As much work as this story was for me it really only scratches the surface of a much much bigger series of stories. And I think, I hope to be able to share some of those in the coming weeks and months. Again some of that is out of my hands in terms of the timing.

But look there are a number of untold stories here that are really important. One of which is untangling the role of Shiny Hunters within this group which... I don't know if I'm sharing something scoopy here, but they, not very long ago at all, I think it was a couple weeks ago they completely hacked Team PCP and got access to their internal conversations and stole all kinds of data that they stole and ended up sharing that information with law enforcement and a bunch of people in the research community.

And so there was a period when one of the hackers involved in Team PCP, an Eastern guy goes by the handle Pricks who's been doxxed pretty thoroughly. He invited a Shiny Hunters member to join the group and that member ended up just downloading all the Team PCP stuff and leaking it. So I don't want to get too far into that story because it feeds into some other reporting I'm doing. But that was a pretty interesting wrinkle I thought.

And the other thing that I think we're going to see bubble up that comes out of this story which I think is good because it's an issue that needs to be talked about more broadly. But I will say this investigation has really opened my eyes in terms of just a number of people who are active in security roles at some pretty big companies that are doing things that actively assist threat actors in their breaches or provide them a safe privacy-focused environment for these threat actors to operate.

And one of the things I think we'll see from law enforcement as it relates to Team PCP and the fallout from this group is some action in targeting some of the security industry people which is probably not going to be a great news week for those companies. But I don't know if this has always been the case or if it's just gotten more so over the last few years. But there's just a lot of uncomfortable overlaps between people whose job it is to make life harder for the threat actors and the threat actors themselves. So I'll just leave it at that.

28:48 - 29:11
James Wilson

All right man. Well let's wrap it up there. We've been chatting back and forth for it must be months now on this. And so congratulations on being able to publish this work. And of course folks should head over to krebsonsecurity.com to read the entire incredible piece on this. But man you've piqued my interest now based on what you just said. So stay in touch and I hope I get to talk to you soon. But until then man get some sleep.

29:12 - 29:13
Brian Krebs

Thanks a lot man.

Key Takeaways

On Thomson/Ellis

On OPSEC Failures

On PCP Casper (Louis Gaebler)

On Group Formation

On ShinyHunters

On Lasting Impact

Teased Future Stories