Australian police have arrested two people accused of running the TeamPCP hacking campaign that hit OpenAI, hiring platform Mercor, and other tech companies.
The arrests follow a string of cyberattacks that surfaced earlier this year, tied to the TeamPCP name. The intrusions targeted tech companies that lean on widely used, high-profile open-source software - the common thread investigators drew between victims. OpenAI and Mercor are both named among the affected organizations, though other victims have not been publicly identified. Police have not yet detailed the charges or the scale of data exposed in the breaches.
The case is a reminder that popular open-source components are now a shared attack surface, not just a convenience. When one library or tool sits underneath dozens of companies, a single exploit chain can reach targets as different as an AI lab and a hiring platform. That a company as prominent as OpenAI got swept up in it says more about shared dependencies than about OpenAI's own defenses.
Whether these two are the architects of TeamPCP's campaign or just a couple of its operators is still unclear - the announcement tells us who got arrested, not how much damage was actually done.