Actor Profile

The Com (short for "Community") is a loose-knit online cybercrime collective that targets children and teenagers through multiple specialized subgroups. The group recruits and grooms victims via online platforms including Snapchat, Telegram, and Discord, coercing them into self-harm, violence, and production of child sexual abuse material through blackmail and sextortion tactics. The Com is organized into distinct operational cells: Offline Com (property damage, violence, terrorism), (S)extortion Com (coercing minors into sex crimes, encouraging self-harm/suicide), Cyber Com (network intrusions and ransomware attacks), and 764 (a 2021-era subgroup focused on grooming youth for explicit content production and extortion). The collective operates internationally with a decentralized structure, motivated by peer recognition within the group and financial gain through extortion and ransomware operations.

TTPs (Tactics, Techniques, Procedures)

The Com employs social engineering techniques to establish trust with victims before transitioning to coercion and blackmail. Key TTPs include: initial contact via popular messaging platforms (Snapchat, Telegram, Discord) for victim identification and grooming; collection of private information and intimate images for use as leverage (T1589 - Gather Victim Identity Information); blackmail and extortion tactics threatening exposure to schools, parents, or public distribution (T1657 - Financial Theft); command and control through encrypted messaging applications (T1102 - Web Service); and collection and exfiltration of child sexual abuse material (T1530 - Data from Cloud Storage Object). The Cyber Com subgroup additionally conducts network intrusions and deploys ransomware (T1486 - Data Encrypted for Impact), as evidenced by attacks against Las Vegas casinos (September 2023) and UK retailers including Marks & Spencer, Co-op, and Harrods (April 2025).

Targets & Patterns

The Com primarily targets children and teenagers aged 13-17, with a focus on vulnerable young females who can be manipulated through social engineering and coercion. In the Swaddle case, 117 female victims worldwide were identified in this age range, though evidence showed victims as young as three years old. The collective exploits the digital habits of youth on popular social platforms where trust can be established before transitioning to exploitation. Secondary targeting includes enterprise networks for ransomware operations, with notable attacks against hospitality and retail sectors (Las Vegas casinos, UK retail giants). The dual-track targeting strategy suggests both financially motivated cybercrime (ransomware) and non-financial exploitation (sextortion for peer status within the group). Geographic scope is global, with victims and operations spanning multiple countries, indicating no specific regional limitation.

Historical Context

The Com collective has been active since at least 2021, when the 764 subgroup first emerged. The group gained significant law enforcement attention following high-profile ransomware attacks against Las Vegas casinos in September 2023. In April 2025, two alleged 764 leaders (Leonidas Varagiannis, 21, and Prasan Nepal, 20) were arrested and face life imprisonment for operating an international child exploitation ring. The same month, The Com was linked to ransomware attacks against UK retailers Marks & Spencer, Co-op, and Harrods. Law enforcement response escalated with Operation Project Compass, a year-long Europol-led initiative that resulted in 30 arrests and identification of 179 suspects in February 2026. In July 2026, Europol flagged 4,340 URLs for removal in a multi-week operation targeting Com-related content. The August 2026 sentencing of Justin Swaddle (arrested October 2023, investigation transferred to NCA January 2024) represents ongoing prosecution efforts against individual members of the collective's sextortion operations.

Defensive Recommendations

  • Implement robust parental controls and monitoring on devices used by minors, with particular focus on encrypted messaging applications (Snapchat, Telegram, Discord) where The Com operates
  • Deploy behavioral analytics to detect T1589 (Gather Victim Identity Information) patterns, including unusual information requests or rapid trust-building conversations targeting youth on social platforms
  • Establish mandatory digital safety education programs for children and teenagers focusing on recognizing grooming tactics, blackmail attempts, and safe reporting channels for exploitation
  • Monitor for T1657 (Financial Theft) and extortion indicators including threats to expose personal information, demands for additional content, or coercion language in communications
  • For enterprise environments, implement detection for T1486 (Data Encrypted for Impact) and monitor for social engineering attempts associated with The Com's Cyber Com subgroup, particularly targeting hospitality and retail sectors