Europol Pulls 4,340 Links Tied to 'The Com' Extortion Network

A nine-country push targets an online ecosystem that grooms minors, spreads violence manuals, and has been linked to ransomware attacks on Marks & Spencer and Las Vegas casinos.

ThreatVectr Newsdesk· 4 min read
Aerial 16:9 view of a large modern glass office complex at dusk, lights glowing from within, surrounded by a network of faintly glowing lines radiating outward
Share

Key points

  • Europol flagged 4,340 web addresses for removal between June and July 2026, in a coordinated push against content produced by a network called The Com.
  • Nine countries took part: Belgium, Finland, Hungary, Ireland, Luxembourg, the Netherlands, Portugal, Spain and Sweden.
  • The Com is a loose online network that grooms minors into self-harm, sexual abuse imagery, and violence, often through blackmail.
  • A wider year-long investigation, Project Compass, has produced 30 arrests, 179 identified suspects and 62 identified victims across 28 countries.
  • Groups tied to The Com have been linked to ransomware attacks on Las Vegas casinos in 2023 and on Marks & Spencer, Co-op and Harrods in 2025.

Europol says it has flagged 4,340 web pages for takedown in a multi-week operation against online material produced by a loose network known as The Com. The removal push ran from June to July 2026 and involved police from nine European countries.

The effort was organised by Europol's EU Internet Referral Unit and Spain's Intelligence Centre against Terrorism and Organised Crime, sitting under the European Commission's ProtectEU counterterrorism plan.

What is The Com?

The Com is not a single group. Europol describes it as a decentralised online community, short for "Community", where different factions overlap. Some push far-right and accelerationist politics, meaning ideologies that want to speed up the collapse of society. Others focus on cybercrime or the sexual extortion of children.

Recruitment happens on mainstream social media, messaging apps and gaming platforms. Targets, often teenagers, are then pulled into private chats where members pressure them into self-harm, filming abuse of themselves or others, or handing over intimate images that are later used as blackmail material.

What kind of content was removed?

The flagged URLs hosted violent videos, images of self-harm and suicide, child sexual abuse material (illegal imagery of minors), animal cruelty, and footage of real-world attacks. Europol also pointed to "manuals" circulated inside the community: step-by-step guides on grooming children, making improvised explosives, doxing (publishing someone's private details online) and swatting (making a fake emergency call to send armed police to a victim's home).

One recurring format is what members call a "manhunt": filmed street attacks on strangers, shared for status inside the group.

How is The Com organised?

Europol splits the network into four rough subgroups. The breakdown was first laid out in a February announcement, also covered by BleepingComputer.

Subgroup Focus
Offline Com Property damage, physical violence, terrorism
Cyber Com Network intrusions and ransomware
(S)extortion Com Coercing minors into sexual content and self-harm
764 Grooming young people into producing explicit material for blackmail

Two alleged 764 leaders, Prasan Nepal, 20, and Leonidas Varagiannis, 21, were arrested in April 2025 and face life sentences in the United States for running an international child exploitation ring.

How does this link to major ransomware attacks?

Cyber Com, the hacking wing, has been connected to some of the largest ransomware attacks of the past two years. Ransomware is malicious software that locks a company's files until a payment is made. Investigators have tied people in this orbit to the September 2023 breaches of Las Vegas casino operators and to the April 2025 attacks on UK retailers Marks & Spencer, Co-op and Harrods.

The wider investigation, Project Compass, launched in January 2025 and pulls in law enforcement from 28 countries. It has so far produced 30 arrests, 179 identified suspects and 62 identified victims.

What should parents and young users watch for?

Europol warns that the group's messages are hidden behind coded language and emojis that adults often miss. Practical steps worth taking:

  • Talk to teenagers about sextortion directly, and make clear they will not be punished for reporting it.
  • Treat unsolicited friend requests on gaming platforms and Discord-style chats with suspicion.
  • If a minor is being blackmailed with intimate images, report it to national police and to the platform. In the US, the FBI runs a dedicated sextortion tip line; in the UK, the Internet Watch Foundation and CEOP take reports.

Coerced victims are not the criminals here, and prosecutors have repeatedly said so.

© 2026 Threat Vectr