"The Com": Dismantled – The Nihilist Network Targeting Minors and Businesses
Ransomware

Illustrative image generated with AI

"The Com": Dismantled – The Nihilist Network Targeting Minors and Businesses

Europol dismantled "The Com", a nihilist network targeting minors with CSAM and businesses with ransomware in a major transnational EU operation.

Text generated by artificial intelligence, published without human review. AI transparency

Introduction

Europol conducted an unprecedented transnational operation against "The Com", a constellation of violent nihilist groups organized into specialized factions. Over several weeks between June and July 2026, nine European Union countries – Belgium, Finland, Hungary, Ireland, Luxembourg, the Netherlands, Portugal, Spain, and Sweden – collaborated to remove 4,340 URLs containing child sexual abuse material (CSAM), incitement to self-harm, and subversive propaganda. The operation is part of the ProtectEU plan and extends the successes of Project Compass, which since 2025 has already led to 30 arrests and 179 identified suspects across 28 nations.

Technical Analysis

The Com's structure is leaderless and highly resilient. It is organized into four operational branches:

  • Offline Com: responsible for physical attacks, terrorism, and street assaults (so-called "manhunts").
  • Cyber Com: focused on cyber intrusions and ransomware. It has been linked to the attacks that paralyzed Las Vegas casinos in 2023 and British distribution chains in 2025.
  • (S)extortion Com: dedicated to the coercion of minors, production of self-harm material, and inducement to suicide.
  • 764: specialized in child sexual exploitation and the distribution of CSAM.

Recruitment and radicalization occur through social media, messaging apps, and gaming platforms. Content is conveyed using a cryptic language of emojis, abbreviations, and seemingly innocuous references to evade filters and moderation. Among the removed material are self-mutilation videos, grooming manuals, explosives instructions, doxing, and swatting. The Europol operation targeted content distribution at hosting providers and online platforms, based on proactive reporting by referral units (EU IRU, CITCO) and intelligence sharing among the 28 Project Compass countries.

Impact

The threat is critically severe both for the safety of minors and the integrity of businesses. The most exposed victims are adolescents driven to self-harm or suicide after sexual extortion. The massive spread of CSAM and nihilist propaganda has caused deep, often irreversible psychological and physical harm. On the economic front, ransomware attacks conducted by Cyber Com have generated million-dollar losses, demonstrating an ever-evolving offensive capability. Despite targeted arrests, the network's leaderless nature ensures a strong regenerative capacity: new cells reorganize rapidly, making complete eradication extremely complex.

Mitigation

To curb the phenomenon, Europol and national police forces have adopted a multi-level approach:

  • International coordination: the operation leveraged Europol channels and referral units for the rapid and simultaneous removal of URLs, based on cross-border agreements under Project Compass.
  • Prevention and awareness: families and minors must learn to recognize grooming signals, coded languages (emojis, encrypted slang), and extortion techniques. Promptly reporting suspicious content to platforms and authorities is essential.
  • Corporate defense: businesses must verify their detection capabilities (SIEM/EDR) through attack simulations to intercept ransomware threats and intrusions linked to Cyber Com tactics. Sharing indicators of compromise (IoCs) with law enforcement can accelerate the containment of malicious campaigns.

FAQ

1. What are the main factions of "The Com" and how do they differ?

The factions are four: Offline Com (physical attacks and terrorism), Cyber Com (ransomware and intrusions), (S)extortion Com (coercion of minors and self-harm), and 764 (child sexual exploitation). Each branch has an operational specialization, but all contribute to radicalization and the spread of nihilist propaganda.

2. Why did Europol have to remove thousands of URLs instead of just making arrests?

The decentralized structure and the rapidity with which content is recreated on new domains make arrests insufficient. Coordinated content removal hinders recruitment and the distribution of illicit material, interrupting the network's supply cycle.

3. What can companies concretely do to protect themselves from Cyber Com threats?

They must periodically test SIEM and EDR solutions with exercises that simulate the attack techniques associated with this group. Additionally, integrating specific threat intelligence feeds and collaborating with authorities to share information on detected IoCs is advisable.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsThe ComEuropol operationProject Compasscyber extortionransomware attackschild exploitationnihilist networkCSAM removal
Back to home