# The Com

> As of 2026-08-26, The Com is a threat actor tracked by Threadlinqs Intelligence across 9 threats spanning threat intel, data breach, threat actor. Also known as Cyber Com. ATT&CK coverage spans 92 techniques across 16 tactics in 9 of 9 tracked threats. Most-observed techniques: T1657 (Financial Theft), T1078 (Valid Accounts), T1530 (Data from Cloud Storage).

- **Tracked threats:** 9
- **Categories:** THREAT_INTEL, DATA_BREACH, THREAT_ACTOR, CAMPAIGN
- **Also known as:** Cyber Com
- **As of:** 2026-08-26

## ATT&CK techniques observed

92 techniques observed across 9 of 9 tracked threats. Tactics: Credential Access (14), Resource Development (11), Initial Access (10), Discovery (8), Impact (7), Persistence (7).

- [T1657](https://intel.threadlinqs.com/technique/T1657) Financial Theft — Impact — observed in 9 of 9 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 8 of 9 tracked threats
- [T1530](https://intel.threadlinqs.com/technique/T1530) Data from Cloud Storage — Collection — observed in 8 of 9 tracked threats
- [T1566](https://intel.threadlinqs.com/technique/T1566) Phishing — Initial Access — observed in 8 of 9 tracked threats
- [T1567](https://intel.threadlinqs.com/technique/T1567) Exfiltration Over Web Service — Exfiltration — observed in 8 of 9 tracked threats
- [T1589](https://intel.threadlinqs.com/technique/T1589) Gather Victim Identity Information — Reconnaissance — observed in 8 of 9 tracked threats
- [T1213](https://intel.threadlinqs.com/technique/T1213) Data from Information Repositories — Collection — observed in 7 of 9 tracked threats
- [T1552](https://intel.threadlinqs.com/technique/T1552) Unsecured Credentials — Credential Access — observed in 7 of 9 tracked threats
- [T1588](https://intel.threadlinqs.com/technique/T1588) Obtain Capabilities — Resource Development — observed in 7 of 9 tracked threats
- [T1621](https://intel.threadlinqs.com/technique/T1621) Multi-Factor Authentication Request Generation — Credential Access — observed in 7 of 9 tracked threats
- [T1087](https://intel.threadlinqs.com/technique/T1087) Account Discovery — Discovery — observed in 6 of 9 tracked threats
- [T1098](https://intel.threadlinqs.com/technique/T1098) Account Manipulation — Persistence — observed in 6 of 9 tracked threats
- [T1204](https://intel.threadlinqs.com/technique/T1204) User Execution — Execution — observed in 6 of 9 tracked threats
- [T1528](https://intel.threadlinqs.com/technique/T1528) Steal Application Access Token — Credential Access — observed in 6 of 9 tracked threats
- [T1539](https://intel.threadlinqs.com/technique/T1539) Steal Web Session Cookie — Credential Access — observed in 6 of 9 tracked threats

## Tracked threats

- ["The Com" cross-platform criminal ecosystem: Discord/Telegram/Roblox/Minecraft/X abused for malware distribution, extortion, and predatory recruitment](https://intel.threadlinqs.com/threat/TL-2026-2155) — HIGH
- [Europol Project COMPASS Disrupts "The Com" Network Turning Teen Hackers Into Extortionists and Violent Offenders](https://intel.threadlinqs.com/threat/TL-2026-1734) — HIGH
- [Infinite Campus Salesforce Breach by ShinyHunters / UNC6040 — 137,100 K-12 School Staff Accounts Exfiltrated and Extorted](https://intel.threadlinqs.com/threat/TL-2026-0804) — HIGH
- [ShinyHunters Leaks 5.1 Million Panera Bread Customer Records](https://intel.threadlinqs.com/threat/TL-2026-0055) — HIGH
- [ShinyHunters Evolves TTPs: Vishing and Login Harvesting for SSO/MFA Bypass](https://intel.threadlinqs.com/threat/TL-2026-0054) — HIGH
- [ShinyHunters-Branded Extortion Campaign Expands with Vishing & SSO Attacks](https://intel.threadlinqs.com/threat/TL-2026-0045) — HIGH
- [SLSH Extortion Group - Swatting and Executive Harassment Tactics](https://intel.threadlinqs.com/threat/TL-2026-0035) — HIGH
- [ShinyHunters Extortion Campaign - Evolved Vishing and SSO Credential Theft](https://intel.threadlinqs.com/threat/TL-2026-0030) — HIGH
- [ShinyHunters SSO Vishing Campaign - Cloud Data Theft via Social Engineering](https://intel.threadlinqs.com/threat/TL-2026-0013) — CRITICAL

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/The%20Com
