Europol Project COMPASS Disrupts "The Com" Network Turning Teen Hackers Into Extortionists and Violent Offenders — Threadlinqs Intelligence
As of 2026-07-28, Europol Project COMPASS Disrupts "The Com" Network Turning Teen Hackers Into Extortionists and Violent Offenders is a high-severity threat intel threat attributed to The Com, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 29 indicators of compromise.
Threat ID: TL-2026-1734 · Severity: HIGH · Status: ACTIVE · Category: THREAT_INTEL
Attribution: The Com · DESTRUCTION
Europol-led Project COMPASS, run with 28-29 partner countries including all Five Eyes members, has disrupted "The Com", a decentralized online ecosystem whose subgroups (Cyber Com,
Project COMPASS is a year-long, Europol-coordinated law-enforcement initiative (launched January 2025 by Europol's European Counter Terrorism Centre) targeting "The Com" (also called "The Community"), a loose, decentralized web of online subgroups rather than a single hierarchical organization. The Com operates across Discord, Telegram, Twitch, TikTok, YouTube, and gaming platforms such as Minecraft, using grooming and coercion to funnel minors and other vulnerable individuals into three broad, overlapping activity streams: Cyber Com (network intrusions, credential theft, ransomware deployment, and disruption of online services), (S)extortion Com / Extortion Com (coercing minors into producing CSAM, self-harm, and suicide content), and Offline Com / In Real Life Com (encouraging property damage and physical violence aligned with an accelerationist, nihilistic-violent-extremist worldview).
764, active since 2020-2021 and founded by Bradley Chance Cadenhead (alias 'Felix'/'Brad764') in Stephenville, Texas, is identified as one of the network's most notorious communities. Two of its subsequent leaders, Leonidas Varagiannis ('War') and Prasan Nepal ('Trippy'), were indicted in April 2025 for operating a global child-exploitation enterprise, including an invite-only sub-cell dubbed '764 Inferno', directing victims to commit self-harm and produce escalating abusive content used for blackmail.
The Cyber Com wing overlaps in industry and law-enforcement reporting with Scattered Spider (MITRE ATT&CK group G1015; aka Octo Tempest, UNC3944, Roasted 0ktapus, Storm-0875, Muddled Libra) — a native-English-speaking, largely teen/young-adult cybercriminal collective active since at least 2022 that recruits from The Com/The Community. Scattered Spider relies on social engineering (SIM swapping, MFA-fatigue/push-bombing, and help-desk-impersonation vishing) to bypass identity controls in Okta, AWS, and Microsoft 365 environments, then pivots to Active Directory credential theft, cloud-service abuse, and ransomware deployment. In 2025 Scattered Spider-linked actors adopted DragonForce ransomware — a group that pivoted from pro-Palestine hacktivism (est. August 2023) into a ransomware-as-a-service cartel operating the white-label 'RansomBay' affiliate program (80/20 revenue split) and reportedly absorbing RansomHub infrastructure. DragonForce-affiliated intrusions detonated against Marks & Spencer (initial access February 2025, encryptor deployed 24 April 2025 after months of Active Directory reconnaissance) and were claimed against Co-op and Harrods in May 2025. Earlier, BlackCat/ALPHV ransomware tied to Scattered Spider hit MGM Resorts and Caesars Entertainment in the September 2023 Las Vegas casino breaches, and in 2025 UK teenagers Thalha Jubair and Owen Flowers were charged by the National Crime Agency over the Transport for London (TfL) intrusion.
As of the most recent reporting, Project COMPASS has produced 303 arrests, 4 victims directly safeguarded, 626 identified/partially-identified victims, 179 identified/partially-identified perpetrators, and 9 joint awareness-raising activities, building on earlier February 2026 figures of 30 arrests, 179 identified suspects, and 62 identified victims. A coordinated nine-country referral action (Belgium, Finland, Hungary, Ireland, Luxembourg, Netherlands, Portugal, Spain, Sweden) flagged 4,340 URLs linked to The Com for platform takedown. No CVE/CVSS applies — this is a threat-actor/network disruption story, not a vulnerability disclosure — but the Cyber Com/Scattered Spider/DragonForce wing represents an actively exploited, ongoing intrusion and ransomware threat to enterprises, while 764 and its peers represent an active, ongoing child-safety and violent-extremism threat.
Target sectors: retail, hospitality, gaming, transport, technology, socialmedia, education
Target regions: North America, united kingdom, Europe, Oceania
Detections & IOCs
As of 2026-08-07, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 29 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, HIGH, threat intelligence, cybersecurity, T1589, T1598, T1583, T1585, T1588, T1588, T1566, T1190, T1133, T1078