Europol Flags 4,340 URLs Linked to The Com Network

Europol has flagged 4,340 URLs linked to The Com network, spotlighting the ongoing threat posed by this loosely organised group. The Com’s activities range from digital extortion to violent real-world crimes, and the group’s use of online platforms for recruitment and coordination is a growing concern for organisations worldwide.

Europol’s Referral Action Days Target The Com

Between June and July 2026, Europol and law enforcement partners across the UK, EU, and US targeted thousands of URLs used by The Com as part of the Referral Action Days. These efforts form a key part of Project Compass, launched in 2025, which aims to disrupt the online ecosystem supporting The Com and curb the spread of its influence.

Project Compass involves agencies from multiple nations, including Belgium, Finland, Hungary, Ireland, Luxembourg, the Netherlands, Portugal, Spain, and Sweden. This coordinated action reflects the transnational nature of The Com’s activities and the increasing cross-border collaboration required to combat them.

Details of the URLs and Their Content

The 4,340 URLs flagged for removal represent a broad array of harmful online material. According to Europol, these URLs were used to:

  • Recruit and groom new members, particularly minors, via social media, gaming platforms, and messaging apps
  • Spread propaganda and increase the group’s online status by showcasing extreme acts
  • Coordinate and instruct on digital extortion, doxxing, swatting, and real-life violence

The flagged content includes violent videos and images depicting self-harm, suicide, child sexual abuse material (CSAM), animal cruelty, and assaults. Europol highlighted the trend of users livestreaming these acts, encouraging online spectators, and then archiving the content for further dissemination. Notably, some material described as “blood walls”—art made with blood displaying an extorter’s alias—and “cut-signs,” where victims are coerced into self-harm, were found among the URLs. Manuals instructing followers on committing attacks, grooming, and extortion were also discovered.

The Com Network: Recruitment and Escalating Threats

The Com is not a single entity but a shifting collection of online groups, often comprised of teenagers and young adults. Their activities straddle both cyber and physical realms. Europol describes The Com as a “global threat,” with both minors and adults acting as victims and perpetrators.

The group’s recruitment efforts stand out for their aggressive targeting of vulnerable individuals. The more extreme and harmful the content posted by a member, the higher their status within The Com’s circles. This dynamic drives participants toward increasingly dangerous behaviour, both online and offline. Europol and its partners have documented a rise in violent physical acts, including shootings, stabbings, and arson, all linked to The Com’s operations.

Examples of their tactics include:

  • Grooming minors to commit crimes on behalf of the group
  • Livestreaming violent or illegal acts to recruit and intimidate
  • Circulating guides on extortion, swatting, and doxxing
  • Soliciting violence-as-a-service, such as contract attacks

Law Enforcement Attention and Timeline

Europol’s European Counter Terrorism Centre has received hundreds of requests for assistance related to The Com over the past two years. The coordinated Referral Action Days in June and July 2026 mark the latest phase in a sustained campaign. Law enforcement’s focus on The Com intensified following several high-profile incidents:

  • July 2025: The US FBI warns of increasing swat-for-hire and violence-as-a-service solicitations by The Com’s IRL (In Real Life) subset
  • 2025: The UK National Crime Agency issues alerts about the group’s recruitment of minors for cybercrime and real-world violence
  • 2025–2026: Multiple EU states seek Europol’s help to investigate attacks and online extortion linked to The Com

During the Referral Action Days, investigators from across Europe worked collaboratively to identify and flag URLs, with the aim of removing content as quickly as possible. While the flagged sites were scheduled for takedown, the cat-and-mouse nature of these communities means that new URLs often appear as fast as old ones are removed.

Current Exploitation Status and Ongoing Risks

At present, law enforcement continues to monitor for newly emerging content and URLs linked to The Com. The group’s decentralised structure and use of mainstream social platforms as well as encrypted messaging apps make it difficult to fully eradicate their online presence. Europol’s actions have disrupted recruitment and propaganda efforts, but The Com’s ability to adapt remains a concern.

For organisations, the ongoing threat lies in The Com’s willingness to blend cyber tactics like doxxing, extortion, and swatting with the recruitment of insiders or vulnerable individuals. This hybrid threat model can lead to reputational, operational, and even physical risks for targeted entities or staff.

Why This Matters for Organisations

The Europol takedown highlights how criminal groups increasingly use online platforms for multi-pronged attacks, blending social engineering with cyber and physical threats. The Com’s activities show that cyber threats are not limited to data theft or disruption but can escalate into real-world harm, making vigilance and cross-sector collaboration essential.

What Organisations Should Do Now

While the bulk of The Com’s direct activities target individuals, their tools and tactics—especially doxxing, extortion, and swatting—can spill over to affect organisations, particularly those with a public-facing presence or large youth audiences. Monitoring for emerging threats, reviewing incident response plans, and cooperating with authorities are critical steps in light of this ongoing risk.

Originally reported by www.theregister.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins
Category
Regulatory & Compliance
Published
Jul 24 - 2026
Post Tags
Cypro firewall showing robust network security
Secure your business.
Elevate your security, accelerate your growth. We take care of cyber security for high-growth companies, at every stage of their journey.
Get in touch

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call