The Com, short for The Community, is a loosely organized, primarily English-speaking cybercriminal ecosystem rather than a single centrally directed intrusion set. It is widely described as a decentralized network composed largely of young participants, including minors, with overlapping membership across hacking, SIM swapping, extortion, fraud, harassment, sextortion, and real-world violence. Security reporting and law-enforcement assessments consistently place many prominent English-speaking social-engineering-focused threat clusters within or adjacent to this milieu, including links or overlap with Scattered Spider, Lapsus$, ShinyHunters, BlackFile, Pink, and related splinter brands. The Com is commonly characterized as having multiple overlapping subsets, often referred to as Hacker Com, Extortion Com, and IRL Com. Hacker Com encompasses corporate intrusions, credential theft, phishing, SIM swapping, and data theft. Extortion Com is associated with coercion, sextortion, and exploitation-driven criminal activity. IRL Com refers to actors involved in offline intimidation and violence, including swatting and violence-for-hire. Reporting indicates these categories are porous, with individuals frequently participating across more than one subset and moving fluidly between cyber-enabled fraud, extortion, and physical-world coercion. Operationally, The Com is strongly associated with social engineering as an initial access discipline. Commonly reported tradecraft includes impersonation of IT or help-desk staff, voice phishing, SMS phishing, email phishing, MFA interception, SIM swapping, credential theft, and abuse of legitimate identity and SaaS platforms. Actors linked to this ecosystem have repeatedly targeted enterprise identity providers and cloud applications, including Okta, Microsoft 365, Salesforce, SharePoint, and OneDrive, then used compromised accounts for data exfiltration, internal messaging, and extortion. The ecosystem is also associated with rapid rebranding, infrastructure churn, and the emergence of short-lived extortion brands that preserve the same underlying tactics. The Com has been linked to financially motivated intrusions across a broad range of sectors, including retail, hospitality, telecommunications, technology, aviation, healthcare, finance, and other enterprise environments. Victimology often reflects opportunistic targeting of organizations with exploitable help-desk processes, weak identity verification, or valuable cloud-hosted data. Several Com-linked actors have specialized in stealing data rather than deploying encryption, although overlap with ransomware affiliates and extortion operations has also been reported. A distinguishing feature of The Com is the convergence of cybercrime with coercive and violent behavior. Law-enforcement and industry reporting describe associated actors using swatting, doxing, threats, brickings, arson, kidnapping, shootings, and other forms of intimidation, sometimes as paid services and sometimes as retaliation, status-seeking, or internal discipline. This violence-for-hire dimension has made The Com notable not only as a cybercrime ecosystem but also as a broader criminal network in which online disputes and extortion can spill into offline harm. The ecosystem is also repeatedly associated with the exploitation and recruitment of young people through online communities, including gaming platforms, chat services, and social media. Researchers and law enforcement have described grooming, sextortion, and child sexual exploitation as recurring features in some parts of the network, alongside status-driven subcultures that reward notoriety, humiliation of victims, and escalation. Europol has cited The Com as an example of a decentralized online community in which violence can become a means of gaining recognition, and as illustrative of the blurred boundaries between criminality, violent extremism, and nihilistic online subcultures. Attribution of specific operations to The Com should be treated carefully because it functions as a diffuse social and criminal environment rather than a single command structure. Nonetheless, high-confidence reporting consistently identifies it as a major feeder ecosystem for contemporary English-speaking social-engineering and extortion actors, especially those that rely on credential theft, cloud compromise, data extortion, and intimidation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A decentralised online extremist community where actors move fluidly between extremist narratives, misogyny, nihilism, criminality and terrorist propaganda, with violence used for status, visibility and social capital.
A decentralized cybercriminal network described as likely affiliated with Pink in this campaign.
A decentralized threat network with which the Pink extortion brand is affiliated.
Broader cybercriminal community associated with Scattered Spider members and high-profile cyber theft activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.