Skip to main content
[TIMESTAMP: 2026-07-24 13:49 UTC] [AUTHOR: Runtime Rebel Intel] [SEVERITY: MEDIUM]

Europol Targets 'The Com' Network: 4,340 URLs Flagged for Removal

MEDIUM Threat Intel #Europol
AI-generated analysis
READ_TIME: 4 min read
Primary source: bleepingcomputer.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

// executive briefing tl;dr
  • [01] Europol flagged 4,340 URLs associated with The Com to mitigate physical violence, extortion, and doxing risks globally.
  • [02] Content hosted across 17 platforms including social media and messaging apps was identified as violating extremist content regulations.
  • [03] Organizations should monitor for associated social engineering tactics and cooperate with law enforcement on content removal requests.

Advertisement

Overview of the Multi-Platform Crackdown

Europol has spearheaded a coordinated effort to dismantle the online infrastructure of a decentralized and violent extremist network known as “The Com.” In a multi-week operation, the Europol European Counter Terrorism Centre (ECTC) and the EU Internet Referral Unit (EU IRU) flagged 4,340 URLs for removal across 17 different online platforms, according to BleepingComputer. The operation, which ran from early May to mid-June 2024, targeted content that violates regulations regarding the dissemination of terrorist and violent extremist material.

While not a traditional APT in the sense of nation-state espionage, The Com represents a hybrid threat that bridges the gap between digital cybercrime and physical violence. The network is described as a loosely organized ecosystem of nihilistic groups that engage in a variety of harmful activities, including the glorification of terrorism, the recruitment of minors, and the orchestration of physical attacks against targets.

Understanding The Com Network Extortion Tactics

The groups within The Com utilize a specific set of behaviors that differentiate them from typical cyber-criminal organizations. Their primary objective is often social disruption or personal vendettas rather than purely financial gain, although extortion remains a core component of their operations. The Com network extortion tactics frequently involve “doxing”—the public release of private information—and “swatting,” where false reports are made to emergency services to trigger an armed police response at a victim’s residence.

Technically, these actors often rely on Phishing and social engineering to gain access to the accounts of their victims. Once access is obtained, they leverage the compromised data to threaten individuals, often demanding payments or the performance of specific acts to prevent the release of sensitive information or the continuation of physical harassment. The decentralized nature of the network makes it difficult to attribute specific actions to a single leader, as various subgroups often collaborate or splinter based on shifting alliances.

Technical Referral and Removal Process

The Europol EU IRU serves as a central hub for identifying and referring extremist content to service providers. During this operation, the unit focused on content that promoted “nihilistic” ideologies—a hallmark of The Com. The referral process relies on the voluntary cooperation of platforms to enforce their own terms of service and comply with the EU Regulation on addressing the dissemination of terrorist content online (TCO Regulation).

The 17 platforms involved in this crackdown span social media, file-sharing services, and messaging applications. By flagging these URLs, Europol aims to disrupt the TTP used by The Com to recruit new members and coordinate “simming” (physical assaults filmed for online clout). This disruption is vital for preventing the normalization of these violent subcultures within mainstream digital spaces.

How to detect The Com social engineering and harassment

For a SOC or threat intelligence team, identifying threats originating from The Com requires monitoring for indicators of targeted harassment rather than just malware deployment. Defenders should look for specific patterns such as sudden spikes in account recovery attempts, unauthorized access to employee PII (Personally Identifiable Information), and coordinated social media campaigns against specific staff members. Because these actors frequently use Identity & Access vulnerabilities to fuel their doxing campaigns, enforcing strict multi-factor authentication and monitoring for unusual account activity are essential defense layers.

Defensive Recommendations

Security professionals should treat the activities of The Com as a multi-vector threat that encompasses both digital and physical safety. Organizations should consider the following mitigations:

  • Enhance Executive Protection: High-profile individuals within an organization should be briefed on the risks of doxing and swatting. Encourage the use of privacy services to remove PII from public data broker sites.
  • Incident Response Integration: Ensure that corporate security protocols include a bridge between the SOC and physical security teams to handle threats like swatting or simming effectively.
  • Platform Cooperation: If an organization identifies content related to The Com on their own hosted platforms, they should proactively utilize the referral mechanisms provided by agencies like Europol or local law enforcement.

By disrupting the digital presence of these groups, law enforcement agencies like Europol reduce the reach of extremist ideologies and protect potential victims from coordinated online and offline harm.

Related: The Com: Analyzing the Intersection of Cybercrime and Physical Violence, European Police Dismantle €50 Million Crypto Investment Fraud Ring

Advertisement

Advertisement