The Com's Online Empire Just Lost 4,340 Entry Points
Here's the thing about decentralized networks: you can't storm a headquarters that doesn't exist. But you can make it significantly harder for them to function, and that's exactly what happened this week.
Europol has flagged 4,340 URLs for removal during a multi-week operation targeting "The Com" — a loosely organized network of nihilistic violent extremist groups that's been grooming minors, distributing child abuse material, and producing manuals on everything from murder to improvised explosives. The number alone tells you this wasn't some fringe corner of the internet. It was everywhere.
The operation ran between June and July 2026, involving investigators from nine European countries: Belgium, Finland, Hungary, Ireland, Luxembourg, the Netherlands, Portugal, Spain, and Sweden. Europol called them "Referral Action Days," coordinated by the agency's EU Internet Referral Unit (EU IRU) alongside Spain's Intelligence Centre against Terrorism and Organised Crime (CITCO). This wasn't a flash-in-the-pan raid. It was a sustained, cross-border effort tied into the European Commission's ProtectEU counterterrorism agenda.
The goal was straightforward: disrupt The Com's online ecosystem, limit the spread of nihilistic violent extremism content, and generate actionable investigative leads for law enforcement.
What The Com Actually Is
Europol describes "The Com" (short for "Community") as a decentralized network with no unified ideology. That's the thing that makes it so hard to pin down — there's no central leadership, no manifesto everyone agrees on. Some factions lean violent right-wing extremist. Others are accelerationists. A few are just pure nihilists.
What they share is a recruitment playbook. They use accessible social media, messaging apps, and gaming platforms to distribute propaganda aimed at young people. Once they've got someone's attention, they funnel them into private forums and chat rooms where actual radicalization and victimization happen.
"Coded language and emojis that adults may struggle to decipher" is how Europol put it. The messages are sinister. They encourage self-harm. They push the sexual exploitation of minors. And once victims are in, they're kept under control through (s)extortion — a practice that's become the network's primary enforcement mechanism.
The content flagged in this operation spans the full spectrum of what The Com produces:
- Violent videos and images depicting self-harm and suicide
- Child sexual abuse material (CSAM)
- Animal cruelty footage
- "Manhunt" videos, street attacks captured and shared as entertainment
- Arson footage
- Manuals and guides on grooming, murder, and improvised explosives
- Ideological content designed to radicalize members
- Instructions for doxing and swatting
It's not just content. It's instruction.
The Subgroups Behind the Chaos
The Com isn't a single organization. It's a loose collection of subgroups, each with its own focus. Europol has identified several:
Offline Com promotes property damage, physical harm to others, and acts of terrorism. These are the members who translate online radicalization into real-world violence.
Cyber Com handles network intrusions and ransomware attacks. This is the group that's been linked to some of Europe's most high-profile breaches.
(S)extortion Com coerces minors into committing sex crimes while encouraging self-harm and suicide among its targets. This subgroup is where the most vulnerable victims end up.
764 is perhaps the most notorious. Surfaced in 2021, this subgroup specializes in grooming young people into producing explicit content that's later used for blackmail or shared among members. In April 2025, two alleged 764 leaders, 20-year-old Prasan Nepal and 21-year-old Leonidas Varagiannis, were arrested. They're now facing life in prison for running what Europol called an "international child exploitation ring."
The 764 arrests were significant, but they were just one piece of a much larger puzzle.
Project Compass: The Bigger Picture
This latest URL-flagging operation builds on Project Compass, a yearlong effort launched in January 2025 and led by Europol's European Counter Terrorism Centre. Project Compass brought together law enforcement from 28 countries, nearly every EU member state, to tackle The Com at scale.
The numbers from Project Compass tell their own story: 30 arrests, 179 identified suspects, and 62 identified victims. Those aren't abstract statistics. Each of those 62 victims is a real person whose life was derailed by a network that preyed on vulnerability.
In January 2025, Europol also published a public notification warning about the rise of online cult communities specifically targeting young people. This operation is the operational follow-through on that warning.
The Com has also been linked to some high-profile ransomware attacks that made headlines: the Las Vegas casino breaches in September 2023, and attacks on Marks & Spencer, Co-op, and Harrods in April 2025. These weren't just random cybercrime incidents. They were tied to The Com's Cyber Com subgroup.
Why This Matters
The Com's decentralized structure is what makes it so resilient. You can't arrest a network that has no headquarters. You can't negotiate with factions that don't recognize each other's authority. But you can disrupt their online infrastructure, and that's exactly what this operation did.
Flagging 4,340 URLs is a significant blow to The Com's ability to spread its content. It doesn't eliminate the problem overnight. But it removes thousands of access points that were being used to recruit, radicalize, and exploit vulnerable people.
The operation also demonstrates how European law enforcement can coordinate across borders when the threat is transnational. Nine countries working together on Referral Action Days. Twenty-eight countries contributing to Project Compass. It's the kind of cooperation that's increasingly necessary when extremist networks operate across jurisdictions with equal ease.
The Com will adapt. It always does. But for now, 4,340 URLs are gone, and the network's online footprint is measurably smaller. That's not nothing.
Related Coverage
- Law Enforcement Unleashes Global Crackdown on Social Engineering Fraud
- Targeting the Malware Assembly Line: How Coordinated Legal Tactics and AI Disrupt Cybercrime Infrastructure