The Com: the growing cybercrime network behind recent Pornhub hack

A picture


Ransomware hacks, data theft, crypto scams and sextortion cover a broad range of cybercrimes carried out by an equally varied list of assailants.But there is also an English-speaking criminal ecosystem carrying out these activities that defies conventional categorisation.Nonetheless, it does have a name: the Com.Short for community, the Com is a loose affiliation of cybercriminals, largely native English language speakers typically aged from 16 to 25.Its activities run from crippling the IT systems of British retailers to phoning in bomb threats to schools and encouraging teenage girls to harm themselves.

The latest victims of the Com are premium users of PornHub, one of the world’s largest pornography sites, who have had their search history and viewing habits hacked by a group called ShinyHunters.The gang has emerged from the Com’s sprawling networks, whose constituents also include Scattered Spider, a collective that has been linked with hacks against the British retailers M&S, the Co-op and Harrods.The Com is thought to comprise thousands of people but there is no formal membership and no tightly delineated groups.“The Com ranges from 11-year-olds trying to hack Minecraft to people in their mid-20s targeting vulnerable kids online,” says Aiden Sinnott, principle threat researcher at the cybersecurity firm Sophos.Sinnott describes the Com as operating like a pipeline where older members groom younger recruits into carrying out increasingly sophisticated, and damaging, acts of cybercrime.

“Older members of the Com contact kids and try to get them to commit increasingly sophisticated acts of criminality, moving through to what we are seeing Scattered Spider and ShinyHunters do,” he says.Members of the Com communicate on platforms such as Discord and Telegram, sometimes exchanging extreme imagery or boasting about hacks.One such channel on Telegram, its name an amalgam of the ShinyHunters, Lapsus$ and Scattered Spider groups, carried a post this month stating: “We are the supply and demand for the Com.”The Com is well known to law enforcement on both sides of the Atlantic.In July the FBI issued a public warning about the Com, describing it as a “primarily English speaking, international, online ecosystem comprised of multiple interconnected networks whose members, many of whom are minors, engage in a variety of criminal violations”.

The UK’s National Crime Agency has said reports of Com networks have increased six-fold in the UK from 2022-2024.The NCA describes Com members as “usually young men who are motivated by status, power, control, misogyny, sexual gratification, or an obsession with extreme or violent material”.The Com is split into three subsets.The first is Hacker Com, which comprises groups such as ShinyHunters, Scattered Spider and Lapsus$.Scattered Spider activities include crippling company IT systems and extracting private data, then demanding cryptocurrency for its return as part of a process known as a ransomware attack.

ShinyHunters and Lapsus$ have more commonly stolen data without the ransomware element.Other activities include hacking social media accounts and using them as fronts for crypto scams.Noah Urban, a 20-year-old Florida-based member of the Scattered Spider group, was sentenced to 10 years in jail this year for his part in a cybercrime spree that included cryptocurrency theft.The second subset is IRL, or In Real Life Com, linked to groups such as Bricksquad or ACG.Its activities include calling out armed law enforcement on US university campuses under false pretences, in a process known as “swatting”, subjecting schools to bomb threats, or offering violence-as-a-service where contracts to carry out violent acts – often against other Com members – are posted online, with a financial breakdown for each act of violence.

The last grouping is Extortion Com, which targets vulnerable children and includes a notorious group known as 764,According to the FBI, the victims are typically aged between 10 and 17,They are coerced or extorted into sharing or live-streaming acts of self-harm, sexually explicit behaviour or even committing suicide,The footage is then circulated among network members, so the victims can continue to be extorted or controlled,Manipulating teenagers into carrying out sexual acts and then blackmailing them for money is known as sextortion and the Com is known to carry this out.

But there is also an element of cruel manipulation for the sake of it.The NCA describes Com networks that “manipulate their victims, who are often children, into harming or abusing themselves, their siblings, or pets”.According to Sophos, there are more than 250 active FBI investigations into this branch of the Com alone, with some of its members motivated by a desire to cause “fear and chaos”, according to US law enforcement.In the UK this year, Cameron Finnigan, 19, from Horsham, West Sussex, was given a nine-year prison sentence for possessing a terrorist document and encouraging someone online to take her own life.Counter-terror police said he had become involved with 764, which is described as a “Satanic extremist group” with an “extreme rightwing” ideology.

“It’s not three set pillars,” says Sinnott.“There is some movement between the groups.”The Com is a fluid grouping and a growing threat.
businessSee all
A picture

‘The anxiety never disappears’: Monmouth businesses recover from severe flooding

“It was heart-wrenching,” says Andrea Sholl, recalling the Friday night last month when flood waters started rising inside Bar 125, the restaurant she and her husband, Martin, own in the Welsh border town of Monmouth.The Sholls and a couple of colleagues were still clearing up after a busy evening serving diners when the building started to fill with water at about 1am.They were able to carry some furniture upstairs to protect it, but lost all of their appliances including dishwashers and freezers, as well as fridges full of thousands of pounds’ worth of food.“It was like a huge fountain coming up through the drains. It went through the cellar, then through into the kitchen, then the higher kitchen, and then before we knew it, in the lower dining room it was up to about here,” Andrea Sholl says, pointing to the windowsill

A picture

Christmas ads put on a diet as UK ban on TV junk food advertising bites

The festive season is traditionally a time of national culinary overindulgence but eagle-eyed viewers may have noticed that this year’s crop of big-budget Christmas TV ads have been decidedly lean and sugar-free.From Tesco and Waitrose to Marks & Spencer and Asda, the UK’s biggest exponents of extravagant festive food marketing have put their Christmas ads on a diet to comply with new regulations banning junk food products from appearing in TV ads before 9pm.The UK advertising watchdog will officially start cracking down on ads featuring junk food on TV – and in paid online advertising at any time of day – from 5 January. But the UK advertising industry voluntarily chose to start adhering to the new rules from October, making this TV’s first-ever low-fat, low-sugar and low-salt Christmas.Gone are shots of Christmas puddings and sweet treats, while healthy products have made a conspicuous appearance

A picture

Jim Ratcliffe chemical firms received up to £70m of UK state aid in last four years

Chemical companies owned by the billionaire Jim Ratcliffe had already been granted as much as £70m in UK state aid in the past four years, before this week’s £50m government bailout for its Grangemouth plant in Scotland.State aid to Ineos in the last year alone was between £16m and £38m, according to government disclosures published this week. Since August 2022 the company has received between £28m and £70m.The government stepped in on Tuesday to give Ineos £50m to support Grangemouth, fearing that without it the UK would lose its last plant making ethylene, an important material for making plastics. The government also backed a £75m loan guarantee, while Ineos will invest £30m of its own money

A picture

Donald Trump promised a new ‘golden age’ for the US economy. Where is it?

Most Americans have yet to see this boom – but they’ve certainly heard a lot about it from the presidentMoments into his second term, opening his inaugural address, Donald Trump was unequivocal. “The golden age of America begins right now,” he declared.At a White House reception last weekend, a little over 10 months later, the US president appeared to acknowledge just how far his timeline had shifted.“We’re going to have … I say it’s the golden age of America,” Trump told his audience. “We have an age that’s coming up, the likes of which … this country has never seen

A picture

Retailers hope ‘panic weekend’ will bring Christmas cheer to UK sales

Retailers are hoping for a last-minute dash for the shops this weekend after a lacklustre run-up to Christmas, with UK households forecast to spend £3.4bn, up more than 12% on the same weekend in 2024.Almost 50m shopping trips will be made by last-minute Father Christmases over the weekend, according to research by analysts GlobalData for Vouchercodes.co.uk, the vast majority of which will be to retail destinations including high streets and shopping malls

A picture

Why is Truth Social owner Trump Media merging with a fusion energy firm?

Trump Media & Technology Group, owner of Donald Trump’s social media platform, Truth Social, announced a merger on Wednesday with a company developing fusion energy technology.TAE Technologies, an energy company founded in 1998, will join with Trump Media via a $6bn merger that it promises will propel it to build “the world’s first utility-scale fusion power plant” next year.The move signals that the president and his family continue to look for profit-seeking ventures outside of Truth Social, which remains tiny compared with rival platforms such as Facebook, Instagram and X (formerly Twitter).Here is what we know about the deal so far.The media company, which has dabbled in financial services, is engineering a huge pivot and diving headfirst into nuclear energy