Phishing, exploits & privacy
The Com: social engineering and account compromise
The FBI’s July 2025 Public Service Announcement (I-072325-PSA) calls The Com, short for "The Community" One of the fastest-evolving online criminal ecosystems in recent memory.
Original publication · 19 Sep 2025. Figures, claims and opinions reflect the original publication date.
The original publications are in English. Navigation is available in seven languages.
Who Is “The Com” And Why X and Global Authorities Are Targeting Them
The FBI’s July 2025 Public Service Announcement (I-072325-PSA) calls The Com, short for "The Community" One of the fastest-evolving online criminal ecosystems in recent memory.
This isn’t a single gang but an international, English-speaking web of overlapping hacker crews, many of whom are minors, united by greed, clout, and technical skill.
Law-enforcement, security researchers, and now major platforms like X are taking aim at them for good reason:
The Com splinters into three major factions:
➡️Hacker Com – Technically sophisticated actors tied to ransomware-as-a-service groups. Their portfolio spans distributed-denial-of-service (DDoS) attacks, government email account sales, SIM-swaps, phishing campaigns, custom malware, and cryptocurrency theft worth millions. Many resell stolen data or offer illicit tech services for profit.
➡️IRL Com – Where online disputes spill into the physical world: extortion, kidnappings, firearms threats, and even torture to force crypto transfers. Online insults, rival affiliations, or flaunted wallet balances can escalate to real-world violence.
➡️Extortion Com – Specialises in exploiting children, typically teenage girls, using doxing, swatting, or threats of violence to coerce explicit material or payments.
While notoriety and perceived status drive members to brag and recruit, crypto theft remains the primary motivator.
Ironically, that same greed breeds infighting.
Com actors frequently target one another with SIM-swaps or swatting to steal rivals’ holdings.
A single boast about a wallet balance can paint a target on a member’s back.
Hacker Com actors deploy an arsenal of tools to obscure identity and maximize damage:
➡️Remote-access trojans and phishing kits.
➡️VOIP providers, voice modulators, and spoofing tech.
➡️VPNs, encrypted email domains, and crypto cash-out services.
➡️Live-streaming to flaunt stolen funds or humiliate victims.
These methods let them infiltrate corporate networks, steal PII, and cripple targets while masking attribution. Swatting, placing fake emergency calls to provoke armed police responses, is routinely used both for retaliation and as a distraction during active thefts.
What sets The Com apart is the bridging of digital crime with real-life violence.
The FBI warns of kidnappings, threats against family members, and the use of firearms to extract crypto.
Extortion Com’s targeting of minors compounds the danger, leaving emotional trauma and shattered lives far beyond financial loss.
The group’s visibility has grown through brazen leaks, public bragging, and high-profile breaches.
Internal conflicts spilling onto mainstream platforms draw unwanted attention, making them harder to ignore.
As ransomware payouts climb and child exploitation cases surface, X and global agencies are signaling a coordinated pushback, expect bans, account seizures, and criminal indictments.
Digital-forensics experts track The Com via blockchain traces from stolen funds, shared malware signatures, reused VOIP services, and handle overlaps across forums and messaging apps.
Linking a SIM-swap to a phishing kit or a DDoS pattern to a specific VPN exit can expose clusters of actors. But The Com’s fluid membership, minors splintering off or re-branding—makes takedowns complex and temporary.
The Com is not just “another hacker gang”: it is a decentralized social environment where criminal skill-sharing, reputation gaming, and real-world violence intersect.
The crackdown by X and global authorities is both a public-safety measure and a test of how well platforms can disrupt adaptive, youth-driven cybercrime without simply driving it deeper underground.
- $MASTR

Scattered Spider is a well-known subgroup of The Com (The Community) and one of the most active cybercrime crews identified by law enforcement.
Notable cases tied to The Com/ SS:
Noah Michael Urban (“King Bob”, “Sosa”) pled guilty to SIM-swapping 59 victims (2022–2023), forfeiting $4.8 M, paying $13 M restitution, and receiving 10 yrs in prison.
Alleged boss Tyler Buchanan was arrested in Spain with ~$27 M in Bitcoin.
The 2024 TfL hack cost £39 M, disrupted Oyster cards, and exposed thousands; suspects Thalha Jubair (19) and Owen Flowers (18) were charged, Flowers also linked to U.S. healthcare attacks. July 2025: UK NCA arrested four after Marks & Spencer, Co-op, and Harrods breaches.
Another Brit faces charges for 120+ intrusions and $115 M in extortion tied to Scattered Spider.
The Com’s crimes span crypto thefts, SIM-swaps, ransomware, DDoS, phishing, swatting-for-hire, doxing, child extortion, and even kidnappings and firearm threats for crypto, making it a volatile, reputation-driven criminal network now firmly in law enforcement’s sights.




