Europol has referred 4,340 URLs connected to the violent online network known as “The Com” for removal, marking one of the most substantial recent efforts to disrupt an ecosystem that blends extremist propaganda, cybercrime, child exploitation, coercion, and self-harm content. The action, conducted across June and July by investigators from nine European countries, is significant not simply for its scale but for what it reveals about how dangerous online communities now recruit, groom, communicate, and evade detection.
The distinction in the wording matters. Authorities have flagged or referred thousands of URLs to online service providers; that is not necessarily the same as independently confirming that every link has already been removed. Still, a coordinated referral campaign can sharply reduce access to harmful material, generate intelligence for ongoing cases, and expose patterns in how extremist and criminal networks use platforms.
For Windows users, families, schools, IT administrators, and online-platform operators, the Europol action underscores an uncomfortable reality: the risk is no longer confined to obscure corners of the internet. Recruitment and coercion can begin through mainstream social networks, gaming communities, messaging applications, streaming platforms, and seemingly ordinary online conversations.

Cybersecurity analysts monitor a glowing global network map and digital threat data in a high-tech control room.A Major Disruption Operation Against “The Com”​

The operation was carried out through Europol’s Referral Action Days, a recurring framework designed to identify and disrupt terrorist and violent extremist material online. Investigators from Belgium, Finland, Hungary, Ireland, Luxembourg, the Netherlands, Portugal, Spain, and Sweden participated in the latest action.
Its purpose was broader than content moderation. The campaign aimed to:
  • Disrupt access to material associated with The Com
  • Reduce the circulation of nihilistic violent extremist content
  • Identify platform-abuse patterns
  • Produce new investigative leads
  • Support victim safeguarding efforts
  • Improve cooperation between national authorities and online service providers
The scale—4,340 URLs—is a reminder that harmful networks do not rely on a single website, server, or social-media account. Their online presence is fragmented by design. Content may be reposted across platforms, shared through link aggregators, copied into private groups, embedded in files, or moved between public and invite-only spaces once moderation action begins.
That resilience explains why URL referrals are valuable but cannot represent a complete solution. Removing individual links disrupts discovery and distribution, yet the underlying communities can migrate quickly. The longer-term objective is to identify the people, infrastructure, recruitment funnels, financing, and communication methods behind the links.

What “The Com” Represents​

“The Com,” short for Community, is not a conventional organization with a clear leadership structure, membership list, or consistent ideology. It is better understood as a decentralized and loosely connected ecosystem of groups and individuals that may overlap in their tactics, targets, and online spaces.
Authorities have associated the wider network with a disturbing mix of activity:
  • Recruitment and grooming of minors and vulnerable young people
  • Sexual extortion and the creation or sharing of child sexual abuse material
  • Encouragement of self-harm, suicide, and violence
  • Doxing, swatting, harassment, and coercive online abuse
  • Cyber intrusions and ransomware-related activity
  • Promotion of violent extremist and accelerationist ideas
  • Distribution of violent videos, imagery, propaganda, and manuals
This combination makes The Com particularly difficult to categorize. It is not solely a cybercrime collective, a child-exploitation network, or an extremist movement. Rather, it operates across the boundaries between those categories.
That crossover is central to the threat. A young person may initially encounter an online group through gaming, music, memes, social media, or shared interests. What begins as attention, friendship, or belonging can turn into manipulation, coercion, blackmail, exposure to disturbing content, and pressure to engage in harmful acts.

The Importance of the Referral-Not-Removal Distinction​

Headlines about law-enforcement actions often use terms such as “takedown,” “removal,” or “shutdown.” In this case, the most precise description is that Europol and participating authorities referred 4,340 URLs containing or pointing to harmful material.
A referral generally means investigators have assessed content and sent the relevant URL to a platform or service provider for review under applicable laws, terms of service, or voluntary cooperation mechanisms. The provider may then remove the content, restrict access, suspend an account, preserve evidence, or take other action.
This distinction has practical implications.

Why a referral campaign is still powerful​

A coordinated URL referral operation can have an immediate disruptive effect:
  • Publicly accessible material becomes harder to find
  • New recruits encounter more friction
  • Existing users lose distribution channels
  • Platforms receive intelligence about coordinated abuse
  • Investigators can map reuploads and account networks
  • Harmful material may be preserved before it disappears
  • Providers can strengthen automated and human moderation rules
For groups that rely on visibility, shock value, and rapid dissemination, disrupting discoverability can be especially important. A link that vanishes from a public profile or search result may prevent a vulnerable person from reaching a more private and dangerous community.

Why it is not the end of the problem​

At the same time, URL-focused action has inherent limits. Online groups can recreate channels, register replacement accounts, reuse files, change usernames, or move to encrypted services. A single piece of content may also exist in multiple locations at once.
The most effective response therefore combines content referrals with:
  1. Criminal investigations into organizers and active offenders
  2. Victim identification and safeguarding
  3. Digital-forensic evidence collection
  4. Cross-border intelligence sharing
  5. Platform-level abuse prevention
  6. Education for families, schools, and youth organizations
The 4,340 URLs are not simply a large moderation statistic. They are indicators of a broader, evolving threat network.

Project Compass Provides the Wider Context​

The current action builds on Project Compass, a longer-running international effort focused on The Com and associated activity. The broader project has involved law-enforcement agencies from 28 countries and has already resulted in 30 arrests, the identification of 179 suspects, and the recognition of 62 victims. Authorities also directly safeguarded several victims during the earlier phase of the operation.
Those numbers illustrate why it would be a mistake to view The Com primarily as a content problem. The material online is dangerous, but it is a symptom of deeper victimization and criminal coordination.
Project Compass also highlights an important law-enforcement shift: agencies increasingly treat online exploitation, violent extremism, and cyber-enabled coercion as connected problems rather than isolated categories. That is an important development because the same person may be victimized, threatened, radicalized, extorted, and drawn into criminal conduct through the same network.

A network with multiple operational strands​

Authorities have described several broad segments associated with The Com:
  • Offline Com, linked to property damage, violence, and terrorism-related activity
  • Cyber Com, associated with network intrusions and ransomware activity
  • (S)extortion Com, involving coercion, sexual exploitation, self-harm encouragement, and threats
  • 764, a particularly notorious subgroup associated with grooming young people and using explicit material for blackmail or sharing within the network
These labels should not be treated as neat corporate divisions. Decentralized groups are fluid, and affiliations can overlap or change. But the categories help explain how online harm can transition from abuse in a chat application to real-world intimidation, cybercrime, or violence.

Why Young People Are at the Center of the Threat​

The most disturbing aspect of this ecosystem is its focus on children, teenagers, and otherwise vulnerable individuals. Europol has warned that violent online communities increasingly identify potential victims on accessible, familiar services and then move interactions toward more private channels.
Gaming environments, social platforms, group chats, and streaming communities are not inherently unsafe. They are central parts of modern social life, creativity, entertainment, and communication. The problem is that bad actors understand where young people gather and use the same social features that make online communities engaging.

The grooming pipeline​

The initial contact may not look threatening. It can appear as friendship, validation, shared humor, mutual interests, an invitation to a group, or offers of support during a difficult period.
Over time, the tactics can escalate:
  • Building trust through exaggerated attention and affection
  • Encouraging secrecy from parents, friends, or teachers
  • Requesting personal details or images
  • Pressuring the target to move into private chats
  • Using threats, humiliation, or blackmail to maintain control
  • Normalizing shocking material to reduce emotional resistance
  • Demanding increasingly harmful behavior
The use of coded language, symbols, emojis, and in-group references adds to the challenge. Adults may overlook warning signs because a conversation appears cryptic rather than overtly threatening. That ambiguity is often useful to offenders, who can disguise harmful intent behind irony, memes, slang, or supposedly fictional “edgy” communities.

Vulnerability is exploited, not created​

It is important to avoid framing victims as reckless or responsible for their own abuse. These networks deliberately seek people who may be isolated, distressed, socially anxious, curious, or looking for acceptance. They exploit ordinary human needs for belonging, support, and recognition.
That is why technical controls alone are insufficient. A safer online environment requires informed adults, responsive schools, trusted reporting paths, mental-health support, and platform systems that react quickly when coercion or exploitation is suspected.

From Extremist Content to Cybercrime​

The Com’s reported links to cybercrime make the Europol operation relevant well beyond counter-extremism circles. The network has been associated with activity ranging from harassment and doxing to network intrusion and ransomware.
High-profile ransomware incidents connected in reporting to actors within or adjacent to this ecosystem have demonstrated how overlapping cybercrime communities can produce consequences far beyond their immediate victims. Retailers, casinos, enterprises, and service providers can all become targets when financially motivated intrusions intersect with social-engineering expertise and criminal collaboration.

The role of social engineering​

Modern cybercrime frequently begins with manipulation rather than a software vulnerability. Attackers may exploit help desks, impersonate employees, steal credentials, abuse password-reset processes, conduct SIM-swapping attacks, or trick users into installing remote-access tools.
The Com’s alleged blend of coercion and technical abuse demonstrates a key cybersecurity lesson: identity is an attack surface.
A well-patched Windows device is still vulnerable if an attacker can persuade a user to disclose a password, approve a multifactor authentication prompt, share a recovery code, or install remote-control software. Organizations must treat social engineering as a core security issue rather than a secondary awareness topic.

Why businesses should pay attention​

The threat is not limited to enterprises that consider themselves likely ransomware targets. Any organization with customer data, employee accounts, remote-access tools, cloud services, or a public-facing help desk can be exposed to social-engineering risk.
Security teams should revisit controls around:
  • Help-desk identity verification
  • Password-reset procedures
  • SIM-swap and phone-based recovery risks
  • Privileged-account access
  • Multifactor authentication fatigue attacks
  • Remote-support software
  • Third-party access and vendor support
  • Monitoring for unusual account behavior
  • Rapid escalation paths for suspected coercion or impersonation
Organizations also need to recognize that employees may face personal targeting outside the workplace. Doxing, extortion, compromised social accounts, and harassment can become pathways into corporate systems if security processes depend too heavily on personal details or phone-based verification.

What Windows Users Can Do Now​

The Europol action is a reminder that online safety requires practical habits, not fear. Windows users can reduce exposure to both cybercrime and harmful online manipulation by using the security tools already built into modern systems and by treating unexpected contact with caution.

Keep Windows and core applications updated​

Security updates remain foundational. Enable automatic updates for:
  • Windows 11
  • Web browsers
  • Microsoft Edge or other installed browsers
  • Messaging and gaming applications
  • PDF readers
  • Cloud-storage clients
  • Remote-access software
  • Security software
Updates do not prevent grooming or online coercion, but they reduce the chance that a known software flaw becomes an entry point for malware, credential theft, or remote compromise.

Use strong account protection​

A stolen password can open access to email, gaming, social-media accounts, cloud storage, and saved personal information. Strong authentication practices are therefore critical.
  • Use a unique password for every important account
  • Store passwords in a reputable password manager
  • Enable multifactor authentication wherever available
  • Prefer authenticator applications or security keys when possible
  • Never approve an unexpected sign-in prompt
  • Review account recovery settings regularly
  • Remove unfamiliar devices and active sessions
Email deserves particular attention because it often controls password recovery for nearly every other service. Protecting the primary email account should be a top priority.

Treat “private” conversations carefully​

Moving from a public platform to a private chat is not automatically dangerous. However, secrecy, pressure, threats, requests for explicit content, and attempts to isolate someone from trusted people are major warning signs.
Users—especially younger users—should be encouraged to:
  • Avoid sharing passwords, recovery codes, addresses, school details, or private images
  • Be wary of strangers who insist on secrecy
  • Refuse pressure to join private servers or encrypted chats
  • Save evidence of threats rather than negotiating with an abuser
  • Use in-platform reporting tools
  • Tell a trusted adult, school safeguarding contact, or law-enforcement agency when there is immediate danger
For parents and caregivers, open communication is more effective than blanket surveillance. Young people are more likely to seek help when they believe they will be protected rather than punished for reporting a troubling interaction.

The Challenge for Platforms and Moderation Teams​

The operation also raises difficult questions for online platforms. Harmful networks exploit features that many services deliberately provide: direct messages, private groups, livestreaming, file sharing, user-created communities, pseudonymous accounts, and recommendation systems.
There is no simple moderation rule that will eliminate this abuse. Heavy-handed systems can create privacy and free-expression concerns, while weak enforcement lets harmful communities flourish. The challenge is to build targeted, accountable safety mechanisms that focus on coercion, exploitation, credible threats, and organized harmful behavior.

Effective moderation requires more than keyword filtering​

Coded language and emoji-based communication make basic keyword detection inadequate. A single phrase can be harmless in one context and deeply threatening in another. Moderation systems need to recognize patterns, relationships, behavioral signals, and coordinated reuploads.
Platforms can improve their defenses by investing in:
  • Trust-and-safety teams with specialist training
  • Rapid escalation for suspected child exploitation or self-harm coercion
  • Better detection of repeat offenders and account evasion
  • Cross-platform intelligence sharing where legally appropriate
  • Clear reporting options that do not require victims to understand legal terminology
  • Account and device-level measures against repeated abuse
  • Strong preservation processes for evidence requested by lawful investigations
  • Safety education designed for younger users
Platforms should also ensure that their reporting processes do not leave vulnerable people trapped in automated queues. When a user reports blackmail, threats of self-harm, sexual coercion, or child exploitation, speed matters.

The Strengths of Europol’s Approach​

The Referral Action Days model has several notable strengths.
First, it brings national agencies together around a shared operational objective. The internet does not respect jurisdictional boundaries, and decentralized networks exploit that fact. Cross-border coordination reduces the chance that a group can simply shift activity from one country’s platform ecosystem to another.
Second, it combines disruption with intelligence gathering. Even when a URL disappears, the investigation can benefit from associated account names, file hashes, aliases, infrastructure, timestamps, referral paths, and connections between platforms.
Third, the action recognizes that online extremist material is not limited to polished propaganda videos or manifestos. Manuals, gore content, child-exploitation material, coercive communications, and decentralized group channels can all play a role in recruitment and radicalization.
Fourth, the operation places victim safeguarding alongside enforcement. That is crucial. Arrests and content removals are important, but protecting someone currently being blackmailed, manipulated, or pressured into self-harm can be the most urgent outcome.

Risks and Limitations That Remain​

Despite the value of the operation, the threat remains adaptive. Decentralized groups are difficult to eliminate because their members can use aliases, encrypted communications, disposable accounts, and widely available platforms.
There is also a risk that removal activity pushes harmful material into harder-to-monitor spaces. That does not mean public content should be left online; it means disruption must be paired with sustained investigative capacity and support for people at risk.
Another concern is the potential for overbroad moderation. Terms, symbols, and content can be context-dependent. Platforms and authorities must maintain clear legal standards, meaningful review processes, and safeguards against mistakenly penalizing legitimate reporting, research, journalism, education, or support communities.
Finally, public awareness can be a double-edged sword. Reporting must explain the threat without sensationalizing it, glamorizing the groups involved, or amplifying their preferred imagery and coded language. The focus should remain on prevention, victim support, accountability, and digital resilience.

A Turning Point for Online Safety, Not a Final Victory​

Europol’s referral of 4,340 URLs linked to The Com is an important disruption effort and a clear signal that European authorities are treating this ecosystem as a serious convergence of extremist violence, exploitation, coercion, and cyber-enabled crime. The action’s scale shows both the value of international cooperation and the enormous volume of harmful material that still circulates online.
The key takeaway is not that thousands of links have made the problem disappear. It is that the fight against dangerous online networks must operate on multiple fronts at once: content disruption, criminal investigation, cybersecurity, victim safeguarding, responsible platform design, and early intervention.
For the Windows community, the lesson is equally direct. Strong passwords, multifactor authentication, device updates, privacy awareness, careful account recovery practices, and candid conversations about online coercion are no longer separate issues. They are all part of the same modern defense against networks that exploit technology—and the people using it.

References​

  1. Primary source: SC Media
    Published: 2026-07-24T22:00:46+00:00
  2. Related coverage: bleepingcomputer.com