A Europol-coordinated law enforcement effort dubbed Project Compass has led to the arrest of 30 suspected members of “The Com,” a decentralized, largely Western, youth-driven cybercrime ecosystem linked to hacking, sextortion, and related physical harm targeting minors and other vulnerable individuals. Europol said 28 countries participated, and authorities have fully or partially identified 179 perpetrators, with the operation framed as an attempt to disrupt violent online extremism that can function like an “online cult community” recruiting offenders and victims.
The reporting also notes law enforcement focus on spinoff groups such as “764,” which the U.S. Department of Justice has described as a “nihilistic violent extremist group.” Separately, U.S. officials described ongoing efforts against Southeast Asian scam compounds conducting pig-butchering and other cryptocurrency investment fraud and laundering at scale; while related to transnational cyber-enabled crime, that activity is a different enforcement and threat topic than Project Compass and “The Com.”

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
On February 26, 2026, Europol announced first operational results from Project Compass after a year of work against The Com. Authorities reported 30 arrests, 179 perpetrators fully or partially identified, 62 victims identified, four victims safeguarded, and joint awareness-raising activity across participating countries.
Europol later linked The Com to high-profile cyberattacks against UK retailers in April 2025. The incidents were cited as evidence that the ecosystem spans both child exploitation and major corporate intrusions.
In April 2025, two alleged 764 leaders, Leonidas Varagiannis and Prasan Nepal, were arrested and charged with operating an international child exploitation ring involving child sexual abuse material distribution. Reporting said they faced potential life sentences.
In March 2025, the FBI warned that Com-linked offenders were coercing victims, sometimes as young as nine, into producing or livestreaming self-harm, animal cruelty, sexual content, and suicide-related acts. The alert highlighted the severe child exploitation dimension of the network.
A 19-year-old, Alexis Aldair Chavez, pleaded guilty in the United States to racketeering and child pornography charges tied to leadership of the 764-linked '8884' network. He was reported to face up to 60 years in prison.
Europol's European Counter Terrorism Centre launched Project Compass in January 2025 as a multinational effort to investigate and disrupt The Com. The initiative brought together authorities from 28 countries to improve intelligence sharing, prevention, and coordinated investigations.
U.S. authorities arrested and charged alleged members of The Com in 2024, according to later reporting. The action did not appear to significantly slow the broader network's activity.
The Com was later linked by Europol reporting to breaches affecting Las Vegas casinos in September 2023. The incident was cited as an example of the network's connection to major cyber intrusions.
The Com offshoot known as 764 first emerged in 2021 and became associated with grooming minors into producing explicit material for blackmail and distribution. Later reporting described it as one of the violent extremist-linked subgroups pursued by investigators.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcedatabreaches.net
Open sourcedarkreading.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcehelpnetsecurity.com
Open sourceeuropol.europa.eu
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.