Europol Flags 4,340 URLs in The Com Network Crackdown
Operation Compass: 4,340 URLs flagged, 30 arrests across 28 nations, targeting The Com — the network behind ransomware hits on MGM and UK retailers.
Thirty arrests. A hundred and seventy-nine suspects identified. Four thousand, three hundred and forty URLs flagged for platform removal. Europol wrapped its most recent enforcement push against The Com this week — and for security teams, the detail that matters isn’t the extremist content. It’s the Cyber Com sub-group: the part of this network that runs network intrusions and ransomware deployment.
What The Com is
Europol classifies it as a loosely organized network of nihilistic violent extremist groups operating across gaming platforms and social media, with sub-groups that coerce members into increasingly serious acts. The cyber arm — Cyber Com — focuses on network access and monetization. The Com has been linked to ransomware attacks against MGM Resorts in 2023 and UK retailers Marks & Spencer, Co-op, and Harrods in 2025. Same playbook across both: aggressive social engineering to bypass helpdesk and IT staff, credential theft, then ransomware deployment.
What Europol actually did
Operation Compass has been running for a year across 28 countries. The June–July 2026 Referral Action Days — coordinated by Europol’s EU Internet Referral Unit (EU IRU) and Spain’s Intelligence Centre against Terrorism and Organised Crime (CITCO), with nine EU member states — flagged 4,340 URLs for platform removal. This is referral authority, not seizure authority. Platforms make the final call on what comes down.
The 30 arrests and 179 identified suspects are cumulative across the full yearlong operation, not the product of this action week alone.
What this disrupts and what it doesn’t
The enforcement burns specific coordination infrastructure — the channels and accounts tied to known operators. It won’t retire the playbook. Social engineering tactics for initial access don’t expire when a Discord server goes dark. New recruitment channels stand up. Affiliates who weren’t arrested keep operating.
The disruption window is real. It’s also probably measured in weeks, not months, for a network this decentralized.
Priority call
The Cyber Com attacks that hit MGM and the UK retailers didn’t need a zero-day. They needed a helpdesk rep who approved a password reset over the phone. That’s still the attack surface. If your identity verification for account recovery depends on something an attacker who already has your employee directory can answer — name, role, manager — the Europol action doesn’t change your risk posture.
The fix: out-of-band verification for all helpdesk resets, MFA that doesn’t fall back to voice or SMS, and a policy that makes “I can’t verify this right now” an acceptable answer for anyone on the help desk. That’s what the arrests can’t do for you.
Sources
- BleepingComputer, 2026-07-24: Europol flags 4,340 URLs for removal in ‘The Com’ crackdown
Found this useful? Share it.


