/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A look at the activity of some members of The Com, an online community linked to the Scattered Spider hacking group, and their involvement in extortion groups

which corresponds to the screen name “@Holy” — and found the same account was used across a number of cybercrime channels that are entirely focused on extorting young people into harming themselves or others, and recording the harm on video.’ … BrianKrebs / @briankrebs@infosec.exchange : I hope this goes without saying, but in before anyone asks: This isn't me.  —  Someone filed a petition on change.org to free the alleged admin of Breachforums, Conor Brian Fitzpatrick, aka Pompompurin.  Fitzpatrick was arrested in March 2023 and then prosecutors tacked on CSAM charges after raiding the home where he lived with his parents. … Kevin Beaumont / @GossiTheDog@cyberplace.social : Great blog by @briankrebs on Scattered Spider folks, who continue to cause problems all over.  Includes direct link to LAPSUS$.  —  These Advanced Persistent Teenagers are often dismissed.. but they're the real deal. … X: Will / @bushidotoken : Big update on the case from Krebs, including the alleged identity of “Holy” the individual likely behind the TfL and MGM hacks: https://krebsonsecurity.com/ ... LinkedIn: Dr. Stephen Kraemer : Krebs's story is chilling and deeply concerning.  The further one delves, the darker it becomes.  Perhaps it represents the most comprehensive analysis of the devolution of Dark Net violence. … Andy Smith : There used to be some form of “honor” between hackers surrounding attacks and extortion.  What's happening now is an I guess predictable …

Krebs on Security Brian Krebs

Context & Ripple Effects

This reporting sits at the intersection of financially motivated intrusion crews and online groups that coerce young people into recorded abuse. Earlier coverage documented how group 764 used Discord and Telegram to blackmail teenagers, while a separate analysis described a wider network of violent-predator groups across those services.

The alleged reuse of a handle across these channels makes the boundary between hacking subcultures and abuse-focused extortion groups more consequential. It also follows a history of platform action against account-hijacking communities, including coordinated takedowns of OGUsers members.

First-order effects

  • The reporting increases attribution and investigative scrutiny of the identified Com-linked accounts, particularly where the same identity appears in both intrusion-related and coercive-extortion channels.
  • Platforms hosting the cited channels face a more connected trust-and-safety problem: material that may look like cybercrime community activity can also signal imminent harm to minors.

Second-order effects

  • Moderation and law-enforcement teams may need to join cyber-abuse, child-safety, and fraud signals rather than treating each as a separate enforcement queue; earlier cross-platform action against account-hijacking groups shows why fragmented responses can leave networks intact.
  • Reputation and access risks rise for forums and communications services that become recurring coordination points, encouraging more aggressive account preservation, reporting, and removal decisions.

Third-order effects

  • If these overlaps persist, online-safety enforcement will increasingly be organized around actor networks and behavioral links across services, not around a single offense category or platform.
  • That shift could intensify pressure on platforms to establish reliable identity and evidence-sharing processes while preserving safeguards against mistaken attribution.

The trend: Cybercrime ecosystems are converging with broader online-harm networks, forcing platforms and investigators to treat cross-service identity signals as a core safety capability.

Discussion

  • @Kjaerulv@mastodon.social @Kjaerulv@mastodon.social on mastodon
    ‘KrebsOnSecurity examined the Telegram user ID number of the account that offered media interviews about the MGM hack — which corresponds to the screen name “@Holy” — and found the same account was used across a number of cybercrime channels that are entirely focused on extorting…
  • @bushidotoken Will on x
    Big update on the case from Krebs, including the alleged identity of “Holy” the individual likely behind the TfL and MGM hacks: https://krebsonsecurity.com/ ...