A look at the activity of some members of The Com, an online community linked to the Scattered Spider hacking group, and their involvement in extortion groups
which corresponds to the screen name “@Holy” — and found the same account was used across a number of cybercrime channels that are entirely focused on extorting young people into harming themselves or others, and recording the harm on video.’ … BrianKrebs / @briankrebs@infosec.exchange : I hope this goes without saying, but in before anyone asks: This isn't me. — Someone filed a petition on change.org to free the alleged admin of Breachforums, Conor Brian Fitzpatrick, aka Pompompurin. Fitzpatrick was arrested in March 2023 and then prosecutors tacked on CSAM charges after raiding the home where he lived with his parents. … Kevin Beaumont / @GossiTheDog@cyberplace.social : Great blog by @briankrebs on Scattered Spider folks, who continue to cause problems all over. Includes direct link to LAPSUS$. — These Advanced Persistent Teenagers are often dismissed.. but they're the real deal. … X: Will / @bushidotoken : Big update on the case from Krebs, including the alleged identity of “Holy” the individual likely behind the TfL and MGM hacks: https://krebsonsecurity.com/ ... LinkedIn: Dr. Stephen Kraemer : Krebs's story is chilling and deeply concerning. The further one delves, the darker it becomes. Perhaps it represents the most comprehensive analysis of the devolution of Dark Net violence. … Andy Smith : There used to be some form of “honor” between hackers surrounding attacks and extortion. What's happening now is an I guess predictable …
Context & Ripple Effects
This reporting sits at the intersection of financially motivated intrusion crews and online groups that coerce young people into recorded abuse. Earlier coverage documented how group 764 used Discord and Telegram to blackmail teenagers, while a separate analysis described a wider network of violent-predator groups across those services.
The alleged reuse of a handle across these channels makes the boundary between hacking subcultures and abuse-focused extortion groups more consequential. It also follows a history of platform action against account-hijacking communities, including coordinated takedowns of OGUsers members.
First-order effects
- The reporting increases attribution and investigative scrutiny of the identified Com-linked accounts, particularly where the same identity appears in both intrusion-related and coercive-extortion channels.
- Platforms hosting the cited channels face a more connected trust-and-safety problem: material that may look like cybercrime community activity can also signal imminent harm to minors.
Second-order effects
- Moderation and law-enforcement teams may need to join cyber-abuse, child-safety, and fraud signals rather than treating each as a separate enforcement queue; earlier cross-platform action against account-hijacking groups shows why fragmented responses can leave networks intact.
- Reputation and access risks rise for forums and communications services that become recurring coordination points, encouraging more aggressive account preservation, reporting, and removal decisions.
Third-order effects
- If these overlaps persist, online-safety enforcement will increasingly be organized around actor networks and behavioral links across services, not around a single offense category or platform.
- That shift could intensify pressure on platforms to establish reliable identity and evidence-sharing processes while preserving safeguards against mistaken attribution.
The trend: Cybercrime ecosystems are converging with broader online-harm networks, forcing platforms and investigators to treat cross-service identity signals as a core safety capability.