Executive Summary
In August 2026, Justin Swaddle, a 20-year-old from Leeds and member of the cybercriminal group 'The Com,' was sentenced to two years in prison for blackmail and sextortion offenses involving nearly 120 victims worldwide. Operating under aliases such as 'Epstein,' 'Rugen,' and 'Moscow' on platforms like Snapchat, Telegram, and Discord, Swaddle coerced victims, aged 13 to 17, into self-harm and the production of explicit content by threatening to expose their private information. The UK National Crime Agency (NCA) identified 117 female victims and discovered images of children as young as three on Swaddle's devices, some depicting acts he had incited.
This case underscores the persistent threat posed by decentralized cybercriminal networks like 'The Com,' which exploit online platforms to target vulnerable individuals. The group's activities, including sextortion and the production of child sexual abuse material, highlight the urgent need for enhanced cybersecurity measures and public awareness to protect minors from such exploitation.
Why This Matters Now
The sentencing of Justin Swaddle highlights the ongoing and evolving threat of cybercriminal groups like 'The Com,' which continue to exploit online platforms to target and victimize minors. This case serves as a critical reminder of the importance of vigilance, education, and robust cybersecurity measures to protect vulnerable individuals from such exploitation.
Attack Path Analysis
The attacker initiated contact with victims via social media platforms, gaining their trust to collect sensitive information. This information was then used to escalate control over the victims, coercing them into compliance. The attacker moved laterally by targeting multiple victims across different platforms. Command and control were maintained through continuous communication and threats. Exfiltration involved the collection and storage of explicit images and videos. The impact was severe psychological trauma and exploitation of the victims.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
The attacker initiated contact with victims via social media platforms, gaining their trust to collect sensitive information.
MITRE ATT&CK® Techniques
Gather Victim Identity Information
Phishing
Input Capture
Application Layer Protocol
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST SP 800-53 – Account Management
Control ID: AC-2
PCI DSS 4.0 – Security of Public-Facing Web Applications
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Encryption of Nonpublic Information
Control ID: 500.15
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – User Identity and Access Management
Control ID: 3.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Primary/Secondary Education
Schools face heightened sextortion targeting minors aged 13-17, requiring enhanced network segmentation, egress filtering, and threat detection for student protection.
Higher Education/Acadamia
Universities must strengthen encrypted traffic monitoring and zero trust segmentation to protect vulnerable students from The Com's social engineering campaigns.
Internet
Social platforms enabling The Com recruitment need improved anomaly detection, multicloud visibility controls, and enhanced policy enforcement against exploitation networks.
Computer Software/Engineering
Software platforms require inline IPS capabilities and cloud firewall protections to prevent cybercrime collective recruitment and child exploitation material distribution.
Sources
- Member of The Com sent to prison for blackmail, sextortionhttps://www.bleepingcomputer.com/news/security/member-of-the-com-sent-to-prison-for-blackmail-sextortion/Verified
- The Com: Theft, Extortion, and Violence are a Rising Threat to Youth Onlinehttps://www.ic3.gov/PSA/2025/PSA250723-3Verified
- Sinister cybercrime subculture 'The Com' is poisoning young minds, FBI warnshttps://cybernews.com/security/sinister-cybercrime-subculture-the-com-targeting-youth-fbi/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit cloud workloads may be constrained, reducing the risk of unauthorized access to sensitive data.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges within the cloud environment would likely be constrained, reducing the risk of unauthorized access.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally within the cloud environment would likely be constrained, reducing the risk of widespread compromise.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to maintain command and control channels would likely be constrained, reducing the risk of sustained unauthorized access.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data would likely be constrained, reducing the risk of data loss.
The attacker's ability to inflict harm would likely be constrained, reducing the overall impact of the attack.
Impact at a Glance
Affected Business Functions
- n/a
Estimated downtime: N/A
Estimated loss: N/A
Personal and sensitive information of approximately 117 female victims aged 13 to 17, including intimate images and private data.
Recommended Actions
Key Takeaways & Next Steps
- • Implement robust identity verification and access controls to prevent unauthorized access to sensitive information.
- • Utilize threat detection and anomaly response systems to identify and mitigate suspicious activities.
- • Enforce strict egress security and policy enforcement to control outbound data flows and prevent data exfiltration.
- • Provide comprehensive training and awareness programs to educate users about social engineering tactics and how to recognize them.
- • Establish clear reporting mechanisms for users to report suspicious activities and potential security incidents.



