Executive Summary
In August 2026, 20-year-old Justin Swaddle from the United Kingdom was sentenced to two years in prison after pleading guilty to child sexual abuse offenses and blackmail. Operating under aliases such as 'Epstein,' 'Rugen,' and 'Moscow,' Swaddle was a member of 'The Com,' a decentralized cybercriminal network. He exploited social media platforms like Snapchat, Telegram, and Discord to target 117 female victims aged 13 to 17 across multiple countries, coercing them into providing explicit content under threat of exposing their personal information. (en.wikipedia.org)
This case underscores the evolving threat posed by 'The Com,' which has expanded from cybercrimes like SIM swapping and data breaches to more severe offenses, including sextortion and violence. The network's recruitment of minors and its use of sophisticated online platforms highlight the urgent need for enhanced cybersecurity measures and public awareness to protect vulnerable individuals from such exploitation. (fbi.gov)
Why This Matters Now
The sentencing of Justin Swaddle highlights the escalating threat of decentralized cybercriminal networks like 'The Com,' which are increasingly targeting minors for exploitation. This case serves as a critical reminder for organizations and individuals to bolster cybersecurity defenses and remain vigilant against evolving online threats.
Attack Path Analysis
The attacker initiated contact with victims via social media platforms, establishing trust before coercing them into sharing sensitive information. Utilizing the obtained information, the attacker escalated control over the victims by threatening exposure, thereby gaining further compliance. The attacker then expanded their influence by leveraging the victims' networks, identifying and targeting additional individuals. To maintain control and communication, the attacker employed various online platforms, ensuring continuous access to the victims. Sensitive data and explicit materials were exfiltrated from the victims, with threats of public exposure used to manipulate them. The attack culminated in significant psychological trauma for the victims, with the attacker achieving their objectives of exploitation and control.
Kill Chain Progression
Initial Compromise
Description
The attacker initiated contact with victims via social media platforms, establishing trust before coercing them into sharing sensitive information.
MITRE ATT&CK® Techniques
Phishing: Spearphishing via Service
Financial Theft
Email Collection: Remote Email Collection
Taint Shared Content
Command and Scripting Interpreter: PowerShell
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Maintain a Secure Network and Systems
Control ID: 3.2.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity
Control ID: Pillar 1
NIS2 Directive – Incident Handling
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Primary/Secondary Education
Cybercriminal networks targeting minors create severe risks for educational institutions through platform abuse, requiring enhanced east-west traffic security and student protection measures.
Higher Education/Acadamia
University Discord/Snapchat usage exposes students to sextortion attacks, demanding zero trust segmentation and egress security to prevent data exfiltration and abuse campaigns.
Computer Software/Engineering
Platform providers like Discord face regulatory scrutiny over minor safety, requiring multicloud visibility controls and threat detection capabilities to combat cybercriminal network activities.
Law Enforcement
International cybercriminal investigations necessitate encrypted traffic analysis capabilities and cross-border coordination to prosecute network-based exploitation cases involving multiple jurisdictions and platforms.
Sources
- UK man tied to The Com sentenced for abusing 117 victimshttps://cyberscoop.com/uk-justin-swaddle-the-com-sentenced/Verified
- Hacker Com: Cyber Criminal Subset of The Community Is a Rising Threat to Youth Onlinehttps://www.fbi.gov/investigate/cyber/alerts/2025/hacker-com-cyber-criminal-subset-of-the-community-is-a-rising-threat-to-youth-onlineVerified
- The Com: Theft, Extortion, and Violence are a Rising Threat to Youth Onlinehttps://www.ic3.gov/PSA/2025/PSA250723-3Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could likely limit the attacker's ability to escalate control and exfiltrate sensitive data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit initial trust to gain sensitive information would likely be constrained, reducing the effectiveness of social engineering tactics.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate control through coercion would likely be limited, reducing the scope of their influence.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally within the network to identify and target additional individuals would likely be constrained, reducing the spread of the attack.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to maintain control and communication through various online platforms would likely be limited, reducing their persistent access.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data would likely be constrained, reducing the risk of data leakage.
The attacker's ability to achieve their objectives of exploitation and control would likely be limited, reducing the overall impact on victims.
Impact at a Glance
Affected Business Functions
- n/a
Estimated downtime: N/A
Estimated loss: N/A
Personal information of 117 female victims aged 13 to 17, including names, addresses, and school details.
Recommended Actions
Key Takeaways & Next Steps
- • Implement comprehensive monitoring and anomaly detection systems to identify and alert on unusual access patterns and data exfiltration attempts.
- • Enforce strict egress security and policy enforcement to prevent unauthorized data transfers and communications.
- • Apply zero trust segmentation to limit lateral movement within the network, ensuring that users and systems have access only to necessary resources.
- • Enhance user education and awareness programs to recognize and report social engineering attempts and phishing campaigns.
- • Regularly audit and update access controls and permissions to ensure they align with the principle of least privilege.



