
A member of “The Com,” a loose-knit online cybercrime collective that targets children and teenagers, has been sentenced to two years in prison for blackmail and sextortion offenses against nearly 120 victims worldwide.
20-year-old Justin Swaddle from Leeds (known as ‘Epstein’, ‘Rugen’ and ‘Moscow’ on Snapchat, Telegram, and Discord) was first arrested in October 2023 by West Yorkshire Police.
Swaddle was sentenced today after pleading guilty to multiple child sexual abuse offenses and blackmail at Leeds Crown Court on July 2. He will also be added to the National Sex Offenders Register and will be subject to a Sexual Harm Prevention Order for 10 years.
“Justin Swaddle targeted young and vulnerable victims all over the world to abuse and scare them into carrying out shocking self-harm and sexual activity, purely to gain popularity with his peers online,” said NCA operations manager Danielle Pownall.
“He gained the trust of his victims, before collecting private information about them so he could threaten to share their intimate images or report them to their school or parents to incite further content.
After taking over the investigation in January 2024, the UK National Crime Agency (NCA) identified 117 female victims worldwide, aged from 13 to 17.
While searching seized devices, the investigators also found images of children with ages ranging from three to 17, several of them showing the result of acts encouraged by Swaddle.
“Telegram messages recovered from Swaddle’s device showed he had attempted to incite a child to sexually abuse a younger child and record it for him, threatening to leak indecent images if further content was not received,” the NCA said.
“Numerous images were found on his device showing victims with self-harm injuries, including Swaddle’s aliases being carved into their skin, and indecent images of children in Categories A to C, with A being the most severe.”

The Com (short for Community) recruits and grooms victims through online platforms, coercing them into self-harm, violence, and the production of child sexual abuse material, often through blackmail.
As Europol reported earlier this year, the Com collective is organized into multiple subgroups, including:
- Offline Com: promotes property damage, harming others, and committing acts of terrorism,
- (S)extortion Com: coerces minors into sex crimes and encourages self-harm and suicide,
- Cyber Com: orchestrates network intrusions and ransomware attacks,
- 764: a subgroup that surfaced in 2021, notorious for grooming young people into producing explicit content later used for extortion or shared among members.
Two alleged 764 leaders (21-year-old Leonidas Varagiannis and 20-year-old Prasan Nepal) were arrested in April 2025and now face life in prison for operating an international child exploitation ring.
The Com was previously linked to ransomware attacks against Las Vegas casino breaches in September 2023 and, more recently, UK retailing giants Marks & Spencer, Co-op, and Harrods in April 2025.
In February, a year-long Europol-led operation dubbed “Project Compass” led to 30 arrests and 179 suspects being linked to The Com. Europol has also flagged 4,340 URLs for removal during a multi-week July operation targeting online content tied to the Com group.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.


