Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

English-Speaking Cybercriminal Ecosystem ‘The COM’ Drives a Wide Spectrum of Cyberattacks

The English-speaking cybercriminal ecosystem, commonly known as “The COM,” has transformed from a niche community of social media account traders into a sophisticated, organized operation fueling some of the world’s most damaging cyberattacks.

The English-speaking cybercriminal ecosystem, commonly known as “The COM,” has transformed from a niche community of social media account traders into a sophisticated, organized operation fueling some of the world’s most damaging cyberattacks.

What started as simple forums for trading rare social media handles has evolved into a professional, service-driven criminal marketplace targeting multinational corporations, government agencies, and critical infrastructure across the globe.

The COM’s growth accelerated during the cryptocurrency boom between 2020 and 2021, when cybercriminals shifted their focus from stealing social media accounts to draining digital wallets containing millions of dollars.

This shift introduced new attack methods and monetization strategies that fundamentally changed the landscape of cybercrime.

The ecosystem now operates as a comprehensive supply chain where specialized roles work together seamlessly to execute coordinated attacks.

CloudSEK security analysts identified that The COM’s operational structure mirrors legitimate business models.

Different threat actors specialize in specific roles—some handle social engineering through vishing calls, others manage credential theft, and specialized teams handle data exfiltration and money laundering.

This shift introduced new attack methods and monetization strategies that fundamentally changed the landscape of cybercrime.
Noah Redmond · Thehackingpost

This specialization allows criminal operations to scale rapidly while distributing risk across multiple independent actors.

The emergence of groups like Lapsus$ and ShinyHunters demonstrated The COM’s evolution into theatrical, publicity-driven operations.

Lapsus$ became infamous for breaching major tech companies, including NVIDIA, Samsung, and Microsoft, by manipulating customer support staff through social engineering.

The group pioneered a “leak-and-brag” approach, publicly taunting victims and law enforcement while threatening data releases to accelerate ransom payments.

The Attack Mechanism: Targeting the Human Perimeter

CloudSEK security researchers noted that The COM’s most effective weapon is social engineering rather than technical exploits.

The primary infection vector involves human manipulation through vishing crews who impersonate IT support staff, telecom providers, or corporate help desk personnel.

Advertisement

These operators deceive employees into revealing credentials, approving remote access, or executing system commands that grant attackers entry to corporate networks.

The technique operates through a simple principle: compromising a person is easier than compromising a device. Attackers use detailed victim profiling gathered through open-source intelligence and breached data, enabling highly targeted campaigns.

Once inside networks, attackers leverage legitimate tools like Remote Desktop Protocol and cloud services to move laterally, avoiding detection by blending with regular administrative traffic.

This approach has proven devastatingly effective against even organizations with advanced security infrastructure, making human-focused security measures increasingly critical for enterprise defense strategies moving forward.

Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in  Google .

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories