On September 11, 2023, a caller contacted the IT helpdesk of MGM Resorts International. He had found a LinkedIn profile for an MGM employee, gathered enough personal information to answer identity verification questions, and convinced the helpdesk to reset credentials and disable multi-factor authentication on the account.

The call took approximately ten minutes. What followed took ten days. Casino floors went dark. Slot machines stopped working. Key cards failed. Electronic check-in collapsed. Guests in Las Vegas waited in hour-long queues to receive room keys. The hack cost MGM Resorts an estimated $100 million in revenue and $10 million in immediate recovery costs. Caesars Entertainment, hit by the same group four days earlier, had quietly paid a $15 million extortion demand.

The group responsible was Scattered Spider - a loose constellation of young, English-speaking hackers whose average age, investigators later determined, was around 19. They had started by stealing Instagram handles.

//The COM

"The COM" isn't a formal organisation. It's a term used by researchers and law enforcement to describe the ecosystem of English-speaking cybercriminals who coordinate through a shifting network of Telegram channels, Discord servers, private forums, and real-time voice chats. The community is loud, chaotic, status-obsessed, and remarkably effective.

Its roots trace to 4chan's /b/ board and early Anonymous operations, where the culture of "raids" - coordinated harassment campaigns against specific targets - established both the technical vocabulary and the social dynamics that persist today. From /b/ to IRC to OGUsers to Discord, the throughline is continuous: a community that treats hacking as performance, that values public credit over operational security, and that has consistently demonstrated the ability to compromise targets that employ entire teams of security professionals.

The culture is distinguishable from nation-state hacking or organised criminal groups by its motivation. Financial gain is part of it, but it isn't the whole picture. Status within the community is a significant driver. The ability to demonstrate access - to post a screenshot from inside Uber's Slack, to leak Rockstar's unreleased game footage, to post proof of root on a Fortune 500 network - carries genuine community value. Some of the most significant breaches attributed to COM-adjacent actors produced no meaningful financial return and appear to have been conducted primarily for the flex.

◈ interactive artifact
The Library - COM Coordination Group
Recreated Telegram-style group chat showing COM scene culture - social engineering discussions, SIM swap coordination, and the status-obsessed banter that characterised the community.

//Lapsus$: The Corporate Breach Phase

Between late 2021 and early 2022, a group calling themselves Lapsus$ conducted the most audacious series of corporate intrusions in recent memory. Nvidia, Samsung, Ubisoft, Microsoft, Okta, T-Mobile, Vodafone. Each intrusion followed a similar pattern: social engineering of an employee or contractor, credential theft, access to internal repositories, followed by a demand for payment or - if payment wasn't forthcoming - public data dumps.

The group's Telegram channel served as a running announcement board where they invited the security community and media to watch. They published internal Nvidia schematics. They shared Samsung source code. They held polls on which company to target next. The brazenness was calculated: it maximised the reputational damage to targets and maximised the profile of the group, which attracted new members and motivated internal sources to come forward.

In March 2022, UK police arrested seven individuals aged 16 to 21. The ringleader was 16-year-old Arion Kurtaj from Oxford - identified after a disastrous decision to purchase and leak the Doxbin user database, which prompted the community to dox him in retaliation. His real name, address, and photographs were posted publicly. UK law enforcement had a name and an address.

Even after arrest and on bail, Kurtaj continued. From a Travelodge hotel, using a Fire TV Stick, a hotel television, and a phone for hotspot data - his own computer having been seized - he breached Uber and leaked a 90-video footage dump of Grand Theft Auto VI, Rockstar Games' unreleased title. The leak was the largest in gaming history.

He was assessed as having severe autism and was found not criminally responsible at trial. He was sentenced to an indefinite hospital order. His co-defendants received community sentences.

[WARNING]
Lapsus$ and Scattered Spider both made extensive use of "MFA fatigue" attacks: sending repeated multi-factor authentication push notifications to a victim until they approve one out of frustration or confusion. This technique requires no technical capability whatsoever - only a set of credentials obtained through social engineering or credential stuffing. It defeated MFA deployments at Microsoft, Uber, and Caesars Entertainment.

//Scattered Spider and MGM

The FBI identifies Scattered Spider as a loose group of primarily US and UK actors, overlapping heavily with the COM community and sharing members with Lapsus$-adjacent cells. The name is a designation applied by security researchers to a pattern of behaviour, not a group that self-identifies by that name. Within the community itself, the relevant members would recognise each other by Telegram handles and reputation history.

Their methodology against MGM and Caesars was social engineering against the IT supply chain: identify a human access point - an employee with helpdesk permissions or a third-party contractor - research that person using LinkedIn and breach databases, and make a convincing phone call. Both attacks entered through the same vector. Neither required a zero-day. Neither required nation-state tooling. Both required a confident caller and thirty minutes.

Once inside, the group deployed BlackCat/ALPHV ransomware. The ransomware itself was obtained as a service - another example of the COM's modular economy, where different capabilities are purchased or contracted rather than developed in-house. The callers, the reconnaissance team, the ransomware operators, and the negotiators might all be different people, connected only through Telegram.

[IOC] MGM/Caesars - Attack Summary
Caesars Entertainment: ~September 7, 2023 Attack vector: Social engineering via third-party IT vendor Outcome: Data breach, $15M ransom paid MGM Resorts: September 11, 2023 Attack vector: LinkedIn OSINT + helpdesk MFA reset social engineering Duration: ~10 min initial call; 10-day disruption Financial impact: $100M+ lost revenue, $10M recovery Group: Scattered Spider / UNC3944 (ALPHV affiliate) Arrests: 5 defendants charged 2024; UK teenagers arrested separately

//Why Law Enforcement Struggles

The COM's demographic profile creates genuine challenges for investigators. The actors are typically minors or young adults. Many are in the UK, where extradition and prosecution processes are slower. Several have received autism diagnoses that complicate prosecution and sentencing. The community is highly diffuse - disrupting one Telegram channel produces five replacements.

There's also a cultural mismatch. The FBI's most effective counterterrorism and organised crime tools - flipped informants, undercover operations, financial tracking - work best against structured groups with stable membership and financial flows. The COM is chaotic, membership-fluid, and partially motivated by non-financial incentives that financial surveillance doesn't capture. The kids doing this aren't, in many cases, primarily doing it for the money.

FBI Director Christopher Wray, at a 2023 conference, described the COM as among the most disruptive threat actors his organisation currently faces - not because of technical sophistication, but because of the combination of social engineering skill, community organisation, and operational tempo. They move fast. They don't need to be sophisticated. And there are always more of them.

//The Trajectory

The line from 4chan raids to Scattered Spider is continuous. Each phase was a natural evolution of the previous: 4chan raids became Anonymous operations became OGUsers account trading became SIM swapping became Lapsus$ corporate intrusions became Scattered Spider ransomware.

What changed across that evolution was not the people - many of the individuals involved are connected across phases - but the stakes and the monetisation. The same social engineering skills that worked for stealing an Instagram handle work at the IT helpdesk of a Fortune 500 company. The same reputation-driven culture that made OGUsers handles valuable made Lapsus$ leaks prestigious. The same Telegram infrastructure that coordinated account theft coordinated multi-million dollar ransomware deployments.

The community is still active. The techniques are still the same. The targets are still the same: any organisation that trusts a human being on a phone call.