764 & Its Offshoots / "com" / Internet Extortion Groups - A decentralized extortion community filled with pedophiles, degenerates and larpers on Discords and Telegram chats

  • Want to keep track of this thread?
    Accounts can bookmark posts, watch threads for updates, and jump back to where you stopped reading.
    Create account
Given the money laundering charges, I wonder if this is his cash/cryptocurrency being discovered and seized. If they can't recover the funds, they'll take X amount of his shit, which adds up to the value of the forfeiture order (if it involves criminally obtained funds).

Quintanilla was sentenced in January 2023 to 200 months in custody, and was also ordered to pay a forfeiture of $75,080. He was additionally responsible for a $15,000 fine, a $1,500 special assessment, and $4.1 million in restitution (jointly with co-defendants)
Given the above, the feds are likely seizing his shit to fund the due restitution.
Co-defendant (identified as “AC”) received a forfeiture of $947,454, along with a $915,000 fine, a $6,100 special assessment, and the same restitution amount
Could you provide a link for this? I think you may be getting Aurelio Quintanilla Jr. mixed up for another random guy called Ricardo Quintanilla.
IMG_0305.webp
Link to this document
In this document AC is also mentioned and you can see his name right there. This case had to do with money laundering and I don’t think it had any CSAM charges. I’m pretty sure you’re getting it mixed up here, but you could be right about them seizing his things for the restitution he couldn’t pay.
 
Roblox released an article saying they're opposed to vigilantism on their platform. Have any of the arrests we know about involved vigilante groups or only police investigations? These groups use Roblox to recruit, so it would be interesting to know what lead to their arrests.
 
Roblox released an article saying they're opposed to vigilantism on their platform. Have any of the arrests we know about involved vigilante groups or only police investigations?
Calling the police to report a crime being committed in public, or blocking pedophiles from your private server, are not "vigilantism." Actively assisting sex predators by covering up their crimes for them is what is called being an accessory after the fact and is in fact itself a crime.
 
Calling the police to report a crime being committed in public, or blocking pedophiles from your private server, are not "vigilantism." Actively assisting sex predators by covering up their crimes for them is what is called being an accessory after the fact and is in fact itself a crime.
I agree with you. But making youtube exposure videos is a form of vigilante action. Shining a spot light on things before action can be taken makes the criminals go underground
 
Roblox released an article saying they're opposed to vigilantism on their platform. Have any of the arrests we know about involved vigilante groups or only police investigations? These groups use Roblox to recruit, so it would be interesting to know what lead to their arrests.
The 'vigilantism' in particular was the equivalent of "To Catch a Predator" or the various youtube pedo-sting groups. Pretty sure they were all "underage" decoy into irl sting meetup into cops-on-scene type deals.

Unsure how much actual 'vigilantism' is being done on Roblox outside of Schlep, who was banned recently sent a C&D by Roblox. The significant uproar about it is was lead to their press release about this matter.


So, not related to COM stuff given it was all. uploaded to YouTube, plus using Roblox to try and meet and rape children isn't really their M.O.
 
I agree with you. But making youtube exposure videos is a form of vigilante action. Shining a spot light on things before action can be taken makes the criminals go underground
That makes every newspaper a vigilante operation. The term becomes all but meaningless at that point.
 
Screenshot_20250731-070813~2.webp

If social media platforms do end up requiring ID for age verification, the groomers' modus operandi is going to take a massive blow, never to fully recover. It's funny to imagine all the 764 teens and adults on Discord scrambling to secure fake IDs in time so they don't get kicked off or linked to their crimes.

That was the last screenshot I got of the sextortion manual before it got pulled from the Internet Archive. It was eye-opening while it lasted, but good riddance.1000001795.webp
 
It's funny to imagine all the 764 teens and adults on Discord scrambling to secure fake IDs in time so they don't get kicked off or linked to their crimes.
I'm not sure if it was Trippy or someone else that got arrested but I remember having a laugh at the fact that one of the recent arrests only really happened because a couple subpoenas were issued. A couple subpoenas to platforms got them a home IP, then a subpoena to the ISP led to the arrest. I'm not sure any of these people are smart enough to secure a fake ID. They'd probably just upload their real IDs and then hope for the best lol
 
https://databreaches.net/2025/08/09/scattered-spider-has-a-new-telegram-channel-to-list-its-attacks/ (Archive)

Scattered Spider has a new Telegram channel to list its attacks​

Posted on August 9, 2025 by Dissent

Commenters on reading the new Telegram channel call it “schizo,” “complete chaos,” and “insane.” DataBreaches would just call it “overwhelming.”

A new Telegram channel appeared on Friday afternoon with a name conflating three groups: Shiny Hunters, Scattered Spider, and Lapsus$. How long it will last before it gets banned remains to be seen, but in less than 24 hours, it has already revealed numerous breaches, proof of claims, and data.

Unlike some leak/sales channels that provide a quick statement about a breach and then leak the data or post a sales link, initial posts on the channel were a mix of partial leaks, posts saying “HMU” (“hit me up”) if people were interested in buying the data, memes, commentary, and threats.

Samples and Screenshots​

In a matter of hours, the group leaked a number of files, including the court filings related to the Qantas and Legal Aid Agency injunctions sent to ShinyHunters. Other legal documents that they leaked included the cover page of a subpoena served on Google, a request for mutual assistance that France sent to Moldova (and DataBreaches has no idea what that was about), and ShinyHunters’ replies to the Qantas injunction, previously reported on DataBreaches.net.

Many of their posts revealed data about previously disclosed incidents. The following is not a complete list by any means:

  • Although the Victoria’s Secret breach in May had been disclosed, it was not previously definitively linked to Scattered Spider. In yesterday’s posts, Scattered Spider posted a screenshot taken from the retailer’s console, and a note saying the data were up for sale.
  • A sample of data from Gucci consisted of 100 entries with customer data including name, age range, birthdate (DDMM), email address, mobile phone, and other fields. Gucci is one of Kering‘s brands, with Yves St. Laurent, Alexander McQueen and other high-end brands. DataBreaches does not recall ever seeing any Gucci data leaked before.
  • A screenshot with a listing of .csv files and a note that they were selling a full Neiman Marcus database for 1 BTC. This appears to be the 2024 data breach from the Snowflake campaign. There were also other posts that went back to Lapsus$ attacks and the Snowflake campaign last year.
  • A sample from Chanel with screenshots of negotiations, and a note that they are selling the data. Chanel only first found out about the breach on July 25 and sources had told both DataBreaches and Bleeping Computer that the breach was related to the Salesforce campaign.
  • Other screenshots or posts included references to “Disney,” “AirFrance,” archive.org, S&P Global, T-Mobile, Nvidia, Otelier, Coinbase, Burger King Brazil, Adidas, and CISCO. Some of these incidents had already been linked to ShinyHunters or Scattered Spiders and the Salesforce and Snowflake campaigns. At one point, they leaked Google‘s notification email to people affected by the attack on Google that Google disclosed on August 5. And before they took a break, they leaked Coca Cola Europacific Partners database.
  • Posts with claims or proof of claims about government entities included posts about the governments of England, France, Brazil, and India, as well as posts about hacks involving the Brazilian police and courts and notably, the U.S. Department of Homeland Security. Scattered Spider seemed particularly angry of the 4 recent U.K. arrests and threatened the U.K. Ministry of Justice.

1755356831578.webp
Scattered Spider threatens to leak all of the data from the Legal Aid Agency (MOJ) if Jared Antwon is not released. The attached files are the MOJ’s legal filings to secure an injunction against ShinyHunters. Image: DataBreaches.net.


The U.S. Department of Homeland Security (DHS) has also been targeted:
1755356804593.webp
Scattered Spider posted some proof of claims concerning the U.S. Department of Homeland Security. Image and redaction by DataBreaches.net

1755356777763.webp
“@chinahunterz just popped the DHS again.” Image and additional redaction: DataBreaches.net.


In addition to mentioning exploits and source code that they would be willing to sell, Scattered Spider also used the platform to tease the ransomware that they are reportedly developing:

are CISA ready for whats coming https://sneed.w.org/images/core/emoji/16.0.1/svg/1f97a.svg
n—– not ready for the first kernel level esxi locker

DRAGONFORCE AND LOCKBIT IS NOTHING COMPARED TO SHINYSP1D3R UPCOMING RAAS!!!!!!!!!!!!!

Snowflake 3.0?​

In a recent chat with ShinyHunters, Shiny said:

If trillionaires like Google can’t stop us then billionaires are nothing. Law enforcement doesn’t have such funding or massive budgets either. They will forget about us in a month or two once we’re done. Then we’ll come back and launch another several months to year long sophisticated campaign, Snowflake 3.0. Next time it’s going to be much much worse.
Is Snowflake 3.0 closer on the horizon? Scattered Spider wrote:

Hello, if you work for a Fortune 500 company in retail, insurance, aviation, credit bureaus, finance or banking, travel agencies, car companies or motor related, investment companies, gasoline companies, fastfood/restraunts, hotels, etc

Please contact @UNC5537
UNC 5537 is the tracking number Google used for the Snowflake Campaign, although it has a double meaning in the post as @UNC5537 refers to one of the members of Scattered Spider.

A Direct Message to Salesforce’s CEO​

In addition to posts addressing Mandiant, the U.K. Ministry of Justice, and other entities, Scattered Spider directly addressed Salesforce’s CEO at one point:

Dear, Mr. Marc Benioff

Please pay us 20 bitcoins or else we will leak the data of exactly 91 organizations, multinational conglomerates, and governments.
Benioff has a net worth of more than $8 billion according to Bloomberg and Forbes, and 20 BTC would not make a dent in his wealth, but DataBreaches would be very, very, very surprised if he paid them.

What’s Next?​

Please do NOT use the Comments section to point out all the listings I did not include in this post. I know this is not a complete listing. And if Telegram doesn’t ban the channel, there will be a lot more.

The overall impression the posters created was generally one of kids telling off governments and big businesses, demanding the release of Jared Antwon and others, and generally bragging about their unstoppability.

But there is one impression DataBreaches did come away with apart from thinking that they are angry kids who were somewhat impulsively revealing things last night instead of having and adhering to an organized plan. All that said, they really do come across as unstoppable at this point.

Only posting this because of the title of the channel:
1755357525949.webp

seems like they are COM related, the current telegram link to their channel is https://t.me/leavemealonefbi
 
"If Trillionaires can't stop us, billionaires can't stop us." - Zoomer faggot sitting in stained briefs vaping a fag stick

Post your address on the internet you dress wearing sissy mary and I'll personally stop you using my two bare hands, but you won't because you're a sissy faggot who pees their pants at the thought of having to get up from your computer.
 
View attachment 7717621

If social media platforms do end up requiring ID for age verification, the groomers' modus operandi is going to take a massive blow, never to fully recover. It's funny to imagine all the 764 teens and adults on Discord scrambling to secure fake IDs in time so they don't get kicked off or linked to their crimes.

That was the last screenshot I got of the sextortion manual before it got pulled from the Internet Archive. It was eye-opening while it lasted, but good riddance.View attachment 7784698
Obviously it's a good thing this is gone but the faggots who make use of it probably already have it saved. I wish there was more detailed information saved from it (NOT DIRECTIONS ON HOW TO EXTORT) that could be used to get a better grip of how said faggots operate tho
 
seems like they are COM related, the current telegram link to their channel is https://t.me/leavemealonefbi
SCATTERED SPIDER is a codename given by CrowdStrike to com, basically. Articles will talk about scattered spider as if it's some kind of com subsidiary focused on hacking-related crimes but it's just the same network of zoomer faggots running dig and stuffing creds. That's why you've heard about them, because like all comkids they're attention whores
 
Back
Top Bottom