NVE Tracker: 764 Relational Network

86 incidents · 44 groups · 65 people · 47 aliases · 23 platforms · 20 countries · 24 US states/districts · 10 artifacts · 843 edges
NVE Tracker Home

How to Use the 764 Network Map

This interactive tool visualizes the relationships between people, groups, incidents, platforms, and countries connected to the 764 violent extremist network and its place within The Com, a decentralized meta-network of online violent extremist communities.

What You Can Explore

The network maps 319 entities and 843 relationships, including group lineage and splintering (764 → 8884, 7997, Harm Nation, etc.), who perpetrated which incidents and where, platform usage across the recruitment pipeline (Roblox and Minecraft to Discord to Telegram), cross-group alliances (764 × NLM, MKY × NLM), and the law enforcement response across multiple countries.

Navigating the Map

Sidebar Tabs

Narrative Timeline

The collapsible timeline at the bottom of the screen presents key events in chronological order. Click any event to focus the map on the relevant nodes. Click again to deselect. Toggle the drawer open or closed with the bar at the bottom.

Node Types

Tips

Frequently Asked Questions

What is 764?
764 is a violent online predatory network named for the first three digits of the ZIP code of Stephenville, Texas, where it was founded. The network systematically recruits and grooms minors through gaming platforms, Discord, and Telegram into producing self-harm imagery, CSAM, and violent content. It operates through decentralized cells coordinated by peers and adult recruiters who pose as peers, using blackmail and psychological manipulation to coerce increasingly severe compliance. The FBI designated 764 a “violent extremist” threat in 2023.
What is The Com?
“The Com” (short for “The Community”) refers to the loosely federated online ecosystem encompassing 764, TCC, MKU, and a constellation of affiliated cells that share infrastructure, membership, tactics, and content. Rather than a single organization, The Com is a distributed subculture with fluid membership, shared norms, and a common practice of coercing minors into producing violent and sexual content. It operates primarily through encrypted messaging platforms and private gaming servers. Beyond exploitation of minors, The Com is associated with hacking, SIM swapping, cryptocurrency theft, doxxing, swatting, and non-consensual distribution of intimate imagery.
What are the groups shown in the network?
Groups (shown as dark diamond-shaped nodes) represent organizations, cells, and factions within or adjacent to the 764 ecosystem. These include 764 itself, numbered rebrands like 8884, 7997, and 6996, inner circles like Tophet and 764 Inferno, and affiliated networks such as Harm Nation, CVLT, No Lives Matter, and M.K.Y. Many of these groups share overlapping membership and infrastructure, reflecting The Com’s decentralized structure.
What are artifacts?
Artifacts (shown as brown star-shaped nodes) represent key documents, manifestos, guides, and other operational materials produced or circulated within the network. These include instructional documents on recruitment tactics, coercion methods, and operational security, as well as manifestos and ideological texts. Artifacts help illustrate how knowledge and techniques are transmitted across the network.
What are aliases?
Aliases (shown as teal downward-triangle nodes) represent unidentified co-conspirators referenced in court filings. Federal indictments and plea agreements frequently mention individuals only by their online handles (e.g., “Blood Oath,” “Cript,” “Rex”) when their real identities have not been publicly established. These nodes are connected to the named defendants they conspired with, illustrating the network’s broader membership beyond those who have been publicly identified.
What do the node shapes and colors mean?
Each node type has a distinct shape and color: red circles for incidents (criminal cases), dark diamonds for groups, blue circles for people, teal triangles for aliases, green squares for platforms, orange triangles for countries, purple hexagons for U.S. states, and brown stars for artifacts. You can toggle each type on or off using the checkboxes in the Details tab. The Legend tab provides a full visual reference.
What are the centrality metrics?
Centrality metrics quantify how important a node is within the network. Degree centrality counts how many direct connections a node has. Betweenness centrality measures how often a node sits on the shortest path between other nodes, indicating its role as a bridge or gatekeeper. Closeness centrality measures how quickly a node can reach all others. Eigenvector centrality considers not just how many connections a node has, but how well-connected its neighbors are. Use the “Size nodes by” radio buttons to visually scale nodes by any of these measures.
What is community detection (Louvain)?
Community detection identifies clusters of nodes that are more densely connected to each other than to the rest of the network. This tool uses the Louvain algorithm, a widely used method that groups nodes by iteratively merging them into communities that maximize modularity, a measure of how well the resulting grouping captures the network’s internal structure. Selecting “Community (Louvain)” under “Color nodes by” recolors each node by the community it belongs to, and a set of filter checkboxes lets you isolate individual communities. In this network, communities typically align with operational clusters such as the 764 core, CVLT, M.K.Y., and other affiliated groups, so the view is useful for seeing which people, incidents, groups, platforms, and artifacts cluster together.
How do the entity filters work?
In the Filters tab, select a country, U.S. state, group, or platform to show only that entity together with everything connected to it. For a country or U.S. state, the view expands through that place’s incidents to also show the perpetrators, platforms, and groups involved; for a group or platform, it shows the incidents and people directly attached. One entity applies at a time, and the coercion-technique filter can be combined with any entity selection. The “Clear filters” button resets everything in the Filters tab.
How does the “Coercion Technique” filter work?
The “Coercion technique” dropdown, in the Filters tab, isolates the network by a coercive-control mechanism coded for each incident: sextortion, coerced self-harm, doxxing/swatting, coerced animal cruelty, or physical assault/threats. Selecting one hides everything except the incidents coded for that mechanism, together with the people, aliases, and platforms directly connected to those incidents and the edges among that set, so you can see who was involved in a given type of harm and where it occurred. Groups, countries, U.S. states, and artifacts are not shown by this filter, which is limited to incidents, people, aliases, and platforms. It composes with the “Show node types”, community, and entity filters, and the “Clear filters” button resets everything in the Filters tab. Mechanism coding reflects the project’s incident dataset and records documented conduct only, so it represents a floor rather than a ceiling; incidents with no coded mechanism do not appear under any selection.
How do I navigate the network?
Click and drag on the background to pan; scroll to zoom. Click any node to view its details in the sidebar, including case information, connections, and centrality metrics. Hover over any edge (connection line) to see a tooltip explaining the relationship. Use the search box to find specific nodes by name. The filter checkboxes let you show or hide node types, and the timeline drawer at the bottom lets you explore cases chronologically.
Is the network comprehensive of all 764 nodes and connections?
No. This map reflects what is available in public sources, including federal indictments, plea agreements, DOJ press releases, analyst reports, and open-source research. 764 is a secretive network, and it is reasonable to assume that many of the network’s members and their connections have not been exposed in the public record. The map should be understood as a partial view of a larger, largely hidden network.
Where does the data come from?
The network is built from federal court filings (indictments, criminal complaints, plea agreements, and sentencing documents), Department of Justice press releases, analyst reports, and open-source investigative journalism. Each source is listed in the Sources tab.
How often is this updated?
The network is updated periodically as new court filings are unsealed, new cases are charged, and new research is published. Because the 764 ecosystem is the subject of active federal investigations, new information becomes available on an ongoing basis.