1378, Part 1
Of all the 764 splinters we've investigated, the one called 1378 was simultaneously the most sadistic and the easiest for our team to dismantle. This is a success story.
As the sadistic child exploitation group known as the 764 network continued to morph and evolve, predators involved in the group’s criminal activities began to split off from the main group and form their own splinter factions. These individuals are obsessed with attention. They hope that by creating their own version of 764, they can gain notoriety and rise in status within the broader landscape of extortion Com.
Start here to learn more about 764 and Com:
These groups have taken on many names – Harm Nation, 646, Court, Leak Society, and Slit Town are some notable splinters that have been mentioned in recent arrest records. It generally isn’t smart to give these groups individual recognition. All of them are involved in the same criminal activities within the same core group of abusers, and their sole intention for splitting off is to get attention. It makes more sense to blanket them all under the 764 umbrella, both to avoid confusing the general public when reporting on it and to deny the bad actors their place in the spotlight.
Denying them the recognition they so desperately seek also tends to make them angry, and criminals make mistakes when they’re angry.
Though I tend to stick by the general rule of lumping all splinters under the 764 umbrella, there are times when it becomes impossible to tell a story without addressing the subgroup. This is one such story.
The 764 splinter known as 1378 wasn’t much different from the other copycat groups we’ve encountered over the past few years. The members of 1378 operated as a child exploitation and extortion racket, working together to produce nauseating self-harm and sexual content from children in a perverted contest to see who could be the most evil.
Like most splinters before it, they followed the same M.O. After finding unsupervised children on social media and gaming platforms like Instagram, X, and Roblox, they would first groom and then extort their young victims into cutting names and symbols into their bodies, writing on walls with blood, killing and mutilating animals, and sexually exploiting themselves on camera.
1378 had some of the most graphic content we had ever come across, and that’s saying a lot. Gaping wounds, bloody hands scrawling pledges to Satan on walls, and even a disemboweled cat with its intestines strewn out to spell “1378” were posted openly to X by members of the group.
Members of 1378 also used X to direct violent threats at me in a desperate attempt to get attention. I usually avoid giving them that attention on my platform, but the severity of the threats one member, “Script,” made against me and my family pushed me to try something different.
So, at the risk of breaking X’s terms of service, I offered up a bounty.
The reward I offered in exchange for actionable information was only a “head pat”, but that didn’t stop offers from pouring in; from seasoned hunters offering to search private databases to other members of Com who had interacted with Script in the past. And as luck would have it, Script had already been tentatively identified by one of Com’s “anti-extortion” groups.
Anti-extortion (AE) groups consist of other participants in the sprawling online Com landscape who have organized in response to the rise of networks such as 764. Their stated goal is to drive child extortionists out of those spaces. While their intentions are often genuine, formal investigators and researchers must treat these groups with caution.
First, the information they collect on suspects is frequently inaccurate or incomplete. Material obtained from AE groups – typically Doxbin-style entries or similarly formatted dossiers – therefore requires heightened scrutiny and independent verification.
Second, some AE members have themselves been found operating concurrent extortion schemes. In a number of cases, individuals later revealed to be predators have posed as vigilantes in order to target personal enemies inside the same communities. Their objective is frequently to coerce the suspect into deleting accounts rather than to facilitate an arrest. Forcing an account deletion is often claimed as a success; in practice it simply destroys potential evidence and allows the individual to reappear later under a new identity, complicating subsequent criminal investigations.
Finally, AE participants rarely submit tips through official channels. Information identifying a possible 764 member should be reported to the FBI’s National Threat Operations Center (NTOC) and the National Center for Missing & Exploited Children (NCMEC) Cybertipline. The formal process can be cumbersome and may risk exposing the tipster’s identity – risks that AE members are generally unwilling to take. As a result, there have been multiple instances in which a 764 participant was identified months or even years before the information reached law-enforcement. In the 764 environment, such delays can translate into dozens or hundreds of additional victims.
When we receive material originating from AE groups, our due diligence begins with a thorough independent background search on the tentatively identified individual. We may, for example, run the name through our own databases, locate family social-media accounts, obtain photographs of the person, and compare those images against screenshots captured during Discord calls or other online interactions.
We also run a parallel reconstruction of the OSINT data using our own resources to see if we can replicate the dox. If we can, we escalate the information to law enforcement via whatever channels are available to us.
The personal dox of Script by an AE guy named Paragon was a rare victory on the first try. Not only were we able to locate family photos of the suspect – 19-year-old Drake Miller from Warren County, Kentucky – but we were also able to replicate the OSINT data via parallel reconstruction. After feeling pretty confident that we had a positive identification, we submitted the information to the authorities.
This is the point where I usually create a file on a suspect, add their name and information to a shared spreadsheet used to monitor our suspects, and wait. A few months went by before Drake Miller’s arrest popped onto our radar in August of 2025.
I was both thrilled and fascinated by the catch. Most of our prior scalps were the result of messages sent to me by victims or by my team’s original OSINT analysis that was sent in to the tip line. This time, the arrest may have been the result of me taking a much more brazen, albeit dangerous, approach to hunting.
Sticking with the spirit of the catch, I quickly made another post on X bragging about the arrest of Miller and warning his friends in 1378 that their time was quickly approaching. I was already being targeted, after all. How could one more post hurt? Maybe I could replicate my success with Miller.
In addition to drawing out Miller’s friends, who immediately retaliated with even more violent threats, my post also caught the attention of the FBI. Being a citizen investigator with no formal relationship to the Bureau and no handler means that anyone from the FBI can contact me at any time and for almost any reason. I had gotten used to receiving calls from field offices all over the United States with questions about 764 subjects.
I also knew from various associates that the FBI was very interested in my online activity. Podcasts I appeared on and even posts I made on X tended to circulate around internal FBI email chains. The knowledge that every post I made online was being read and circulated around the FBI was intimidating.
After I made my post about Drake Miller, the special agent in charge of his case got a hold of me through my X DMs. After doing my due diligence and calling the field office in Kentucky to verify, I got him on the phone. The agent was friendly, but cautious. He wanted to know how I knew so much about Drake Miller’s online activity as “Script”. This information hadn’t been released to the public.
Well, that’s easy, I explained. I made the tip.
The agent told me Drake Miller faced 13 federal child exploitation charges, several carrying mandatory minimum sentences of 10 years. In all, he was charged with two counts of online enticement and 11 counts of production of child pornography. Miller was going away for a very long time.
After expressing my gratitude for the quick work, I shifted the focus of the conversation to the other members of 1378 who were still out there. While the arrest of Miller was encouraging, 1378 activity hadn’t slowed down. Notable members such as Dawn, Varkull, Blade, Bleach, Slitted and Envy had been energized into being even worse. Perhaps it was a silver lining that they had temporarily halted their predation of children to focus on what they saw as the biggest threat to their online existence - me.

Up Next: Part 2 – As the threats towards me increased, so did the flow of information. In a massive team effort, multiple members of 1378 were quickly identified and escalated to authorities, resulting in a cascade of arrests.
1378, Part 2
The FBI Special Agent in charge of Drake Miller’s case listened closely as I described my interactions with him on social media. The agent even raised the possibility of adding another charge to reflect the threats Miller had sent me. As tempting as it was to pursue justice for myself, I was more focused on securing the arrests of Miller’s friends. The agent sent me his email address and encouraged me to forward every piece of evidence I could gather on each subject.












Good stuff.
Well done, looking forward to part 2. Also you write beautifully.