Back to Resources
Beyond the Gates: Using OSINT to Help Prevent School Shootings
OSINT

Beyond the Gates: Using OSINT to Help Prevent School Shootings

US Secret Service research shows that plots against schools are almost always preceded by warning signs, and much of that "leakage" now appears in public online spaces. The Coalition of Cyber Investigators examine how disciplined, lawful open-source intelligence can strengthen school vigilance, verification and safeguarding, and suggest some practical actions for schools, questions parents should ask, and further intelligence-led measures.

Paul Wright & Neal Ysart30 July 202611 min read
Share

INTRODUCTION

In 2021, the US Secret Service National Threat Assessment Center reviewed 67 disrupted plots against schools and found that every case was stopped after someone reported behaviour that caused concern. In many cases, information came from pupils, friends, classmates, family members, school staff, or school resource officers. The findings, which are set out in an analysis entitled Averting Targeted School Violence, have a clear message - prevention measures must include structured vigilance, reporting, assessment, and intervention procedures.

Open-source intelligence (OSINT) has a key role to play in enhancing vigilance, providing the tools and techniques needed to help identify and evaluate these warning signs before they can escalate.

OSINT AND LEAKAGE

The term "leakage" was first used in this context by former FBI profiler Mary Ellen O’Toole in her 2000 study of school shooters. Leakage refers to the intentional or unintentional disclosure of clues about violent thoughts, fantasies, grievances, plans, or intent prior to an act of targeted violence. This could mean a direct statement, a boast, a threat, a diary entry, artwork, video, message, or an online post or comment. When statements like these are made in the public domain, OSINT tools and techniques can help identify, assess and place it in context alongside other relevant indicators.

In a later threat-assessment research paper in 2001, J. Reid Meloy and O’Toole defined leakage more narrowly as communication to a third party of an intent to harm a target. Examples include a threat naming a school or individual, a post praising a previous attacker, sharing images of weapons alongside a grievance, or discussing a desire to harm others. Importantly, they stressed that leakage is an indicator, not a standalone prophecy. In other words, like any risk indicator identified through the analysis of intelligence, it does not in isolation prove that violence will occur. Young people often make impulsive, offensive or overly-dramatic statements and it’s vital to understand the surrounding context. OSINT can help build that picture by providing that context such as what else was said, who saw or heard it, whether the statement appears credible, whether it forms part of a wider pattern, whether the person has access to weapons, or whether there are signs of planning or coordination.

In this regard, OSINT tools and techniques, in the right hands and with the appropriate safeguards, provide a practical opportunity to identify, assess and escalate concerning public material, before the situation develops further.

WHERE WARNING SIGNS MAY APPEAR ONLINE

Schools must recognise that a concerning post may not appear on a pupil’s main Instagram or TikTok account. Much of the online activity relevant to an assessment may be public but dispersed across platforms with different cultures and different levels of visibility.

For example, Reddit is organised into topic-based communities called subreddits. Users often post under pseudonyms, which can encourage candid discussion - and Reddit is known for the ease with which users can create anonymous personas. A public Reddit profile may show a history of comments, interests, grievances, images, links, or participation in particular communities and can provide useful context where a specific concern has already been raised. However, experienced investigators know that this content should never be treated as proof of identity or intent without corroboration.

Discord is structured around servers, which are online communities with text, voice, video, and forum channels. Some servers are publicly searchable, while others are private or invitation-only. Discord is widely used by gaming, hobby, study, and social groups. It can also host conversations that do not appear in ordinary web searches. A publicly visible Discord profile, server description, channel title, or shared invitation link may help clarify a reported concern, however, private content should not be pursued by schools or parents without lawful authority combined with the relevant operational, procedural and legal safeguards.

Other public sources may include YouTube, Twitch, gaming profiles, public Telegram channels, public Facebook groups, online marketplaces, school-related hashtags, blogs, image-sharing sites, and local community pages. The relevant question is always the same: does publicly available material add credible context to a defined threat or concern?

The Coalition of Cyber Investigators describes OSINT, digital forensics, cybercrime, and investigations as connected and converging disciplines. That convergence is particularly relevant in schools. A report of a threatening post may raise safeguarding issues, evidence-preservation issues, incident-response questions, duty of care responsibilities, or questions about the school’s own digital exposure.

These converging issues shouldn’t be taken lightly, nor should they be managed by unskilled or inexperienced resources who may, despite noble intentions, run the risk of inadvertently tipping off a subject that they are under investigation, disrupt or interfere with an ongoing law enforcement investigation, provide a ready-made defence that due process was not followed, or miss critical warning signs that could have helped prevent an atrocity.

SOME PRACTICAL OSINT-BASED ACTIONS FOR SCHOOLS

1. Creating clear routes for concerns

A sensible starting point is to establish effective ways for information to reach the right people. Reports may come from pupils, parents, staff, local residents, police, other schools or an independent whistleblowing channel. They may also arise from cyber intelligence or focused manual OSINT workflows which review relevant public sources for specific threats.

The focus should remain on the identification and assessment of credible local risk indicators. It should not involve indiscriminate monitoring of pupils or attempts to find ordinary behaviour that can be treated as suspicious.

An independent whistleblowing mechanism can significantly strengthen the process. Pupils, staff, parents and members of the community may hesitate to report concerns through normal school channels because they fear being identified, ignored or blamed. Peer pressure can also discourage reporting. A confidential, independent route gives people a safer way to submit concerns quickly, including uploading links, screenshots, documentation and account details, where available.

2. Preserving information properly

When a concern is received, the school or its specialist partner should preserve the original report carefully. This includes recording the source, date and time, relevant account name, original URL where available, screenshots, images, video and any accompanying explanation.

This is more than an administrative task. Material may later be needed to support safeguarding decisions, a police investigation or legal proceedings. Any third-party provider should have appropriate safeguards, skills and experience to preserve potential evidence properly. If they cannot demonstrate this capability, the school should reconsider whether they are the right provider.

Information relating to a potential threat should not be circulated informally through staff WhatsApp, Viber, Signal or similar messaging groups where context, confidentiality and evidential integrity can quickly be lost.

3. Triage, urgency and escalation

The next consideration is urgency. Material that identifies a target, date, location, weapon, intended act of violence or other immediate threat should trigger the school’s emergency and safeguarding procedures. Where there is a credible risk of imminent harm, police should be contacted without delay.

Other concerns may require assessment but not immediate emergency action. The school should still have a defined route for escalation to the designated safeguarding lead, senior leadership and, where appropriate, police, local authority safeguarding teams, parents or carers, and mental health professionals.

4. Verifying public-source information

For less immediate concerns, OSINT can support proportionate verification. This may involve checking whether an account or item of content is publicly accessible, whether it appears authentic, when it was posted, whether it has been taken out of context, and whether other public information supports or weakens the concern.

A single screenshot or anonymous allegation should not be treated as established fact. Accounts can be impersonated, posts can be altered, and content can be reposted without the context needed to understand its meaning. The aim is to establish a reliable picture before decisions are made, while recognising that some reports may still warrant urgent protective action even before every detail can be verified.

5. Building the right capability

Schools should consider who is best placed to undertake this work. Some may choose to invest in training so safeguarding leads can properly undertake basic preservation, verification and escalation. Others may choose to engage specialist cyber intelligence or OSINT support, particularly where information is spread across multiple platforms, changes quickly or requires more advanced analysis.

A school does not need to do everything itself. It should, however, understand where specialist capability can add value and ensure that any work undertaken is lawful, documented and proportionate to the concern.

6. Turning information into protection

Any findings derived from the collection and analysis of OSINT should feed into a wider safeguarding and risk-management process. Depending on the circumstances, the response may involve welfare support, a safety plan, increased supervision, conflict management, protective measures, family engagement or further professional assessment.

OSINT does not replace professional judgement or safeguarding practice but it can help provide critical information and context, allowing the right people to make better decisions before a concern develops into a crisis.

SCHOOLS MUST ALSO REVIEW THEIR OWN PUBLIC EXPOSURE

OSINT also has a defensive purpose. It can show a school what a potential attacker, fraudster, stalker, or hostile actor can discover without ever entering the site.

A school’s public digital footprint may include its website, social media accounts, planning applications, supplier documents, online prospectuses, virtual tours, staff pages, event notices, newsletters, images, archived documents, and posts by third parties.

A cyber risk assessment may identify public material showing:

  • Floor plans, entry points, gates, or site layouts.
  • Security cameras, access-control systems, alarm panels, keys, or staff badges.
  • Arrival and departure routines.
  • School events, visitor arrangements, or evacuation routes.
  • Contact information that could support phishing, impersonation, harassment, or social engineering.
  • Personal information about staff, pupils, or families.
  • Historic documents that should no longer be publicly available.

The Coalition of Cyber Investigators has published analysis of the risks created by publicly exposed information and the importance of disciplined, ethical OSINT. Its article, “Crowdsourced Intelligence: The Power and Perils of Open-source Investigations” explains some of these risks but also reinforces the reasons why poor verification, privacy failures, a lack of procedural rigour and uncoordinated investigations can cause real harm.

Further Intelligence-led Measures

Human intelligence gathering

Warning signs often appear offline first. Friends, family, and staff are often the first to notice and can be a vital source of intelligence. Build a culture of confidential, stigma-free reporting.

School-to-school intelligence sharing

Risks do not stop at the school gate. Formal partnerships with neighbouring schools and local authorities allow for the lawful exchange of anonymised intelligence.

Police-led education

Presentations from cyber investigators can teach students how to spot credible warning signs in online messages and the importance of immediate reporting.

Cyber cadets

A Cyber Cadet programme can give students a structured role as digital safety ambassadors, helping promote responsible internet use and cyber hygiene across the school community.

Understanding how students use the internet

Use education, not surveillance. Anonymous surveys and classroom discussions help reveal which platforms students use, providing further potential intelligence sources.

CONCLUSION – MAKE OSINT PART OF SCHOOL RESILIENCE

The research by O’Toole and others shows that leakage of violent intent frequently appears in public online spaces well before any attack takes place. This creates a clear intelligence opportunity that is tailor-made for OSINT.

Schools and education authorities that do not develop the procedures and capability to gather and assess this information leave themselves open to risks that could otherwise be identified and prevented.

OSINT should strengthen vigilance, not replace human judgement. The people closest to a potential problem often spot it first. Friends, classmates, parents, teachers, pastoral staff and local police need a trusted way to report concerns and be confident that someone competent will take them seriously.

Applying OSINT tools and techniques can bring significant benefits to schools and education authorities, turning scattered information into better-informed safeguarding decisions. Performed properly, it supports verification of public claims, identification of relevant context, evidence preservation, reduction of the school’s own digital exposure, and more effective collaboration with police and specialist partners. However, these benefits only materialise when skills, training and procedural safeguards are in place. Enthusiastic amateurs, however well-intentioned, are not equipped for work of this seriousness and the consequences of failing to identify and act on leakage-derived intelligence are too severe to leave to chance or goodwill.

Schools and education authorities therefore carry a clear responsibility to ensure that any intelligence-led safeguarding work is conducted to the appropriate standard, whether that capability is developed internally or secured through properly qualified external support.

In light of the continuing risk of targeted school violence, it could be argued that failing to take advantage of the benefits OSINT offers may also be a failure in a school’s duty of care towards its pupils and staff.

Authored by:

The Coalition of Cyber Investigators, Paul Wright (United Kingdom) & Neal Ysart (Philippines).

©2026 The Coalition of Cyber Investigators. All rights reserved.

The Coalition of Cyber Investigators is a collaboration between Paul Wright (United Kingdom) - Experienced Cybercrime, Intelligence (OSINT & HUMINT) and Digital Forensics Investigator;

Neal Ysart (Philippines) - Elite Investigator & Strategic Risk Advisor, Ex-Big 4 Forensic Leader; and

Lajos Antal (Hungary) - Highly experienced expert in cyberforensics, investigations, and cybercrime.

The Coalition unites leading experts to deliver cutting-edge research, OSINT, Investigations, & Cybercrime Advisory Services worldwide.

Our co-founders, Paul Wright and Neal Ysart, offer over 80 years of combined professional experience. Their careers span law enforcement, cyber investigations, open source intelligence, risk management, and strategic risk advisory roles across multiple continents. They have been instrumental in setting formative legal precedents and stated cases in cybercrime investigations and contributing to the development of globally accepted guidance and standards for handling digital evidence. Their leadership and expertise form the foundation of the Coalition’s commitment to excellence and ethical practice.

Alongside them, Lajos Antal, a founding member of our Boiler Room Investment Fraud Practice, brings deep expertise in cybercrime investigations, digital forensics, and cyber response, further strengthening our team’s capabilities and reach.

The Coalition of Cyber Investigators, with decades of hands-on experience in cyber investigations and OSINT, is uniquely positioned to support organisations facing complex or high-risk investigations.

Our team’s expertise is not just theoretical - it’s built on years of real-world investigations, a deep understanding of the dynamic nature of digital intelligence, and a commitment to the highest evidential standards.