A single phone call can now ground a flight, evacuate a data center or send armed officers to an executive's front door. It requires no weapon, technical skill or intention to cause real physical harm. And for a growing number of organizations, it is already part of the threat environment, whether they have prepared for it or not.

The number that should concern every security leader

1,019. That is how many hoax bomb threats were made against India's airline sector in 2024. The year before, the figure was 71, a tenfold increase in twelve months. Each one triggered a genuine response: evacuations, mid-air diversions, military fighter escorts and fuel dumps costing hundreds of thousands of dollars per incident. Aviation, though, is only one data point in a much larger story. The same category of threat is now being directed at corporate executives in their homes, AI data centers under construction, election workers, schools, and judges. The vector is different each time. The underlying logic is identical: file a false emergency report, force a response and impose disruption, fear or reputational harm at near-zero cost.


Hoax threats are cheap to execute, difficult to prosecute and increasingly accessible to anyone with a grievance and an internet connection. For organizations that are not prepared, the cost of a single incident can exceed the cost of mitigation measures many times over.


What a hoax threat is and why it works

A hoax threat is a deliberately false communication to emergency services, security personnel or the public, designed to force an operational response in the absence of any genuine emergency. The objective is not violence, but the response itself: the evacuation, diversion, tactical deployment, reputational coverage or the disruption.

The most visceral example is swatting: a false emergency call, typically reporting a hostage situation, active shooter, or bomb threat, that sends armed law enforcement to a target's address. In 2017, a swatting call in Wichita, Kansas resulted in police fatally shooting an uninvolved resident. The perpetrator received 20 years in federal prison. The incident established a hard truth: this tactic carries a real and credible risk of death, for the principal, their family and the officers who respond.

Since then, the threat category has expanded far beyond individual targeting. Threats against critical infrastructure are being posted on social media platforms by ideologically motivated actors. Schools across the United States recorded over 850 swatting incidents in a single 18-month period, at an estimated taxpayer cost exceeding one billion dollars.

Three developments that changed everything

A hoax threat attack once required meaningful technical capability. That is no longer true. Three shifts have turned a niche harassment tactic into a scalable, accessible weapon.

  • Caller ID spoofing. VoIP services allow an attacker to make an emergency call appear to originate from the victim's own number, instant automatic credibility before a word is spoken.
  • AI voice cloning. Generative AI tools now produce synthetic audio of gunfire, screaming and distressed callers convincing enough to pass initial dispatcher checks. The attacker need not speak at all.
  • Commoditized attack services. Criminal actors openly market swatting and bomb threat services on Telegram for under $50 per incident. A motivated individual needs only a target, an address and a grievance. The infrastructure is provided for them. 

That final ingredient, grievance, is the critical variable. And the institutions and individuals who generate grievance at scale are precisely those now being targeted.

Why this is a business risk, not just a security one

The targeting logic of hoax threats follows symbolic and operational value, which is why the pattern maps so cleanly into corporate exposure.

Executive targeting is rising sharply, reportedly doubling in 2025 against the previous year, reaching their highest level on record. The reaction to the assassination of a UnitedHealthcare CEO in December 2024 signaled a broader shift in how a segment of the population views corporate leadership as a target class. Hoax threats sit at the lower-risk end of that same spectrum, and they are accelerating.

Technology and critical infrastructure are drawing sustained online calls for sabotage of AI data centers and violence against tech leaders, with physical incidents already occurring. Even government and judicial officials have been affected: in 2026, Supreme Court Justice Amy Coney Barrett testified before Congress that her family had been swatted and doxxed. The Supreme Court Police is anticipating a 38 percent increase in threats in 2026.


The attack begins on your corporate website, your leadership bio or press release. It ends with armed officers at your executive's front door, a diverted aircraft or a data center evacuation. The gap between those two points is smaller than most organizations assume with direct financial, operational and reputational business implications.


What good preparation looks like

Hoax threats are defensible, but only if the work is done before an incident. Three actions carry the most weight across every vector.

  • Pre-notify law enforcement. Flag executives and key facilities with your local police non-emergency line and request a Computer-Aided Dispatch premise alert, a note that prompts a verification call to your security team before officers deploy. In several US jurisdictions, formal anti-swatting registries exist for this purpose. This single step can stop a tactical deployment before it starts.
  • Reduce the digital footprint. Reconnaissance takes little more than a website and thirty minutes. Remove executive personal information from broker sites and audit leadership pages. A smaller footprint is a harder target.
  • Brief the people who will be in the room. Family members at the residence, aviation cabin crew and ground staff, data center and facility security operations staff are all first line responders. They need to know what a hoax threat looks like, what to do, and who to call. Preparation that does not reach them is incomplete. 

The bottom line

Hoax threats sit at the intersection of digital vulnerability and physical consequence. They begin with open-source data and end with evacuated aircraft, shuttered facilities or armed officers at the door. The best-protected organizations do not necessarily have the largest security budgets. They have done the preparatory work: reducing digital exposure, establishing law enforcement relationships and briefing their people before an incident occurs.

Control Risks advises clients across sectors on hoax threat preparedness as part of broader security and executive protection programs. If this is a conversation your organization needs to be having, we welcome the opportunity.

Sources:

Bureau of Civil Aviation Security (India) 2025;

K-12 School Shooting Database 2024;

Volt AI / Campus Safety Magazine 2025;

The Soufan Center 2025-26;

FBI PSA I-122920;

TorchStone Global Annual Executive Protection Report 2024;

Nisos, Escalating Executive Threats: Key Findings, 2025.

Get in touch

Can our experts help you?