
Social Media and Protective Intelligence
By Matthew C. Parker
CEO, Independent Security Advisors LLC | Director of Training, EPTraining.us
ISA Defending Democracy Initiative
September 2026
Social media has changed how a protection team assesses the environment around a public official or other protected person. Genuine criticism can now exist beside fake accounts, coordinated influence operations, and purchased engagement, making online anger appear larger or more organized than it really is.
The question by the protection specialist is not simply whether an account is fake. The important question is whether online activity is drawing more attention to the principal, reaching real people, or producing behavior that requires the detail to take a closer look.
An executive-protection detail should not discover a developing threat for the first time when the person is twenty-one feet from the principal. At that distance the agent is dealing with an immediate physical threat, but the person may already have spent days or weeks building a grievance, focusing on the principal, researching a residence, identifying family members, studying public appearances, looking at security or preparing to approach.
Social media gives us another place where some of that behavior may appear before the person reaches the principal. It also makes the assessment harder because legitimate criticism, political disagreement, misinformation, foreign influence activity, domestic manipulation, purchased engagement, fake identities and genuine threat behavior can appear in the same online discussion.
The protection team’s responsibility is not to decide whether criticism of the principal is acceptable or to label politically hostile users as bots. The responsibility is to determine what information can be trusted, what the online activity tells us about what is happening around the principal, and whether an identifiable person is doing something that should concern the detail.
The ability to manufacture online voices is established. In July 2024, the Justice Department disrupted a Russian government-operated, AI-enhanced social-media bot farm involving 968 accounts that often presented themselves as people in the United States and were used to distribute messaging supporting Russian-government objectives.
OpenAI later documented a China-origin operation that used fake personas and generated political material supporting opposing sides of divisive American issues. Meta has also reported disrupting large numbers of coordinated fake-account networks, while Google continues to remove coordinated influence networks operating through YouTube.
None of that means a bot is going to physically attack the principal. The concern begins when fake or manipulated information reaches real people, puts more attention on a particular person, strengthens an existing grievance or becomes part of the information somebody uses while deciding what to do next.
There was a time when an executive-protection detail could look at the crowd outside an event, estimate its size, listen to what people were saying, identify organized groups, talk with local law enforcement and develop a reasonable picture of what was happening around the principal. The assessment was never perfect, but the detail could physically observe much of the crowd it was preparing to deal with.
Part of that crowd now exists online, and we cannot automatically assume that every person apparently participating in it is real. The angry constituent may be genuine while several accounts agreeing with him are fake, and a legitimate organization may be criticizing the principal while unrelated fake accounts amplify that message.
A real controversy can also be surrounded by purchased likes, fake comments or automated activity that makes the reaction appear larger than it actually is. A foreign influence operation can introduce a story or accusation without controlling what happens to that information after real people begin repeating it.
Genuine users can share it, commentators can debate it, legitimate news organizations can cover the controversy and ordinary people can encounter the allegation after it has passed through several other sources. By that point, many of the people repeating the information may be completely real and may have no connection to whoever originally created or amplified it.
That distinction matters to a protection team because two questions now have to be answered. The team needs to understand where the information came from when that can be determined, but it also needs to watch what real people are doing after they receive it.
The detail does not need to identify every fake account operating on the internet. It does need to know whether manipulated information is drawing more attention to the principal, exposing personal information, increasing activity around an event or becoming part of the fixation of an identifiable person.
A bot, a fake persona, a coordinated network and a foreign influence operation are not interchangeable terms. A real person can purchase followers or artificial engagement without being part of a sophisticated influence campaign, while a commercial company can sell fake likes and comments to anyone willing to pay.
A domestic organization can operate deceptive accounts, a foreign government can conduct a covert influence campaign and an individual can create several identities simply to make his own opinion appear more popular. A genuine American user can also unknowingly repeat information that originated with a foreign or coordinated operation.
Those are different findings and should remain separate. The original OSINT framework for this project correctly separates confirmed networks from accounts showing several suspicious indicators, possible overseas activity supported by evidence, coordinated behavior and genuine human political accounts.
Several accounts expressing the same political opinion do not automatically constitute a coordinated network. An unfamiliar name, unusual writing style or foreign-looking photograph also does not establish that an account is foreign-operated.
Major social-media platforms use combinations of behavior when they investigate fake accounts and coordinated activity. That is a much better standard than deciding that an account must be fake because something about it simply looks wrong.
An analyst who cannot determine whether an account is authentic should say that clearly. Giving the detail a confident answer that the evidence does not support creates bad intelligence and can pull attention away from the person whose behavior really does require closer examination.
The Russian bot-farm case provides a clear example of how a manufactured political voice can be made to look domestic. The Justice Department described an operation using fake social-media personas that frequently presented themselves as people living in the United States.
The apparent identity matters because people judge information partly by considering who appears to be saying it. A statement openly attributed to a foreign government is likely to be received differently from the same statement appearing to come from an American veteran, voter, parent, employee or business owner.
OpenAI’s investigation of the operation it called Uncle Spam demonstrated another version of the same technique. The China-origin operation generated political material on opposing sides of contentious American issues and created fake U.S.-focused personas to distribute or support that material.
An operation intended to increase political division does not have to convince everybody to support the same position. It can increase anger by telling different groups that the people on the other side are dishonest, dangerous or responsible for the problems they care about.
The person posting a message can be genuine while much of the apparent reaction surrounding that message is fake. Purchased engagement can create the appearance that an accusation, grievance or political argument has far more public support than it actually has.
The NATO Strategic Communications Centre of Excellence demonstrated this in its 2025 experiment examining commercially available social-media manipulation. Researchers purchased engagement on deliberately created, non-political posts across major platforms and identified more than 30,000 inauthentic accounts responsible for more than 100,000 units of artificial engagement.
The experiment generated tens of thousands of purchased comments, likes, shares and views. It was not an election influence operation, but it clearly demonstrated that visible online popularity can be bought.
That matters to a protection team because the number beside a post does not necessarily tell us how many real people support, oppose or even care about what was posted. A message can look far more important than it really is because somebody paid to make it look that way.
Artificial activity can also place that message in front of real people. Once genuine users begin joining the discussion, repeating the allegation and spreading it through their own networks, the original fake activity can become mixed with completely real human behavior.
This is why social-media volume by itself is not a threat assessment. Ten thousand hostile comments do not equal ten thousand people willing to harm the principal, while one account with almost no followers may belong to the person who is actually researching the principal’s residence or attending every public appearance.
The total number of comments can help the detail understand how much attention an issue is receiving. The behavior of identifiable people tells the agents where they need to look more closely.
The older version of the social-media bot was often easier to identify. Accounts sometimes had little history, poor language, stolen photographs, repetitive content and posting behavior that did not resemble normal human use.
Artificial intelligence makes those shortcuts less reliable. Anthropic reported in September 2026 that influence operators were using AI to create fake political personas, profile photographs, fake journalists, fake news organizations and systems capable of producing and distributing political material at scale.
One commercial election-manipulation system identified by Anthropic managed more than 1,000 fake X accounts. The system also used warm-up procedures intended to make those accounts look legitimate before they were used for political activity.
That warm-up process matters because it is designed to defeat the simple checks many people use when deciding whether an account is fake. The account may have a posting history, a photograph, a biography, previous conversations and weeks or months of normal-looking activity before it appears in the political discussion the analyst is reviewing.
Anthropic separately documented a commercial influence operation using approximately seventy fake news websites and more than 250 inauthentic commenting accounts. The operation used fake journalists and AI-generated profile photographs while rewriting legitimate stories in different political directions depending on the intended audience.
An established-looking account therefore should not automatically be considered real simply because it looks more convincing than the crude bots people learned to identify years ago. Analysts still have to verify what they can and state clearly what they cannot.
Coordinated influence activity is not limited to one social-media service. Google’s first-quarter 2026 reporting showed large networks operating across YouTube, including thousands of channels linked to coordinated influence activity originating from several countries.
Google reported terminating 2,254 YouTube channels in January 2026 as part of an investigation into an ongoing PRC-linked network publishing Chinese- and English-language material about China and U.S. foreign affairs. The company reported another 2,602 removals from the same network in February and 1,096 more in March.
The same reporting period included coordinated operations linked to Russia, Iran, Azerbaijan, Bangladesh, Brazil, Indonesia, the United States and several other countries. Those operations supported different governments, organizations and political positions, which is why agents should not think of fake-account activity as belonging to only one ideology or political side.
The protection detail does not need to reproduce the work of a social-media company or intelligence service. It needs enough understanding to recognize that the apparent level of support, anger or outrage surrounding the principal may include activity that is not genuine.
The online discussion belongs in the atmospheric assessment because agents need to understand what is happening around the principal before deciding whether any part of that activity requires a closer look.
The assessment should identify the issue driving the controversy, how much attention the principal is receiving, whether demonstrations or counterdemonstrations are being organized, what stories or accusations are spreading and whether information involving the principal, family, residence or upcoming events is circulating more widely.
That information helps the detail understand what it may be walking into. It does not prove that any particular individual intends to commit violence.
A sudden increase in hostile discussion or demonstrations can change the conditions surrounding an event without producing a direct threat. The detail still needs to distinguish ordinary political opposition from behavior that shows a person is becoming focused on the principal.
Political affiliation, race, religion, ethnicity, immigration status or membership in a demographic group does not establish dangerousness. Attending a protest and criticizing the principal also do not establish that a person intends to cause harm.
Those facts may help explain why people are angry or why they are gathering. The protection concern begins with what identifiable people actually do.
Protective intelligence is not an exercise in deciding whose political opinions are extreme. Agents and analysts are trying to determine whether an identifiable person is showing behavior that gives the detail a reason for concern.
The Secret Service National Threat Assessment Center has repeatedly emphasized examining threatening and concerning behavior in context rather than waiting for an explicit threat. Its guidance identifies behaviors such as fixation, stalking or harassment, significant behavioral changes, increasing anger or aggression, target research, weapons research, attack planning and preparations intended to conceal what the person is doing.
The analyst should be asking whether the grievance is becoming focused on the principal, whether contact is increasing and whether the individual is beginning to identify family members or collect addresses. The detail should also know if the person is researching schedules, discussing protection, appearing repeatedly at locations associated with the principal or trying to get physically closer.
Other behavior raises the concern further. Surveillance, repeated approaches, travel toward the principal, weapons acquisition or statements showing an intention to act all tell agents more about the developing threat than the person’s political position ever could.
An angry citizen may write dozens of offensive messages and never take another step. Another person may never make a direct threat but may quietly spend weeks collecting information about the residence and the principal’s upcoming appearances.
The second person’s behavior may be far more important to the detail. That is why agents cannot use the loudest rhetoric as their only measure of concern.
Public officials are criticized every day, and criticism by itself may have little effect on the protection plan. What agents need to recognize is when the attention begins shifting from the issue to the person.
The argument may begin with an election, prosecution, policy, court decision or other public issue. It changes when people begin identifying the principal personally, circulating photographs, naming family members, discussing the residence or looking for information about upcoming appearances.
Most of the people taking part in that discussion will never threaten anyone. The detail still needs to recognize that more people now know who the principal is, where the principal may be found and why somebody has told them they should be angry.
Publicly available information does not become threatening simply because somebody looks at it. The concern increases when an identifiable person combines that information with fixation, threats, repeated appearances, surveillance or other behavior that shows increasing interest in reaching the principal.
The experience of Georgia election workers Ruby Freeman and Wandrea “Shaye” Moss demonstrates how quickly a person’s exposure can change. Before the controversy surrounding the 2020 presidential election, neither woman was a nationally recognized political figure.
False allegations subsequently accused them of participating in election fraud, and their names and images became connected to a much larger national grievance. Freeman later testified that the FBI advised her to leave her home because it was not considered safe.
She also described strangers appearing at the residence and an incident involving people attempting to enter her mother’s home while claiming they intended to make a citizens’ arrest. Threats, residence concerns and family exposure had now replaced what had begun as accusations about election administration.
The protection lesson is not about which political argument somebody accepts. The lesson is that two previously obscure election workers became the personal focus of anger held by people across the country.
A protection team watching a similar situation should be looking for that shift before people begin arriving at a residence. Agents should know when a person’s name and photograph start circulating more widely, when personal information appears and when identifiable individuals begin moving from commentary toward direct contact or physical approach.
Justice Department election-threat cases provide additional examples of political grievances becoming focused on identifiable people. Brian Jerry Ogstad sent threatening messages to Maricopa County Elections after referring to allegations of election fraud and ultimately pleaded guilty before receiving a federal prison sentence.
Joshua Russell repeatedly threatened an Arizona state election official while accusing that official of failing to protect the 2020 election and committing election fraud. His communications moved well beyond criticism of an election and became direct threats against the individual.
Travis Ford provides an especially useful example for protection training because his messages included comments about whether the target’s security could protect him. According to DOJ, Ford told an election official that the individual’s security was too thin and incompetent to keep him safe.
That kind of change in language matters to an agent because the person is no longer simply saying he is angry about an election. He is now looking at the official as a person and thinking about whether the protection around that person can be defeated.
The same concern applies when somebody begins naming children, distributing family information, asking where the official will appear or discussing the residence. The political grievance may explain why the person is angry, but the questions he begins asking tell the detail whether his attention is moving closer to the principal.
The attack at the Pelosi residence demonstrates a later stage in the same progression. Federal trial evidence established that David DePape selected then-Speaker Nancy Pelosi as a target and collected personal information about her, including her home address, before the October 2022 attack.
DePape then traveled to the Pelosi residence carrying equipment that included a hammer, sledgehammer, duct tape, rope and zip ties. He forced entry into the residence while Nancy Pelosi was away and ultimately assaulted Paul Pelosi.
The sequence matters to protection agents because the violence was not the first thing that happened. DePape focused on a person, collected information, identified the residence, prepared equipment, traveled to the location, forced entry and carried out the attack.
Not every part of that sequence would necessarily have been known to a protection team beforehand. Hindsight gives investigators information that agents may not have possessed at the time, but the case still shows that attack behavior can develop long before the subject reaches the principal.
The case also demonstrates that the intended principal is not the only person at risk when an attacker reaches a residence. Nancy Pelosi was absent, but the person who was home became the victim.
The 2016 armed assault at Comet Ping Pong demonstrates a different concern. The allegations were false, but the person who believed them and the firearms he carried were real.
According to the Justice Department, Edgar Maddison Welch transported three loaded firearms and ammunition from North Carolina to Washington, D.C., and went directly to the restaurant. DOJ said he was motivated, at least in part, by unfounded online allegations claiming that the restaurant was involved in child sex trafficking.
Welch entered the restaurant armed while employees and customers were inside and discharged his rifle while attempting to access a locked area. The story that brought him there had no factual basis, but that did not make the weapon, the person or the danger imaginary.
Protection agents therefore cannot dismiss a developing security concern simply because the underlying allegation is obviously false. The important question is whether somebody believes it strongly enough to identify a location, prepare to act and travel there.
The plot against Michigan Governor Gretchen Whitmer demonstrates how online communication can become part of a developing physical threat. According to the federal complaint, the FBI investigation began after authorities became aware through social media that individuals were discussing violent action against government and law-enforcement targets.
The activity did not remain online. Investigators documented planning directed toward kidnapping the governor, the use of encrypted communications and other security measures, coordinated surveillance of the governor’s vacation residence and discussions involving explosives intended to interfere with law enforcement.
The important distinction for protection agents is between somebody expressing anger and somebody beginning to act on it. Coordinated surveillance of a protected residence and planning intended to interfere with the security response are not simply political speech.
Once individuals begin conducting reconnaissance, coordinating travel, looking for weaknesses in protection or preparing equipment, the agents are dealing with behavior directed toward a protected person and location. That requires a different response from the reaction to ordinary hostile political language.
Foreign influence operations can also combine deception with direct intimidation. In 2021, the Justice Department charged two Iranian nationals in connection with what prosecutors described as a cyber-enabled disinformation and threat campaign related to the 2020 U.S. presidential election.
The indictment alleged that the operators obtained voter information, distributed false election material and sent threatening communications while impersonating members of the Proud Boys. According to DOJ, threatening messages were sent to tens of thousands of registered voters, while false election communications were also directed toward members of Congress, senators, campaign personnel, White House advisers and media organizations.
The charges were allegations when they were announced, and that distinction remains important. The case nevertheless shows why an account’s apparent identity should not automatically be accepted as the real identity of the person behind it.
A threatening communication that appears to come from a domestic political group may actually have another source. The detail still has to evaluate the threat while investigators work to determine who really sent it.
Fake accounts create another problem because they add more low-value information for analysts to review. A principal can receive thousands of hostile comments during a controversy, and those comments may include genuine criticism, attempts to provoke a reaction, repeated language, automated posts and coordinated messages.
Somewhere inside that volume may be one person whose behavior is different. That person may be trying to identify the entrance the principal uses, repeatedly appearing at events, discussing the protective detail or looking for information about the residence.
If every hostile comment receives the same attention, analysts will quickly be overwhelmed. They have to give greater weight to specificity, persistence, fixation, access, capability and movement toward the principal.
The account posting the same slogan hundreds of times may deserve very little protective attention. The account with twenty followers that begins posting photographs taken near the principal’s residence may deserve immediate review.
A protection detail cannot collect screenshots and assume it has intelligence. Agents and analysts still have to determine whether the information, account and apparent source are real.
A screenshot can be genuine while the account is fake. A real account can use a stolen photograph or false biography, while a genuine person can repeat information created by a covert influence operation without knowing where it came from.
Legitimate news organizations may report on a false allegation because the controversy itself has become newsworthy. Fake news organizations can also take real reporting, change the wording or political angle and publish it under fake names.
Anthropic’s September 2026 investigation documented an influence-for-hire operation using approximately seventy fake news websites, fake journalists, AI-generated profile photographs and coordinated commenting accounts. The operation rewrote legitimate stories in different political directions for different audiences.
This is why source reliability has a direct purpose for the detail. Before agents change staffing, routes, residence coverage or event procedures because of something found online, the analyst should establish where the information came from, whether another source confirms it and how much confidence should be placed in it.
Bad information can produce bad protection decisions. As fake content gets better at imitating real people and legitimate sources, agents have to become more careful about what they accept as fact.
A protection team should not require somebody to write a perfectly clear statement of intent before paying attention to concerning behavior. Secret Service threat-assessment guidance has repeatedly emphasized examining concerning behavior in context rather than waiting for a direct threat.
An individual may begin contacting the principal repeatedly without making a direct threat. A person who once discussed a broad political issue may begin focusing almost entirely on one official, identifying relatives, asking about appearances or discussing where the person lives.
The behavior can become more serious as the pattern develops. The individual may begin appearing repeatedly at events, photographing access points, asking questions about the detail, traveling toward locations associated with the principal or acquiring the means to commit violence.
No single act automatically proves that an attack will occur. Agents and analysts have to determine whether the behaviors are connected and whether the person is moving closer to the principal through planning, preparation, capability or physical proximity.
Waiting for the direct threat can mean waiting too long. The purpose of protective intelligence is to recognize meaningful behavior while the detail still has time to do something about it.
Several of the cases discussed here ultimately involved a residence. Ruby Freeman left her home after the FBI advised that it was unsafe, David DePape collected Nancy Pelosi’s home address and attacked there, and members of the Whitmer conspiracy conducted surveillance of the governor’s vacation residence.
The residence presents a different protection challenge from an official building or controlled event. Family members may be present, routines can be predictable, staffing may be lighter and the surrounding property may provide more opportunities for observation or approach.
Publicly available information has also increased what somebody can learn without conducting traditional physical surveillance. Mapping services, property records, social-media photographs, news footage and publicly posted images can reveal streets, entrances, neighboring property, vehicles and movement patterns.
Looking at publicly available information does not by itself establish hostile intent. The concern increases when the person gathering that information has also demonstrated fixation, made threats, repeatedly approached the principal or shown other behavior that concerns the detail.
Agents therefore need to know what information about the residence is publicly available and whether a person of concern appears to be collecting or distributing it. That information may affect residence coverage, family instructions and coordination with local law enforcement.
A grievance directed toward a public official can expand to include spouses, children, parents, aides or other people closely associated with the principal. When that happens, the detail has to consider the safety of more than the principal alone.
The Pelosi attack demonstrates that point directly because the intended target was absent while Paul Pelosi was present. Election-threat cases have also included references to family members and children.
The protection plan should expand when the information shows that the anger is expanding to other people. That does not mean every family member automatically receives a full protective detail, but it does mean the principal and family should understand what has changed and know what unusual contacts or behavior should be reported.
The purpose is not to frighten the family. The purpose is to make sure the people closest to the principal understand the specific concerns the detail has identified and what they need to do if something changes.
Public appearances give people an opportunity to move from online interest to physical proximity. Schedules may be published by the principal’s own organization, news outlets announce appearances, supporters distribute event information and protesters lawfully organize attendance.
None of that is inherently suspicious. Public officials appear before the public, and citizens have the right to attend, support, criticize or protest within the law.
The situation changes when a known person of concern begins using the same public information as part of a larger pattern. Somebody who has repeatedly threatened the principal and then begins asking detailed questions about an upcoming town hall requires different attention from a constituent who simply wants to attend.
Venue photographs also have to be viewed in context. A supporter photographing the stage is not the same as a person of concern repeatedly documenting restricted entrances, vehicle staging areas or where the agents are positioned.
This is why protective intelligence and the advance cannot operate separately. Information about a known subject’s interest in a specific event has to reach the agents controlling access, watching the crowd, managing transportation and coordinating with local law enforcement.
A threat assessment has little value if significant changes in threat information never cause the detail to reconsider its plan. The assessment is supposed to help agents make better protection decisions, not simply prove that somebody completed paperwork.
A change in online activity does not automatically mean that more agents are required or that a public event should become more restrictive. Sometimes the review will show that the current plan is still adequate.
The important point is that the decision follows an evaluation of the information. If the principal’s residence begins circulating within a hostile discussion, residence security should be reviewed, and if a known person of concern begins discussing an upcoming appearance, the advance should receive that information before the event.
If family members are being identified, the detail should determine what guidance they need. If a person begins discussing the protection team or testing access at events, that information should reach the detail leader and the agents responsible for that location.
A sudden increase in expected attendance may also change staffing, observation, access control, transportation or coordination with local law enforcement even when almost everyone attending is peaceful. The response should follow what the assessment tells the detail rather than the politics of the people attending.
Public officials and high-profile protectees often become accustomed to hostile language because they receive so much of it. In many cases that reaction is reasonable because the overwhelming majority of people posting angry comments will never attempt to harm the person they are criticizing.
The principal should not have to read thousands of hostile posts and personally decide which ones matter. A functioning protective-intelligence program should filter that information and identify the behavior the principal and detail actually need to know about.
The detail should be able to tell the principal when an issue is producing a large amount of ordinary political criticism without identifying any current behavior that requires a change. The same detail should also be able to explain when a specific person has moved beyond ordinary criticism and is collecting residence information, discussing the family or repeatedly trying to determine where the principal can be approached.
The principal needs a useful assessment rather than an unfiltered social-media feed. The purpose of protective intelligence is to reduce the noise and help the principal and agents make better security decisions.
The analyst may be the first person to identify a concerning change, but the information has little value if it never reaches the agents responsible for the principal. The detail leader has to understand what was found and determine who else needs to know.
A residence concern needs to reach the residence team, while information involving an upcoming appearance needs to reach the advance. A person focusing on vehicles, arrivals or departures may require attention from transportation and field personnel.
Local law enforcement may also need identifying information, threat history or photographs when appropriate. Staff may need guidance about public schedules or personal information being released, and the principal may need specific instructions based on what the agents are seeing.
Communications in executive protection is therefore more than radio traffic. It is how threat information gets from the analyst to the agents who can change what they are doing.
If the analyst identifies a developing threat and the agent responsible for the location never receives the information, the protective-intelligence process has failed where it matters most.
Executive protection cannot be taught as a series of unrelated physical drills because the threat assessment, intelligence work and protection plan depend on one another. Information collected at the beginning of the process is supposed to affect what agents do later.
MGT 201 addresses what the threat assessment tells the detail, while MGT 302 turns collected information into actionable threat intelligence. MGT 304 requires the analyst to determine whether information and sources can be trusted, and MGT 305 examines the physical environment in which the protection operation will take place.
EPO 300 turns the assessment into the protection plan and rings of security, while EPO 400 carries that planning into the advance. MGT 306 and MGT 307 structure movement, and EPO 301 addresses hostile surveillance and countermeasures.
Communications connects those functions so that something discovered during intelligence collection reaches the people responsible for the residence, event site, route, transportation or principal. Social-media information can affect any of those areas.
A fake account may initially be an OSINT finding, while a rapidly spreading allegation may change what the detail expects at an event. An identifiable person who becomes fixated on the principal may require protective-intelligence attention, while research into the residence or venue may require changes to the advance or protection plan.
The value comes from moving the information through the detail and using it to make decisions. Collecting information that never affects the people protecting the principal does not improve protection.
Executive protection does not provide a justification for monitoring people simply because they disagree with a public official. A lawful protest organization does not become a threat organization because it opposes the principal, and a person’s race, religion, party affiliation or ideology does not establish that the person is dangerous.
Those facts may help agents understand why a group is gathering or why somebody is angry. They do not replace evidence about what an individual is actually doing.
If analysts begin treating political opposition as threat behavior, they create large amounts of useless intelligence and divert attention from the people whose conduct really does warrant closer examination. They also risk missing the person who is quietly researching the residence while everybody else is loudly arguing online.
Agents and analysts should stay focused on behavior relevant to the safety of the protected person. That standard should remain the same regardless of the politics of the principal or the person being assessed.
Foreign influence networks exist, fake personas exist, commercial engagement manipulation exists and false narratives have been followed in documented cases by threats and violence. Those facts do not prove that every politically motivated threat or attack was caused by a foreign influence operation.
OpenAI reported that Uncle Spam generated little genuine engagement despite its ability to produce large amounts of polarized political content. Anthropic has likewise documented sophisticated operations that did not break out into genuine communities in a meaningful way.
That matters because the ability to run an influence operation does not prove that the operation changed what real people did. A protection assessment should not create a connection that the evidence cannot support simply because the resulting story would sound more dramatic.
Agents need to concentrate on what could actually be seen and assessed before a person reached the principal. If fake accounts are inflating a controversy without generating genuine human interest, the detail should know that, and if real people begin repeating the information, the detail should know that as well.
The concern increases when an identifiable real person begins collecting information about the principal, residence, family, event schedule or security arrangements. At that point the detail should concentrate on that person’s behavior rather than continuing to argue about whether every account participating in the larger conversation is real.
The process is easier to understand without attaching complicated labels to it. Fake accounts, coordinated networks, fake news sites or purchased engagement can first make a subject appear more popular, more controversial or more widely accepted than it really is.
Real people can then encounter the material and begin repeating it, arguing about it or distributing it through their own communities. By that point, many of the people sharing the information may have no idea that fake activity played any role in putting it in front of them.
A much smaller number of people may move farther and begin focusing on a specific person. That can mean repeated contact, direct threats, research into the principal, collection of personal information, surveillance, travel, preparation or attempts to get physically closer.
Those steps are not automatic because most influence operations never reach a large genuine audience and most people exposed to false or inflammatory information never threaten anybody. Most angry citizens also never commit violence.
Executive protection agents are concerned with the small number of people whose behavior begins moving toward the principal. The agent’s job is not to assume that everyone exposed to inflammatory information will become dangerous, but to identify the person whose actions give the detail a reason to pay closer attention.
The modern executive-protection detail has to recognize that part of the apparent online crowd can be manufactured. Some accounts may represent fake people, some visible engagement may have been purchased, and some apparent political agreement or outrage may have been amplified by coordinated networks.
The evidence establishing that ability is substantial. The Justice Department disrupted a Russian AI-enhanced bot farm involving 968 accounts that frequently presented themselves as Americans, OpenAI identified China-origin activity using fake personas to generate polarized American political material, and Google continues removing thousands of channels associated with coordinated influence activity.
Anthropic has also documented commercial systems operating large numbers of fake social-media accounts, fake news organizations and fake political personas. These operations demonstrate how much easier it has become to create the appearance of a large online crowd.
That evidence does not mean the anger directed toward a principal is automatically false. It means the detail cannot assume that the number of comments, likes or shares on a screen accurately represents the number or behavior of real people.
The documented threat cases show why that distinction matters. Ruby Freeman and Shaye Moss demonstrate how false allegations can suddenly put previously obscure people at the center of public anger and eventually create threats and residence-security concerns.
Election-threat cases show how a broad political grievance can become focused on an individual, family or security detail. The language matters because somebody who begins discussing whether the detail can protect the principal is doing something different from somebody who simply criticizes an election result.
David DePape demonstrates movement from political grievance into collection of personal information, identification of a residence, preparation, travel, forced entry and violence. The Comet Ping Pong attack demonstrates that a false online allegation can still cause a real person to travel armed to the location he believes is connected to the grievance.
The Whitmer kidnapping plot demonstrates another path in which online communication became part of planning, surveillance and preparation directed toward a governor and her residence. Those cases did not have one cause, and they should not be forced into a single explanation.
They do show different ways information can put more attention on a person, reinforce a grievance, circulate residence and family information, help people communicate and create large amounts of noise around the one person whose behavior may actually become dangerous.
That is why OSINT cannot sit by itself. OSINT helps agents understand what is being said and shared online, while the atmospheric assessment tells the detail what is changing around the principal and protective intelligence identifies the people whose behavior requires closer attention.
The protection plan then has to answer the next question: what do the agents need to do differently, if anything? That may involve no change at all, or it may affect the residence, advance, staffing, transportation, access control, local-law-enforcement coordination or instructions given to the principal and family.
I have said repeatedly in executive-protection training that we cannot wait until a threat is twenty-one feet from the principal before the detail begins reacting. At twenty-one feet, the agent may have only seconds to recognize the attack, move the principal and stop or escape the threat, while protective intelligence can sometimes give the detail something reaction alone cannot provide: time and distance.
The same principle applies to online threat information. Agents should identify concerning behavior before the person researching the residence is standing outside it, before the individual studying the protection detail is testing access and before the person following the public schedule is moving toward the principal at an event.
No intelligence program will identify every fake account, detect every developing threat or predict every attack. The standard is whether the detail used the information that was reasonably available, separated credible information from noise, recognized meaningful changes in behavior and used that information to make better protective decisions.
The voice may be fake and the outrage may be fake, but the person who eventually acts on what he believes can be very real. That is why online activity belongs in the protective threat assessment and why agents need to identify the real behavior before it reaches the principal.
Protective intelligence is the collection and assessment of information that helps agents identify people, behavior and circumstances that may affect the safety of a protected person. It is not limited to direct threats. Agents may also examine fixation, repeated contact, target research, surveillance, residence interest, family information, security questions, travel and preparation when those behaviors appear in a relevant pattern.
Fake accounts can make an issue appear more popular, hostile or widespread than it really is. They can also amplify accusations and expose those accusations to real people. Executive-protection agents therefore need to distinguish artificial online activity from genuine people whose behavior may be changing in ways that affect the principal’s safety.
No. Criticism, political disagreement, offensive language and lawful protest do not automatically make somebody a threat. Agents and analysts should focus on behavior, including persistent fixation, repeated contact, collection of personal information, residence or family interest, surveillance, preparation, weapons acquisition, travel or attempts to approach the principal.
Analysts should look for changes in behavior rather than rely on one isolated statement. Important indicators can include repeated focus on the principal, increasing contact, collection of personal information, interest in family members or the residence, schedule tracking, questions about the protective detail, repeated appearances at events, surveillance, increasingly specific threats, weapons or attack research, travel and other preparation.
A residence can provide an attacker with a predictable location where staffing, barriers and access controls may be different from an official workplace or public event. Publicly available maps, property information, photographs and social-media posts can also reveal details about the location. The information becomes more important when a person who is already showing concerning behavior begins collecting or distributing it.
Protective social-media analysis focuses on behavior relevant to the safety of the principal. Political affiliation, ideology, criticism, race, religion or participation in lawful protest do not establish dangerousness. Analysts should concentrate on specific behavior such as threats, fixation, target research, surveillance, repeated approaches and preparation.
Fake online activity can distort how large or intense a controversy appears and can bury genuinely concerning behavior inside thousands of low-value posts. Agents need to understand the difference between artificial noise and the identifiable person who begins researching, approaching or preparing to act against the principal.
Yes. Online behavior can sometimes precede physical behavior such as target research, travel, surveillance, repeated attendance at events, residence approaches or attack preparation. Not every online grievance becomes a threat, but protective-intelligence analysts should identify when a person’s behavior begins moving from expression toward action.
Defending Democracy: Protecting Public Officials in an Era of Escalating Threats
https://www.eptraining.us/defending-democracy-protecting-public-officials/blog/
Fear Is Already Here: Threats Are Changing How Public Officials Serve—and How Judges Rule
https://www.eptraining.us/fear-is-already-here-threats-elected-officials-judges-2026-threats-to-elected-officials/blog/
EPTraining.us Executive Protection Blog https://www.eptraining.us/blog/
EPTraining.us Home Page https://www.eptraining.us/
By Matthew C. Parker
Independent Security Advisors LLC | EPTraining.us
Article Section: Executive Protection / Protective Intelligence / Threat Assessment
Publisher: EPTraining.us