Estimated reading time: 11 minutes
Key Takeaways
- Leakage is common but often hidden: About 40% of mass public shooters leaked warning signs, but most communicated to family, friends, or private channels where law enforcement may never see them.
- High-risk threats are a minority: Only 41% of threats were high-risk, the level at which threat assessment tools recommend intervention. Most threats and threateners are medium or low risk, meaning many potential attackers could be missed.
- Threat content provides clues, but not a perfect map: Only 40% of shooters carried out their threat exactly as communicated, though the content often offers partial insight into plans.
- Offender risk doesn’t predict threat risk: High-risk individuals don’t necessarily issue high-risk threats, so agencies must consider both threat content and offender characteristics.
- Threat assessments are effective but not standalone: They can help identify high-risk situations if information reaches law enforcement and is properly analyzed, but they must sit within a trusted, system-wide approach that includes reporting pathways, interagency sharing, and community engagement.
It’s a regular Tuesday morning at your agency. A community member calls and says their cousin overheard a kid at the high school talking about “shooting up the school.” It’s vague, secondhand, and unsettling, but it’s something.
What would your agency do with that information?
For many departments, the answer is still… not totally clear. And that uncertainty is exactly why understanding threat assessment (and its limits) matters.
Because we’ve seen what happens when warning signs are there, but systems fail.
Nikolas Cruz leaked threats for years before Parkland.
Elliot Rodger filled journals and videos with grievances.
Seung-Hui Cho wrote violent stories and sent disturbing messages while attending the Virginia Tech campus.
Leakage is common. It’s visible. And, too often, it’s missed.
A recent study by Joel A. Capellan and Carla Lewandowski asked the question that sits behind every one of these tragedies:
Could a structured threat assessment have prevented any of them?
Let’s break down what they found and what your agency can take from it.
What We Know About Leakage of Mass Shootings
In the world of targeted violence, one behavior shows up again and again long before an offender ever arrives at a school, workplace, or public space.
Leakage
It’s the idea that a person communicates, directly or indirectly, to someone else that they’re thinking about doing harm. It can be intentional or unintentional, obvious or subtle, a rant or a quiet comment. But it’s communication that signals movement toward violence.
And we’ve seen it across many high-profile cases:
- Nikolas Cruz posted threats and violent statements online and told people he wanted to be a “school shooter.”
- Elliot Rodger wrote extensively about his planned attack in journals and videos.
- Seung-Hui Cho turned in disturbing creative writing assignments and made dark, violent references that deeply concerned his professors.
- Dylan Klebold and Eric Harris left videos, writings, and comments that previewed the ideology and intent behind Columbine.
Prior research has consistently shown that leakage is one of the most common warning behaviors among mass public shooters. It’s not subtle. Many of these individuals tell friends, classmates, online communities, or even family members what they’re thinking about doing.
And yet, leakage only matters if someone recognizes it for what it is, takes it seriously, and knows how and where to report it.
How the Study Tested Threat Assessments
Joel A. Capellan and Carla Lewandowski set out to evaluate whether a Secret Service based threat assessment tool, the kind used to identify high-risk threats and threateners, could have helped prevent past mass public shootings.
To do that, they conducted a retrospective analysis of 278 mass public shootings in the United States between 1966 and 2016. Their dataset required there were 4 or more victims in the incident and excluded felony-related events (e.g., gang-related violence, robberies, home invasions) and domestic/familicide cases to focus specifically on public, targeted attacks.
They built their dataset using open-source records including news articles, government documents, court filings, and multiple existing mass-shooting databases. Each incident was cross-referenced across more than 50 lists and eight search engines to gather as complete a picture as possible.
The threat assessment framework they tested focuses on two things:
1. Threat Risk
How risky is the threat itself?
Threats are categorized as high, medium, or low risk based on their specificity and plausibility whether the offender identifies a target, an act, a method, and shows the capacity to carry it out.
2. Threatener Risk
How risky is the person making the threat?
This score is based on four factors used in the study:
- history of mental illness
- criminal record
- substance abuse history
- acute strain
Individuals fall into low, medium, or high risk based on where they land in the overall distribution.
Using these two components, the authors asked a series of questions to test if a threat assessment would have prevented prior mass shootings:
- How often do shooters leak information?
- How often do they make threats and how specific are those threats?
- How many threats and the threateners would qualify as high, medium, or low risk?
- Who are they revealing these threats to?
- Do “high-risk” individuals make “high-risk” threats?
- And ultimately: Would this threat assessment framework have recommended intervention before the attack?
This is the lens they used to examine all 278 cases.
Key Findings
1. A lot of mass shooters leak but not always in ways that agencies will ever see
40% of shooters leaked info ahead of time.
But 57% of leaks were made to family/friends or left on personal social media. Places where they’re least likely to be reported to law enforcement.
This is key because your agency can only act on information it actually receives.
2. Many threats could have triggered a threat assessment
Of all threats:
- 41% were high-risk
- 27% medium
- 32% low
High-risk threats are the ones the threat assessment actually recommends acting on (specific target, specific act, plausible method).
On paper, that looks promising with nearly half of all threats were the type that would have triggered intervention under this model.
But here’s the issue:
Most threats, and most people making them, fall into the medium or low categories.
- 59% of threats were medium or low risk
- 85% of threateners (the individuals) were medium or low risk
And because the tool only recommends action on high-risk threats and high-risk threateners, a large share of genuine future shooters would have slipped through.
3. Threats Provide Insight, but Often Change
Only 40% of shooters carried out their threat exactly as stated.
50% changed at least one major element such as the target, timing, or method.
And 10% completely deviated from what they originally communicated.
So, while threats don’t always map perfectly onto later actions, their content can still offer useful clues about at least part of the plan.
4. Offender risk level doesn’t match threat risk level
A high-risk offender does not necessarily produce a high-risk threat.
Low-risk offenders often leak to friends/family; higher risk offenders tend to leak verbally or directly to victims.
So, if an agency only acts on those who are high-risk threateners and high-risk threats, they’re missing a huge swath of potential attackers.
So, Can Threat Assessments Prevent Mass Shootings?
The study’s answer: They can help. But not alone.
Threat assessments could theoretically have been applied to 40% of cases.
But they would have failed to intervene in most of them because most threats and most offenders weren’t categorized as “high risk.”
So the tool is helpful, but it’s only one part of the system.
Another major barrier was the simple fact that information often never reached law enforcement to begin with.
What Should Your Agency Do?
Let’s return to that call about the student planning to shoot up a school.
Here’s what a strong system looks like based on both research and real cases:
1. You need a clear internal pathway for where that information goes
Every officer (patrol, dispatch, SROs) should know:
- Who handles threat assessments
- How to document the tip
- What qualifies as actionable information
- What to do immediately if the threat is specific
A lot of agencies fail not because they don’t have a process, but because no one knows what the process is. And even when information is reported, it can still fall through the cracks. Siloed inside a unit, not acted on, or never routed to the person who can actually assess it.
2. Build two-way communication with the public
Prior research shows that family and friends often don’t report threats to law enforcement.
People often hesitate because they worry about:
- “What if I’m wrong?”
- “What if reporting triggers a harsh response for the person I care about?”
- “Will police take this seriously?”
- “Will I stay anonymous?”
Agencies can help close this gap by:
- Educating the public on realistic warning signs
- Highlighting anonymous or low-barrier reporting options
- Reassuring people that reporting doesn’t automatically mean punishment for the person they are reporting on. It can be a pathway to help, support, or intervention.
3. Strengthen intel connections
Fusion centers, SROs, community leaders, campus security teams, mental health partners – all these relationships matter.
After Parkland, we saw the consequences of information staying siloed: the FBI had received tips about Nikolas Cruz but did not share them with local law enforcement, missing opportunities to intervene.
Create a pathway to share credible threat information across agencies and partners.
4. Train officers on leakage and warning behaviors
Most officers know what a “threat” looks like.
Fewer are trained to recognize leakage in non-threat forms:
- Violent creative writing
- “Wish I could make them pay…” statements
- Increased fixation on past attackers
- Suicide + homicide ideation
- Social media spiraling
Threat assessment is about pattern, not profiling.
5. Use the tool but know its limitations
Threat assessments are structured guides.
They’re not crystal balls.
They work best when:
- Information is reported
- Info is complete
- Agencies have the capacity to analyze it
- Follow-up is consistent
They work poorly when:
- Info never makes it to police
- Threats appear “low risk”
- Agencies don’t share intel
- The case spans years like Omar Mateen’s, who exhibited warning behaviors and made concerning statements over a long period, but the scattered information and lack of coordinated follow-up prevented timely intervention.
Resources for Agencies
Here are places to start or strengthen your program:
U.S. Secret Service (USSS) – National Threat Assessment Center (NTAC), Behavioral Threat Assessment Units: A Guide for State and Local Law Enforcement to Prevent Targeted Violence (2024)
International Association of Chiefs of Police (IACP) + Bureau of Justice Assistance (BJA) — Mass Violence Advisory Initiative (MVAI)
Mass Violence Advisory Initiative | International Association of Chiefs of Police
Office of Justice Programs (OJP) — Mass Attacks Defense Toolkit: Preventing Mass Attacks, Saving Lives (2022)
Mass Attacks Defense Toolkit: Preventing Mass Attacks, Saving Lives | Office of Justice Programs
Final Thoughts
Mass shootings leave communities grappling with grief, shock, and the haunting question: “Could this have been prevented?”
Threat assessments aren’t a silver bullet. They won’t catch every potential attacker, they can’t fill gaps in reporting, and they cannot replace community trust.
What they can do is provide a structured way for agencies to evaluate risk. To take the scattered pieces of information, the warning signs, the leakage, and potential threats, and turn them into something actionable.
The research shows that these tools have promise, but only if agencies understand how to use them correctly and recognize their limitations.
At the heart of an effective prevention system is one that:
- Ensures information reaches the right people
- Can consistently assess risk
- Builds trust so that community members feel safe reporting concerns
Threat assessment tools can be greatly beneficial, but only when they sit within a system that works.
Enjoyed this post?
Get more research translated into plain language delivered straight to your inbox twice a week.
Subscribe below and let me know which topics you want to hear more about. It only takes a minute.
If you found this helpful, share it with your team or on your socials. It helps more people make sense of research that matters.