What Being Swatted Taught Me About Personal Security
March 16, 2026 · 5 min read
On January 3rd, 2025, armed officers showed up at my house because someone called in a fake emergency. I want to tell you what that actually looked like — and what it taught me about a threat most of us in security haven't really thought through.
I've spent 25 years helping organizations prepare for security incidents. I've been on the phone during ransomware attacks, in the room during breach disclosures, on the other end of the line when an executive realizes their systems are compromised. I thought I knew what it felt like to be the target. I was wrong.
Being swatted is different from every corporate security incident I've ever managed, and it comes down to one thing: it's immediate, physical, and personal. There's no runbook. No IR retainer to activate. No escalation path. It's just you, your family, and armed officers responding to a threat that doesn't exist.
What Actually Happened
Someone called local emergency services with a made-up story designed to trigger an armed response. I'm not going to get into every detail — partly because some of this is still under active investigation, and partly because the specifics matter less than the pattern.
What I can tell you is the response was fast — which, if the call had been real, would've been exactly right. The officers were professional. Nobody got hurt. And when it was over, I had to sit with the fact that someone had just weaponized emergency services against me and my family.
The investigation is still ongoing. I have a pretty good idea who's behind it. And honestly, I've learned more about the personal attack surface of public figures, security folks, and executives in the months since than in the previous twenty-five years combined.
The Personal Attack Surface Most Executives Ignore
Here's what the swatting attack required: my home address. That's it. Everything else — the fake story, the 911 call, the armed response — all of it flowed from that one piece of information.
Most executives and public figures have way more personal data floating around than they think. Home addresses show up in property records, voter registrations, court docs, and dozens of data broker sites that scrape public records. Phone numbers tied to family members are often easier to find than yours. Your kids' schools, your spouse's employer, your vehicle registration — it's all out there, and someone who wants to do harm can piece it together pretty quickly.
This isn't theoretical. It's your home address sitting in a property record. Your spouse's name in a social media bio. Your kid's school mentioned in a local news article from three years ago. All of it is findable — and for some people, it's already been found.
This isn't something your corporate security program covers. Your org's security posture has zero bearing on whether your home address is sitting in a data broker database. Your endpoint protection doesn't protect your family.
What I Did and What I Recommend
Since January 3rd, I've gone through my personal exposure pretty methodically and started cleaning things up. Some of this anyone can do on their own. Some of it you'll want professional help for. Here's what I'd tell any executive, security professional, or public figure who's starting from scratch:
- •Run a personal data broker audit. Services like DeleteMe, Kanary, and others will show you where your info appears and help you get it removed. It won't catch everything, but it shrinks the haystack a lot.
- •Check your property records. In a lot of jurisdictions, you can ask to have your home address pulled from publicly accessible records, especially if you're in a line of work that makes enemies.
- •Look at your family's exposure too, not just yours. The path to you often runs through the people around you. Your address in a property record is one thing — your address in your kid's school newsletter is something else entirely.
- •Call your local police non-emergency line. Introduce yourself. Tell them you're a potential swatting target. A lot of departments can flag your address so officers have the right context if a suspicious call comes in.
- •Document your exposure before something happens. Know what's out there about you, so if an incident does occur, you already understand what was exploited.
I went back and forth on whether to write this. Security professionals aren't supposed to be the ones who get caught off guard. But that's exactly the problem. I know the threat landscape as well as almost anyone, and I still wasn't ready for this — because I'd never really applied what I know professionally to my own personal life. If even one person reads this and takes their personal security seriously before something happens to them, then the discomfort of putting it out there is worth it.
Next Step
Ready to strengthen your organization's resilience?
A 30-minute discovery call to discuss your cybersecurity posture, incident readiness, and whether advisory support is the right fit.