GENERAL

School Swatting in 2026: Why AI Video Verification Closes the 911 Detection Gap

May 5, 2026 11 min read
Swatting hoaxes are crippling K-12 districts, universities, and public venues in 2026. Phone forensics catches the caller eventually. AI video verification closes the 911 detection gap in real time, while the response is still unfolding.
On May 4, 2026, Pennsylvania State Police were investigating multiple swatting incidents across high schools in Bucks, Chester, and Montgomery counties after callers from out-of-state numbers claimed armed suspects were en route to schools with assault rifles and pipe bombs. Pennsbury High School and Council Rock High School were both placed on lockdown. By midday, every threat had been ruled a hoax. By dismissal, the day was a national news story.

That single morning is a snapshot of where school swatting sits in 2026. The hoaxes are coordinated, technically sophisticated, and showing no signs of slowing. And the gap that lets them keep working has nothing to do with how police respond. It has to do with what the 911 dispatcher can actually verify before that response begins.

The School Swatting Wave Has a Pattern

School swatting is the practice of placing a fraudulent 911 call that falsely reports a violent emergency, almost always an active shooter or bomb threat, in order to provoke a heavily armed law enforcement response at a school, university, or public venue. The FBI tracks these incidents through its National Common Operational Picture Virtual Command Center, established in May 2023. The agency now logs thousands of incidents per year.

The K-12 School Shooting Database recorded at least 853 swatting incidents at U.S. elementary, middle, and high schools between January 2023 and June 2024. March 2023 saw 210 K-12 swatting incidents in a single month. On March 30 of that year alone, New York logged more than 220 swatting calls to K-12 schools, forcing districts statewide into simultaneous lockdown while police raced to confirm each threat was unfounded.

The 2025 fall semester brought the higher education wave. By mid-September, 45 U.S. colleges and universities had been targeted with active-shooter swatting calls, including Villanova, Auburn, the University of Tennessee at Chattanooga, the University of Maryland, the University of Southern California, and three colleges in Georgia hit on the same day. TDR Technology Solutions estimated the response cost at the time exceeded $62 million across affected institutions, with roughly 1.1 million students directly impacted by lockdowns and shelter-in-place orders.

The most recent data point predates this article by hours. On May 4, 2026, Governor Josh Shapiro publicly announced that state police were investigating coordinated swatting threats against Pennsylvania high schools. The day before, the same wave hit zoos in Akron, Cleveland, and Columbus, with bomb-threat hoaxes triggering visitor evacuations.

The actors driving these waves are increasingly visible to law enforcement. In late April 2026, federal prosecutors charged a juvenile member of the cybercriminal group "Purgatory" for the August 2025 university wave. In February 2025, 18-year-old Alan Filion was sentenced to four years in federal prison for one of the most prolific swatting sprees in U.S. history: at least 375 hoax calls to schools, houses of worship, government buildings, and private homes across the country between August 2022 and January 2024. Filion used synthesized voices, spoofed phone numbers, and livestreamed his calls to online audiences.

Every one of those incidents shares the same operational reality at the moment the call comes in.

The Detection Gap: Why 911 Cannot Tell Real From Fake

The reason swatting works is not a failure of law enforcement protocol. It is a failure of verification. When a 911 call comes in claiming an active shooter at a school, the dispatcher has no way to see the building, the hallway, the cafeteria, or the parking lot. They have an audio claim, a caller ID that may or may not be spoofed, and an address. That is it.

Standard dispatch protocols correctly require that every active-threat call be treated as real until proven otherwise. The cost of dismissing a real threat is unthinkable. So the response goes out: officers arrive code 3 with lights and sirens, weapons drawn, treating the building as an active crime scene. Lockdowns are ordered. Students hide under desks. Police clear classrooms room by room. The 2023 commentary from the K-12 School Shooting Database team captured the dynamic plainly: when 911 dispatches officers urgently to a reported shooting in progress, the people inside the school often have no idea a threat was even called in until armed officers are searching their classrooms.

Phone forensics is the established response to this problem, and it works, eventually. The FBI's Virtual Command Center collates incidents across jurisdictions. Federal prosecutors trace IP addresses, scripts, and audio fingerprints. Filion was caught. The "Purgatory" juvenile was caught. Those investigations matter. They build deterrence over months and years.

But phone forensics operates on a different clock than the active response. By the time a swatting call has been traced, the lockdown has happened. The trauma has happened. The building-ramming, gun-drawn classroom search, and tearful parent texts have all happened. The detection gap is not whether the caller eventually faces consequences. It is whether the people inside the building, and the officers running toward it, have any visual ground truth before the response unfolds.

What Happens Inside the Building

The cost of an unverified swatting call is not theoretical. Patrol officers responding to a reported active shooter at a school will, in many jurisdictions, breach the building rapidly using whatever means are available. Documented responses include officers ramming school doors with patrol vehicles to gain immediate entry. Teachers in 2023 Michigan swatting incidents described officers entering classrooms with weapons drawn while students hid under desks, no warning given because none was possible.

The trauma that follows does not stop at the school door. Parents who receive panicked texts from their children during a lockdown cannot tell whether the situation is real until well after it ends. Communities that have already experienced a school shooting are re-traumatized every time sirens approach. A school safety researcher at the Rockefeller Institute of Government noted in 2025 that residents of Uvalde, Texas, would visibly freeze every time a siren sounded for years after the 2022 shooting at Robb Elementary, regardless of why the siren was running.

The response itself carries physical risk. In 2017, a Wichita police officer responding to a fake hostage call shot and killed Andrew Finch, a 28-year-old man who had no connection to the original online dispute that triggered the call. In 2020, Tennessee resident Mark Herring died of a heart attack during a swatting response to his home. The FBI has stated publicly that law enforcement personnel have been wounded responding to swatting incidents and that victims have suffered medical emergencies including heart attacks during the events.

And then there is the resource cost. The fall 2025 wave alone consumed an estimated $62 million across 45 universities, with police forces, dispatch centers, and campus emergency response teams diverted from other calls during each event. Every minute of that response is a minute that real emergencies elsewhere are operating without those resources.

Scale of the Hoax Wave

School swatting in the public record

A four-year arc of confirmed incidents and the response burden they have placed on schools, universities, and law enforcement.

853
K-12 swatting incidents Jan 2023–June 2024
220
NY K-12 calls on a single day, March 30, 2023
45
Universities swatted, Fall 2025 semester
$62M
Estimated higher-ed response cost, Fall 2025
1.1M
Students directly impacted, Fall 2025 wave
375
Hoax calls in the Filion sentencing, Aug 2022–Jan 2024

Sources: K-12 School Shooting Database, FBI, U.S. Department of Justice sentencing records, TDR Technology Solutions higher-education tracker, Pennsylvania State Police, contemporaneous news reporting.

The AI Video Verification Layer

AI video verification cannot stop a swatter from picking up the phone. What it can do is provide what the 911 dispatcher and responding officers have never had during an active call: a live, automated visual readout of what is actually happening inside the building.

Computer vision systems running on a school's existing camera infrastructure can analyze every feed continuously, looking for visual evidence of an actual threat. AI weapon detection identifies firearms by their pixel-level visual signature, not by who is holding them. The system flags real weapons in real time and remains silent when no weapons are present. The detection runs whether or not anyone is watching the monitor wall.

For a swatting call, that capability changes the verification clock. A 911 dispatcher receives an active-shooter claim about a specific school. While the call is being processed and units are dispatched, the AI layer is already analyzing every camera in that building. If no firearm has been visually detected, no person is moving with a hostile pattern, and no panic-flight behavior is registering across the building, that information becomes part of the situational picture available to incident commanders before they arrive on scene. It does not cancel the response. It contextualizes it.

The privacy architecture matters here. AI weapon detection at IntelliSee operates without facial recognition or identity-level analysis. The system detects what is present in the frame, not who is in the frame. No biometric data is collected. No watchlists are built. This is not a marketing distinction. It is a deliberate technical decision that allows the technology to be deployed in K-12 environments where facial recognition is increasingly restricted by state law.

IntelliSee holds DHS SAFETY Act QATT designation for firearm detection analytics, the same federal designation tier as ZeroEyes and Omnilert, approved in November 2025 and valid through January 2031. That designation reflects independent evaluation of the technology's effectiveness for protecting against acts of terrorism, including the active-shooter scenario that swatters fraudulently impersonate.

IntelliSee AI gun detection identifying a firearm in real time with a visual alert overlay, the same verification capability that confirms or contradicts a swatting call before officers arrive on scene

Real IntelliSee detection: AI weapon detection identifies a firearm visually in real time, providing the verification layer 911 dispatchers and responding officers do not get from a phone call alone.

Where AI Verification Does Not Help

Honest framing matters on this topic, because the security technology industry has a history of overpromising on swatting solutions.

AI video verification does not stop the call from being placed. Phone systems and platform-level controls handle that, and progress there has been slow. AI video verification does not change federal or local law enforcement protocols. Standard active-threat response will continue to treat every call as real until cleared. AI video verification does not identify the caller or build the criminal case. The FBI's Virtual Command Center and federal prosecutors do that work, and the recent Filion sentencing and "Purgatory" charges show it is working over the medium term.

What AI video verification does is collapse the time between "call received" and "visual ground truth available," from minutes or hours into seconds. That compression matters most in the window when the response is unfolding and the cost of uncertainty is highest. It is one layer in a stack that includes phone forensics, federal investigation, dispatcher training, and lockdown planning. It is not a replacement for any of those layers. It is the missing one most facilities still do not have.

How the Verification Layer Applies Across Sectors

School swatting receives the most national attention, but the same hoax model is hitting public venues, government buildings, and houses of worship.

K-12 schools. The 853 incidents tracked between January 2023 and June 2024 represent the most-targeted vertical, and the one with the least security infrastructure to respond. AI video verification deployed on the cameras a district already owns is the deployment path that fits inside K-12 budgets without rip-and-replace projects. Alyssa's Law compliance and emerging state-level mandates for AI weapon detection in schools provide the policy framework that funding can flow through.

Higher education. The fall 2025 university wave proved that even institutions with mature campus security operations and sworn campus police were unprepared for coordinated, multi-campus hoax campaigns. AI verification across distributed campus camera infrastructure provides a unified visual layer that no human operator could manage at scale. A Tier 1 research university may have over a thousand cameras across academic buildings, residence halls, libraries, and athletic facilities. Continuous human monitoring of that volume is mathematically impossible.

Houses of worship. The Filion case included synagogues and churches among the 375 targeted locations. Faith communities frequently lack dedicated security staff and rely on volunteers or off-duty officers during services. The verification layer becomes especially valuable in environments where the human watch is thin or absent.

Public venues. The early May 2026 hoax wave that hit U.S. zoos demonstrated that the swatting playbook is being adapted to soft-target civic institutions. Museums, libraries, courthouses, and other public buildings are increasingly on the target list. AI weapon detection on existing camera infrastructure provides a verification layer those institutions can deploy without expanding their security headcount.

Frequently Asked Questions

Can AI video verification actually stop swatting calls from being placed?

No. The hoax call itself is a phone-platform and law enforcement problem, addressed through caller-ID forensics, IP tracing, federal prosecution, and platform-level abuse controls. AI video verification operates on a different layer of the problem: it provides visual ground truth during the response window so that incident commanders, dispatchers, and on-scene officers have automated information about whether weapons or threats are actually visible inside the building.

Does not AI weapon detection generate constant false positives?

Modern visual weapon detection systems use multi-stage validation rather than single-frame classifiers, which substantially reduces the false positive rate compared to early-generation systems. Independent evaluations of false positive rates across enterprise AI gun detection deployments show meaningfully different operational profiles depending on architecture. The federal SAFETY Act QATT designation IntelliSee holds reflects formal independent testing of detection performance at scale.

How quickly does the verification feedback loop run?

Visual analysis of camera feeds runs continuously, in real time, across the full deployed camera fleet. When a swatting call is placed, the relevant question is not how quickly the AI system can begin analyzing, because it is already analyzing every frame from every camera at the moment the call is placed. The detection state for any building is current to within seconds at all times. That is the verification clock advantage over phone forensics, which by definition cannot begin until after the call has been placed and routed.

The Reactive-to-Proactive Pivot Swatting Forces

For most of the history of school security, the conversation around hoax calls has focused on what happens after the response: better tracing, harsher penalties, more federal coordination. Those efforts matter. They are also fundamentally reactive. They prosecute the caller after the lockdown has already happened.

The proactive layer the conversation has been missing is the one that runs while the response is still unfolding. AI video verification does not solve swatting. It changes which side of the clock the verification happens on. It moves the moment of "we can confirm what is and is not happening inside this building" from after the police arrive and clear it, to before. In a hoax wave that is producing daily incidents at K-12 districts, universities, and public venues, that compression is what turns a four-hour traumatic event into a 20-minute coordinated all-clear.

The cameras to make this work are already installed in most of the buildings being targeted. The technology to layer AI weapon detection on top of those cameras is operational and federally designated. What remains is the institutional decision to stop running cameras as a recording archive and start running them as a real-time verification layer.

If your district, campus, or facility is rebuilding its swatting and active-threat protocols this year, IntelliSee runs on the cameras you already own. Talk to our team about how the verification layer fits into your existing security architecture.

]]>
Take the Next Step

Turn Your Cameras Into Proactive Protectors

See how IntelliSee layers real-time AI threat detection onto your existing surveillance infrastructure, with no camera replacement required.

Request a Demo