Learning from Bomb Threat Hoaxes Targeting Recent US Elections
A collaborative analysis of past (2024-2025) and emerging election bomb threat activity, prepared for election officials and law enforcement.
Three organizations. One shared view of the threat.
We are the Bomb Threats Task Force (BTTF)—a working group of three organizations that came together in 2026 to examine bomb threat hoaxes in the 2024 and 2025 elections to help election officials and law enforcement prepare for what could come next.
- SocialScout: an election-security team that tracks threats, harassment, and influence operations targeting US elections.
- Nisos: a human risk intelligence company that uses open-source intelligence to attribute online threats to the people behind them.
- Microsoft: protects customers around the world from cyber threats. Through its Tech for Society initiative and the Microsoft Digital Crimes Unit, Microsoft brings threat intelligence, investigative expertise, and election security experience to help mitigate election security issues, including bomb hoaxes.
No single organization has the full picture. Election officials see the inbox, law enforcement responds to 911 calls, and researchers see the sender infrastructure. This report pulls those views together in one place.
The report is the beginning of our work to support those who will make decisions in the moment a threat comes in—elections officials, local law enforcement, and the partners who support them.
Examining the patterns behind recent election threats
The research relies on publicly available news reporting, open-source intelligence, and third-party investigative tools. We refer to the threats as bomb threat hoaxes throughout the report; we do not focus on real or credible bomb threats but rather the hoaxes designed to create confusion and chaos. All the bomb threat hoaxes we evaluated were sent via email, not phone. We continue to receive new information regarding bomb threat hoaxes; each new piece of evidence improves our understanding and analysis. For more information on our underlying sources and approach, please see Appendix A: Methodology and Tradecraft.
We left active news URLs live so readers can follow the reporting. Other links—particularly to sender infrastructure or hostile domains—are defanged, a security-industry convention that wraps the period in brackets (e.g. cyberfear[.]com) so the link cannot be clicked or visited by accident.
What the 2024 and 2025 threats reveal
The threat of similar foreign or domestic actors leveraging anonymous infrastructure to coordinate simultaneous, widespread bomb threats for disruption very likely will persist in the 2026 midterms. While we do not assess that artificial intelligence (AI) played a significant role in the 2024 and 2025 hoaxes, the technology could enable rapid message generation and sending at scale in future elections.
- Actors sent approximately 250 likely bomb threat hoaxes across two waves in 2024 and at least 30 more threats in 2025.
- On Election Day, Tuesday, 5 November 2024, polling locations in Georgia, Michigan, Pennsylvania, Wisconsin, and Arizona received more than 124 threats, which forced evacuations and, in some jurisdictions, court orders to extend voting hours.
- A second wave occurred during ballot counting on Friday, 8 November 2024 and targeted California, Maryland, Minnesota, and Oregon with at least 126 threats.
- In 2025, seven New Jersey counties received at least 30 threats.
- Both actors used single-purpose accounts on privacy-focused or foreign email infrastructure to limit attribution. Muted Umber routed threats through Mailum/CyberFear, adopted American-sounding and ideological handles, and targeted election offices to disrupt voting and vote counting. Sudden Vermillion routed threats through Mail[.]ru, often using foreign-sounding names to target polling locations—churches, schools, and community centers—on Election Day.
- In the last two years, similar waves of bomb threat hoaxes have targeted zoos and aquariums, airports, LGBTQ+ events, state capitols, and schools, but we have not directly connected these to the election-related campaigns.
- Actors very likely will continue relying on privacy-focused or foreign email infrastructure, and incorporate AI to evolve their tradecraft. Copycats perceiving the 2024 and 2025 disruptions as successful may amplify volume and make it harder to distinguish coordinated bomb threat hoaxes from real threats.
About Nisos®
Nisos is the human risk management company specializing in unmasking threats before they escalate. The company is a trusted advisor, operating as an extension of security, intelligence, legal, and human resource teams to protect their people and business. Nisos’ intelligence-led solutions help enterprises make critical decisions, manage human risk, and drive real world consequences for digital threats. For more information, please visit: https://www.nisos.com.