Updates from the CEO

The latest update from Albert Roberson, on where the civil rights docket is heading this term.

Read the update

News and insights

Clery Act

A hoax threat is still a test of the real emergency plan

The September 25 joint Education and Justice Department guidance on swatting is not binding, but it points to where institutions are most exposed: the minutes between an anonymous threat and a decision about what to tell the community.

Published by Albert Roberson 4 min read

A long, empty hallway with sunlight falling through windows and casting shadows across the floor.

What happened

On September 25, 2026, the Department of Education and the Department of Justice jointly issued Dear Colleague Letter GEN-26-04, Guidance to Educational Institutions on Swatting Threats. It is signed by Under Secretary of Education Nicholas Kent and Associate Attorney General Stanley E. Woodward, Jr., and it is addressed to all educational institutions, including colleges and universities and state and local educational agencies. PK-12 districts are within its audience.

The letter defines swatting as harassment designed to deceive an emergency service provider into sending a police or emergency response to a location based on a false report of a serious emergency. It recommends staff awareness training, a coordination structure with outside law enforcement, multidisciplinary threat assessment teams, tabletop exercises, advance plans for notifying law enforcement, emergency communication procedures written specifically for swatting events, designated officials with pre-assigned roles, standard message templates that release only need-to-know information, and a "Report, Don't Repost" approach for threats circulating on social media. It also lists federal criminal statutes that can reach swatting, including 18 U.S.C. 875(c), 1038, and 844(e).

Why this development is significant

The letter is guidance. It states that it "is not legally binding" and is meant to give institutions flexibility. It creates no new obligation. Its significance lies in the two places where it touches obligations institutions already have.

First, it connects swatting response to the Clery Act emergency notification requirement in 20 U.S.C. 1092(f), observing that institutions "may be able to easily adapt these notifications for swatting events." Second, it states that institutions "may also be required to include information on whether a given event is a hoax or a live threat in their Annual Security Report statistics." The letter does not say which Clery crime categories are involved or how a hoax should be counted, and it does not amend the Clery regulations. That sentence will prompt questions the letter itself does not answer.

What it means for institutions

Swatting is built to exploit the exact decision that emergency notification rules require. Under 34 CFR 668.46(g), an institution must immediately notify the campus community upon confirmation of a significant emergency or dangerous situation involving an immediate threat to health or safety, unless notification would, in the professional judgment of responsible authorities, compromise efforts to assist a victim or contain the emergency. A convincing swatting call arrives looking like that confirmation. An office that waits to rule out a hoax risks failing to warn about a real threat. An office that broadcasts every call amplifies the hoax and teaches the community to discount alerts.

The letter's sequence resolves the tension in the right order: take planned steps to ensure safety first, then continue to evaluate whether the threat is real. In practice, that means the notification decision should not depend on first deciding whether the call is genuine. It should depend on criteria written in advance, applied by named people, and documented as the event unfolds. The documentation matters. After the event, the institution should be able to show what it knew at each point, who made each decision, and why.

The follow-up message matters as much as the first one. An all-clear that explains, without speculation, that the threat was determined to be false closes the loop and protects the credibility of the next alert. The letter's emphasis on need-to-know messaging also applies here: the follow-up should not identify individuals or repeat the content of the threat.

Two further points deserve attention. When a hoax threat targets a particular group or space, such as a cultural center, a religious student organization, or a residence hall community, the institution should consider whether the incident also implicates its civil rights obligations to respond to harassment, not only its safety procedures. And for PK-12 districts, which are not subject to Clery, the same framework applies through state emergency operations plan requirements, board policy, and local agreements with law enforcement.

What compliance leaders should review

  1. Walk the emergency notification decision tree through a swatting scenario. Identify who confirms an emergency, on what information, and how quickly a notification can issue.
  2. Confirm that the emergency response and evacuation policy statement in the Annual Security Report describes the process as it would actually operate during a hoax threat.
  3. Prepare pre-approved templates for the initial alert, updates, and the all-clear, including language for a threat later determined to be false.
  4. Name the officials responsible for communications, law enforcement notification, and threat evaluation, with backups and after-hours coverage.
  5. Use a swatting scenario in the annual test of emergency response and evacuation procedures that Clery already requires, and keep the test documentation.
  6. Train the people most likely to receive a threat first: main office staff, residence life, dispatch, and anyone who answers a public phone line.
  7. Decide, in writing and with counsel, how the institution will record swatting events for Clery purposes until the Department explains the statistics sentence, and apply that decision consistently.
  8. For PK-12 districts, align the protocol with the state emergency operations plan requirements and any memorandum of understanding with local law enforcement.

What remains uncertain

The statement about hoax and live-threat information in Annual Security Report statistics has no implementing explanation. The Department published a separate 30-day information collection notice for the Campus Safety and Security Survey on the same day, with comments due October 26, 2026. The notice does not describe the proposed revisions, and we have not confirmed whether they touch on hoax threats. It is also unclear how either department would treat the letter's recommendations in a Clery program review or a civil rights investigation. Institutions should build the protocol now and watch for clarification on the reporting question.

Sources

Trust, operationalized

Work with us

Engagements begin with a scoping conversation. We look at the portfolio you are carrying, the exposure you are managing, and the seat you need covered, then we tell you plainly whether we are the right firm for it.

Book a call