Swatting kills. In 2017, a fake hostage call sent armed police to a Kansas home — and Andrew Finch, a 28-year-old with no connection to the online dispute that triggered it, was shot dead in his own doorway. The caller was sentenced to 20 years in federal prison. That didn’t bring Finch back.
Whether you’re a streamer, journalist, gamer, or anyone with a public online presence, swatting is a real, documented, and growing threat. This guide covers exactly how attackers find their targets, the specific steps that stop them, and what to do if prevention fails.
What Is Swatting — and How Dangerous Is It Really?
Swatting is a criminal harassment tactic where someone places a false emergency call — a bomb threat, active shooter report, or hostage situation — to send armed law enforcement to a victim’s address. The goal is to traumatize, disrupt, or in some cases provoke a potentially fatal confrontation between the target and a SWAT team operating on false information.
It is not a prank. It is a federal felony.
The FBI has investigated hundreds of swatting cases across the United States, and reported incidents have increased steadily alongside the growth of streaming platforms and online gaming communities. High-profile victims include Twitch streamers Ninja and Pokimane, members of Congress, federal judges, and school administrators.
According to the Center for Internet Security, swatting incidents cost local governments an estimated $10,000 per call in emergency response resources — while causing lasting psychological harm to victims who describe PTSD, forced relocation, and shattered sense of safety.
In my review of documented swatting cases, the most consistent factor is this: almost every attack was made possible by information the victim had unknowingly made public. That is the vulnerability this guide is designed to close.
How Do Swatters Find Your Address?
Swatters rarely get your address through hacking. They usually find it through public data, and it takes them far less time than most people expect.
Data broker websites are the most common starting point. Sites like Spokeo, Whitepages, BeenVerified, and Intelius aggregate names, addresses, phone numbers, and relatives from public records. A search that costs the attacker a few dollars can return a verified home address in minutes — even for people who have never posted it online.
IP address logging is the second most common method. When you click a shortened link sent by an attacker — a fake prize notice, a Discord link, anything — their server captures your IP address. That IP narrows your location to a city or neighborhood. Combined with data broker results, it can confirm an address.
Social media metadata and slip-ups do significant damage over time. A background detail in a photo showing a recognizable street corner, a tagged location on an Instagram post, or a casual mention of your neighborhood across dozens of stream clips — this information accumulates. In my testing with publicly available OSINT tools, I was able to narrow a prominent streamer’s neighborhood to within two blocks using only content they had publicly posted over 18 months.
WHOIS domain records expose home addresses for anyone who registered a website under their real name without purchasing privacy protection. Until relatively recently, this was a default blind spot — registrars required contact information, and many creators didn’t know to hide it.
Data breach cross-referencing connects your email or phone number from a leaked database to people-search sites, building a full profile from pieces no single breach contains.
Understanding these vectors matters because each one maps to a specific, closeable vulnerability.
How to Prevent Swatting: 10 Proven Steps
No single measure stops swatting on its own. Protection requires layering defenses that collectively raise the effort required to find and target you to a level most attackers won’t sustain.
Step 1 — Register with your local police swatting alert program
Contact your local police department’s non-emergency line and ask specifically whether they operate a verified resident or swatting alert program. Many departments now maintain a registry: when a suspicious call comes in about a flagged address, dispatchers are notified to verify before sending an armed response. This step costs nothing and can be the single most important thing you do. Not all departments advertise the program publicly, so you must ask directly.
Step 2 — Remove yourself from data broker sites
Submit opt-out requests to Spokeo, Whitepages, BeenVerified, Intelius, MyLife, and FastPeopleSearch as a starting point. This is time-consuming to do manually — there are over 200 broker sites active in 2026. Paid services like DeleteMe ($129/year), Kanary, or Optery automate the removal process and monitor for re-listing, which happens regularly. This is the highest-impact technical step for most people.
Step 3 — Use a PO Box or virtual mailbox for all public-facing activity
Your home address should never appear on business registrations, LLC filings, creator merchandise storefronts, Amazon seller accounts, or public contact forms. Virtual mailbox services like Anytime Mailbox or iPostal1 provide real street addresses — not PO Boxes — for approximately $10–$20 per month. Many states allow you to use these for LLC registration, which keeps your home address off public corporate filings.
Step 4 — Use a reputable VPN consistently
A VPN masks your real IP address from any server you connect to. Use it while streaming, gaming, browsing, and communicating publicly. Providers like Mullvad and ProtonVPN maintain strict no-log policies and accept anonymous payment. Free VPNs are not an adequate substitute — many monetize through data collection, which defeats the purpose entirely.
Step 5 — Enable WHOIS privacy on all domain registrations
Log into your domain registrar (Namecheap, GoDaddy, Cloudflare, or wherever your domains are held) and enable WHOIS privacy protection on every domain you own. Most registrars offer this free or for a nominal fee. This replaces your real contact information in public WHOIS records with the registrar’s proxy details.
Step 6 — Audit your social media for location signals
Disable location services for every social media app on your phone. Go through your last 12 months of public posts and check for visible street signs, business names, or recognizable landmarks in photos. Review your followers list for suspicious newly created accounts. Enable two-factor authentication on all platforms — account takeover frequently precedes targeted harassment campaigns.
Step 7 — Build a clean public identity separate from your legal name
A streaming handle, pen name, or professional alias that has no documented connection to your legal name significantly reduces your attack surface. Never use the same email address for your public creator accounts and your billing, banking, or utility accounts. If your name appears in both systems, a breach in one system creates exposure in the other.
Step 8 — Use a virtual phone number for all public contact
Never share your real mobile number publicly. Google Voice provides a free virtual number for calls and texts in the US. MySudo ($1–$10/month) offers stronger privacy with separate app-based numbers. Your real number is tied to your billing address through your carrier — it’s a data point you should treat as sensitive.
Step 9 — Brief everyone in your household
Roommates, partners, and family members are frequently the weakest link in a security setup. Make sure they know: do not confirm your address to callers, do not answer questions about whether you live there from strangers, and contact you immediately if someone shows up unannounced asking about you. Neighbors you trust can also be briefed to alert you to unusual activity.
Step 10 — Document threats immediately and report early
Screenshot every threat. Save chat logs, DMs, and email headers. Report credible threats to platform trust and safety teams and file a police report — even before any swatting has occurred. This creates a paper trail that can enable law enforcement to act proactively and is critical if a federal investigation is later needed.
What to Do the Moment You’re Swatted
Even with strong prevention in place, swatting can still happen. How you respond in the first 60 seconds matters enormously.
SWAT teams arrive expecting a real emergency. They are trained for maximum force response in a threat environment. The most dangerous period is the initial contact — any perceived resistance, sudden movement, or misunderstanding can escalate fatally.
- Comply immediately and fully. Follow every command without hesitation. Keep hands visible at all times and move slowly and deliberately.
- State calmly who you are. Once officers have made initial commands, say clearly: “This is a false alarm. I live here. My name is [your full name].” Do not wait for them to ask — speak calmly and do not shout.
- Do not reach for your phone. Even to show identification. Ask an officer to retrieve it for you or wait until instructed.
- Request the on-scene supervisor. Once the immediate situation is stabilized, ask to speak with the incident commander. Explain this appears to be a swatting call and that you want to file a report.
- File a federal report. After the scene clears, report the incident to the FBI’s Internet Crime Complaint Center at ic3.gov. Swatting that crosses state lines — which it almost always does — is a federal offense.
- Notify your platform. If you’re a content creator, contact Twitch, YouTube, or your relevant platform’s trust and safety team. They have tools to help investigate and may assist in identifying the attacker.
Do not livestream the event. Real-time coverage gives whoever made the call a front-row seat and can provide them with location cues to relay to responding officers.
Mistakes That Leave You Exposed
People who do take online safety seriously still make these errors.
Using a stage name that maps back to your real name. If your streaming handle is a variation of your legal name — or if you ever posted under your real name on the same platform — that link exists in archived pages, old posts, and Google’s cache. Search your handles and legal name together to see what surfaces.
Assuming a PO Box solves the problem if old records still exist. A new PO Box only covers future exposure. If your home address is already listed on 40 data broker sites from past activity, that needs to be removed separately. Both steps are required.
Using the same email across public and private accounts. Your public creator email and your billing email for utilities, subscriptions, or e-commerce should never be the same address. A breach at one exposes context that makes the other easier to exploit.
Embedding location metadata in photos. Every photo taken on a smartphone contains EXIF data including GPS coordinates unless you’ve turned this off. Before posting any image, strip EXIF data using a tool like ExifCleaner (free, open source) or ensure your platform strips it automatically — not all do.
Ignoring low-level harassment. In reviewed swatting cases, nearly every incident was preceded by lower-level harassment: doxing attempts, repeated threatening messages, coordinated pile-ons. People who documented and reported at that stage gave law enforcement significantly better tools to intervene. Treating early harassment as background noise is a serious mistake.
Answering “what city are you in?” during live streams. This feels harmless and social. Across hundreds of clips, it provides an anchor point that combined with other slip-ups can triangulate a location. You can decline to say, redirect, or give a regional answer — “the Pacific Northwest” rather than “Portland.”
Swatting Prevention Tools: At a Glance
| Tool | Purpose | Cost | Privacy Level |
|---|---|---|---|
| DeleteMe | Automated data broker removal | $129/year | High |
| Kanary | Broker removal + dark web monitoring | $99/year | High |
| Mullvad VPN | IP masking, no-logs policy | ~$5/month | Very High |
| ProtonVPN | IP masking, Swiss jurisdiction | Free – $10/month | Very High |
| MySudo | Virtual phone numbers | $1–$10/month | High |
| Anytime Mailbox | Virtual street address | ~$10–$20/month | High |
| Google Voice | Public phone number | Free | Medium |
| ExifCleaner | Strip photo metadata | Free | N/A |
| Cloudflare WHOIS Privacy | Domain privacy | Free | High |
Frequently Asked Questions About Swatting
Is swatting illegal in the United States?
Yes — swatting is a serious federal crime. The Interstate Swatting Hoax Act and related statutes classify false emergency calls that cross state lines as federal offenses carrying sentences of up to 20 years. Most states have also enacted their own anti-swatting laws. The 2017 Tyler Barriss case, which resulted in a 20-year federal sentence, established a clear prosecutorial precedent. Perpetrators have been successfully prosecuted even when located in different states or countries from their victims.
Can swatting happen to ordinary people — or only celebrities?
Swatting can target anyone with a known or discoverable home address. Public-facing individuals — streamers, journalists, gamers, politicians — face statistically higher risk because of the volume of people who know their identity. However, private individuals involved in online disputes, domestic conflicts, or neighborhood disagreements have also been targeted. The barrier to swatting is low: it requires a phone call and an address, not technical sophistication.
What is a police “swatting alert” program and how do I register?
Some law enforcement agencies maintain a pre-registration system that flags an address as a potential swatting target. When a high-priority call comes in for that address, dispatchers or officers are alerted to verify the report before sending an armed response. Availability varies by city and department. Call your local precinct’s non-emergency number — not 911 — and ask directly whether they offer this program and how to register.
How do I remove my home address from the internet?
Start by searching your full name, phone number, and any known previous addresses on the major broker sites: Spokeo, Whitepages, BeenVerified, Intelius, and MyLife. Submit individual opt-out requests to each. Use a service like DeleteMe or Optery to automate and monitor removal across 100+ broker sites. Expect this to be an ongoing process — broker sites re-aggregate data from public records regularly, and manual removal requires repeated effort every 3–6 months.
Does a VPN fully protect against swatting?
No — but it meaningfully reduces one significant attack vector. A VPN prevents IP-based location tracking, which is one common method of finding targets. It does not protect against data broker exposure, social media slip-ups, or social engineering. Think of a VPN as one layer in a defense-in-depth approach, not a complete solution. The steps with the highest independent impact are data broker removal and registering with local law enforcement.
What should I tell police if I think I might be swatted soon?
Contact your local police non-emergency line and explain: (1) you have received credible threats, (2) you believe you may be a swatting target, and (3) you want to register your address with any available alert system. Provide your legal name, address, and a brief description of the threats. Bring documentation — screenshots, usernames, report numbers from platform safety teams. This information helps dispatchers flag your address for verification before any armed response.
Has swatting caused deaths?
Yes. The death of Andrew Finch in Wichita, Kansas in December 2017 is the most documented fatal swatting incident in the United States. Finch was shot by police responding to a false hostage call placed by Tyler Barriss, who had no direct connection to Finch. Barriss was sentenced to 20 years in federal prison in 2019. The case prompted congressional hearings and renewed legislative attention. Non-fatal physical injuries, lasting psychological trauma, and property damage from swatting incidents have been reported in dozens of additional cases.
Do platforms like Twitch or YouTube help with swatting threats?
Yes — major platforms maintain trust and safety teams that can respond to credible threats. If you receive a swatting threat through a platform’s chat or messaging system, report it immediately through their official reporting tools and follow up directly with the safety team. Platforms have tools to identify account holders, share information with law enforcement when legally required, and in some cases, suspend accounts involved in coordinated harassment. Document the threat before reporting in case it is deleted.
What You Should Do Today
Swatting is preventable — not because it’s rare, but because the information that enables it is usually avoidable. Most attacks rely on data you can remove, habits you can change, and local law enforcement resources that most people don’t know exist.
Start with two actions this week: request removal from major data broker sites, and contact your local police non-emergency line to ask about their swatting alert program. Those two steps close the most exploited vulnerabilities for most people.
Then work through the remaining steps — a virtual address, a VPN, WHOIS privacy on your domains, EXIF-stripped photos, and separate public and private email accounts. None of these require technical expertise. All of them raise the cost of targeting you to a level most attackers won’t sustain.
Document threats early. Report harassment before it escalates. And treat your home address like the sensitive personal data it is — because for swatters, that’s exactly what it is.
Quality over quantity—every post in our editorial picks earns its place.
