Situation Room: Bomb threat hoax calls were widespread in November 2025, spurring a new focus on readiness.
Resource Library: Bomb Threats and Hoaxes - Mitigating Election Disruption describes five critical steps you can take to reduce the risk of disruption in the event of a bomb threat.
Planning Desk: Explore applying OPSEC measures to effectively protect sensitive information, ensure operational integrity, and enhance employee safety.
Bomb Hoaxes - the new election normal?
At least 41 voting sites in three states – New Jersey, New York, and Pennsylvania – received bomb threats on election day in November 2025. Distinct methods of delivery suggest at leastthree independent operations, each targeting multiple polling places. This report draws on insights from conversations with analysts who spoke with election officials.
Why does it matter for elections?
Election day bomb threats are likely to persist. The wide range of targeted jurisdictions suggests all election offices are vulnerable and emphasizes the importance of training and planning:
Almost all targets were polling places in schools.
Disruption was minimal, with most sites remaining open or closing for 10 to 20 minutes. In a few cases, voting was promptly moved to a nearby existing polling site.
Election officials seem to have been well prepared.
In New Jersey, emails were sent directly to school staff before polls opened. According to localnewssources, multiple staff at each site received the email, a likely lesson learned from prior incidents when single-recipient emails went unanswered.
On the other hand, targeting a mix of NJ schools - some open, some closed on election day - may suggest a lack of local knowledge.
The NJ targets showed political patterning, including targeting small towns whose partisan history runs contrary to that of their county. This could suggest an effort to cloak partisanship, suggesting the actor had some political sophistication. Note that targeting is not proof of origin. Threat actors sometimes target their own side to generate sympathy or stir dissension.
In New York City, poll workers themselves received the emails between 6:00 and 9:30 AM, sent “through the Board of Elections email system,” according to multiplereports. Polling places in three neighborhoods were targeted.
In Upstate New York, threats against polling places were received by at least six county election offices, via email or the contact form on their website. Election administrators chose not to close polling places or notify the media. (Our knowledge of these incidents comes from private conversations.) These threats had almost no impact beyond unsettling people who were aware of them.
For details on bomb threat defense, assessment, and response, review the resources highlighted below in theResource Librarysection of this newsletter.
The Situation Room focuses on real security incidents and threats in the news relevant to election security. To review previous issues, see the newsletter archive.
Bomb Threat Mitigation
Bomb Threats and Hoaxes - Mitigating Election Disruptionis a step-by-step guide developed by the Committee for Safe and Secure Elections (CSSE) describing actions you can take to reduce the risk of disruption from bomb threats. It recommends integrating bomb threat scenarios into security training with election partners.
CISA’s Bomb Threats webpage provides an overview of how to plan for, assess, and respond to bomb threats against election facilities and polling places. In addition, links on that page lead to their Bomb Threat Guide, an in-depth planning resource, and a Bomb Threat Checklist to help you record details that may assist an investigation.
The Resource Library section of the newsletter spotlights election security resources. All highlighted resources are available online in the Resource Library.
Week E-35: Prevent exposure of the small details!
Seemingly insignificant details, such as a staff schedule visible in a photo posted online or a photo of the ballot storage room, can reveal vulnerabilities in your operations and create opportunities for a malicious actor to target your election infrastructure.
Operational security, or OPSEC, is a process of identifying and protecting sensitive information, data, and capabilities. This includes reducing unnecessary exposure of small pieces of information that, when combined, can reveal more than intended.
Set aside 30 minutes for an OPSEC check-in with your team. OPSEC is everyone’s responsibility, so consider including communications, IT, legal, and operations staff in the discussion. The following steps provide a simple framework to guide that review.
Step 1:Identify Sensitive Information
Purpose: Identify information that could be valuable to an adversary.
Examples: Staff roles and schedules; details of facilities and equipment, election procedures, security protocols, systems, and networks.
Step 2: Understand Threats
Purpose: Consider who might seek this information and how they might use it.