Emerald Icon
◆

Emerald Pages

◆
placeholder

Photo: Emerald Book Image

On October 2, 2026, FBI agents arrested three Black college students at the University of South Alabama for social media comments. Within 72 hours, the agency had tracked their posts, linked their accounts, and secured federal charges. The coordination was seamless, the response immediate. Fourteen months earlier, a 20-year-old man with a rifle climbed onto an unsecured rooftop 400 feet from a presidential podium in Butler, Pennsylvania, and fired eight shots.

The shooter had been flagged as suspicious 45 minutes before he pulled the trigger. Local law enforcement had spotted him, photographed him, and even tracked him flying a drone over the rally site. But because of fragmented radio systems and "siloed practice for sharing threat information" — as a Senate report later described it — that crucial intelligence never reached the Secret Service agents protecting the former president. The contrast is not just embarrassing. It is a searing indictment of how America's national security apparatus prioritizes risk, allocates resources, and fundamentally misunderstands what a "threat" actually looks like.

The South Alabama Case: What Actually Happened

The three students — Amare Jemal Woods, Cameron Lamark Lewis, and Kayla Leaann Smith — were arrested on federal charges of making "threatening communications" directed at President Donald Trump. The posts were entirely unrelated to one another. They didn't know each other. There was no coordination, no plan, no weapons, no conspiracy.

Woods allegedly commented "He gotta die bro" under a TikTok video announcing Trump's upcoming campus visit. Smith allegedly commented "We only got one chance, let's take it" alongside an image mimicking the holding of a firearm. Lewis allegedly made posts on X referencing political violence. None of them had a criminal record. None of them possessed weapons. None of them had a plan.

Defense attorney Jason Darley, representing Woods, pointed out that his 18-year-old client made a single off-hand remark on TikTok that took seconds to type. "The statute criminalizes a threat," he told reporters. "It doesn't have to actually be communicated to the President, but it does have to be taken by a reasonable person as a serious expression of intent to cause harm." The divide between "social media talk" and an actual criminal conspiracy, he argued, is massive and life-altering.

The Legal Machinery That Made Arrests Possible

Under federal law, the FBI does not need to prove a suspect had a weapon, a plan, or even the actual intent to carry out violence. Under 18 U.S.C. § 871, prosecutors only need to prove that a reasonable person reading the post — given the context of a major political rally happening on their own campus days later — would view it as a serious expression of an intent to cause harm.

The Supreme Court's 2023 decision in Counterman v. Colorado clarified that for an online statement to be prosecuted as a true threat, the speaker must act with reckless disregard for how their words will be perceived. Prosecutors don't have to prove the students intended to carry out the act. They only have to prove the students knew — or blindly disregarded — that their words would be taken as a serious threat of violence by a reasonable observer.

Context matters enormously. A comment like "he gotta die bro" posted on a random video months ago might be viewed as protected political rhetoric. But posting it directly under a video announcing a target's physical arrival at the user's specific campus changes the context entirely. Federal courts consistently rule that proximity and timing convert general speech into a localized, actionable threat.

  • Automated geofences and keyword trackers: When a presidential rally is announced, the FBI's National Threat Operations Center sets up digital dragnets over social media networks, flagging any post containing violent language paired with the name of the venue or city.
  • Real-time prioritization: Because the South Alabama students posted text and imagery tied directly to the campus visit, their accounts were immediately pushed to the top of the pile for rapid intervention.
  • No capability required: Federal law punishes the communication of the threat itself, regardless of whether the person owned a firearm, had money, or possessed a tactical plan.

The Butler Failure: What Went Wrong

While the FBI was busy tracking down college students for reckless TikTok comments, a 20-year-old man with a rifle walked onto an unsecured rooftop less than 400 feet from a presidential podium. He had been flagged as suspicious 45 minutes before the shooting. Local law enforcement had spotted him acting strangely, photographed him, and tracked him flying a drone over the rally site.

But the Secret Service never received that intelligence. A scathing Senate report released in September 2024 detailed the failures: the warehouse building — the exact roof the shooter used — was not included inside the secure event perimeter. Highly critical information was never communicated to the agents surrounding Trump due to "siloed practice for sharing threat information." The shooter had no public social media blueprint. He didn't post "he gotta die bro" on TikTok. He prepared in the physical world — researching previous assassinations, practicing at a firing range, buying components under a pseudonym.

Because he did not trigger the automated public keyword filters, he remained entirely invisible to mass digital surveillance. The system that caught three college students in 72 hours could not catch a lone gunman who had been flagged in person 45 minutes before he opened fire.

The Inversion of Risk

This reveals a fundamental flaw in how risk is prioritized. The system is optimized to catch the most visible, loud, and uncoordinated individuals because they are the easiest to track using automated algorithms. Meanwhile, it remains highly vulnerable to quiet, determined, or localized physical failures.

The vast majority of people flagged by automated keyword sweeps are engaging in reckless political venting, dark humor, or online bravado. They are completely disorganized, unarmed, and often shocked when federal agents show up at their door. Because algorithms look for words rather than intent, these systems generate an immense amount of "noise." Security agencies spend millions of dollars tracking down teenagers, trolls, and internet contrarians who pose zero actual physical risk.

This creates a paradox where law enforcement resources are diverted to investigate low-risk individuals simply because their public posts triggered a keyword filter. Meanwhile, individuals who have the genuine capability, resources, and intent to carry out real-world political violence do not advertise their specific plans on mainstream public timelines. They operate in the shadows — using encrypted channels, closed forums, or simply keeping their intentions entirely to themselves until the moment of an attack.

What the System Misses

When a genuine, serious attack or operational plot is actually stopped by federal authorities, it is almost never because a computer program flagged a public tweet. It happens because of deep, long-term human intelligence, insider tips, or direct infiltration.

In June 2026, the FBI announced it thwarted a plot to use drones and snipers to attack a White House UFC event. The case broke open because a suspect's mother noticed him buying tactical gear and interacting with dangerous people online, prompting her to call local police. The FBI thwarted an attack on the Mall of America by an 18-year-old — not through a casual public post, but because undercover agents and confidential informants had been tracking and directly messaging him for nearly two years, eventually arresting him during a sting operation.

These operations required patience, human judgment, and long-term infiltration. They did not rely on automated dragnets. They relied on the kind of deep intelligence work that no algorithm can replicate — and that no keyword filter can replace.

The Embarrassing Contrast

Federal agencies have the advanced technology to track down an 18-year-old college student over a single, off-hand TikTok comment within hours, yet they suffered a historic failure because of basic mistakes like leaving a rooftop unmonitored and failing to share radio communications.

This exact disconnect is what led to the resignation of the Secret Service Director shortly after the Butler incident and forced a massive, ongoing overhaul of how political events are secured. It proved that relying on high-tech digital surveillance cannot replace fundamental, real-world competence. It shows just how fractured the system can be when it focuses its immense power on the wrong targets.

The students at the University of South Alabama were released from custody on Monday, October 5, under strict conditions — including travel restrictions, no contact with one another, and a total social media ban. They await grand jury review. Their lives have been altered forever by a few seconds of typing. Meanwhile, the shooter in Butler is dead, the Secret Service Director has resigned, and the agency that spent millions on social media surveillance still cannot explain how a 20-year-old with a rifle walked onto an unsecured roof less than 400 feet from a presidential podium.

No Ads. By Us. For Us.

This article was made possible by readers like you. We hope it inspired you to support Emerald Book, so we can continue producing content like this.

We will never show you ads, sell your data, or require a subscription to consume our content. Your gift helps us keep the truth accessible.

Click the Support button to give a gift of any amount today.

Thank you for making this work possible.

◆

Emerald Pages is a publication of
Emerald Book, Inc.

Follow us
Share
Scroll to Top