Skip to content

Using OSINT To Understand Indicators of Potential Workplace Violence

Liferaft |    September 02, 2026

Office team collaborating at night with a cracked glass overlay, symbolizing workplace violence risk and the need for proactive prevention and safety planning

When the FBI's Behavioral Analysis Unit studied 63 active shooter cases from 2000 to 2013, it found that each attacker had displayed an average of 4.7 concerning behaviors that were observable to the people around them. Someone noticed something in nearly every case. The same study found that in cases where leakage occurred, meaning the attacker communicated intent to a third party, none of the observed instances were reported to law enforcement.

Noticing is rarely where corporate security programs break down. Somebody usually notices. The difficulty comes after that, in whether the observation gets reported at all, who receives it, and whether that person can see it alongside other concerns raised about the same individual over the past two years.

This post covers the behavioral indicators that matter, the ones that get overlooked because they sit outside the employee population, and how open-source intelligence fits into a threat assessment process that can do something useful with them.

 

The Different Types of Workplace Violence

The typology developed by NIOSH and used widely across corporate security divides workplace violence into four categories. Each one produces a different set of indicators, which is why programs built around only one category tend to miss the others.

Type I: Criminal Intent

The perpetrator has no legitimate relationship to the business and is there to commit a crime, most often robbery. Indicators here are environmental and geographic rather than behavioral. Site vulnerability, cash handling, hours of operation, and local crime patterns drive the risk picture.

Type II: Customer or Client

The perpetrator is a customer, patient, client, student, or inmate. This category accounts for the largest share of nonfatal workplace violence, and it is heavily concentrated in healthcare, education, retail, and public-facing service roles. Indicators often appear in complaint records, service interactions, and public posts directed at a specific location or staff member.

Type III: Worker on Worker.

The perpetrator is a current or former employee. This is the category most people picture when they hear the term, and it is the one with the richest behavioral indicator set because the organization has months or years of observational history.

Type IV: Personal Relationship.

The perpetrator has a relationship with an employee rather than with the organization, most commonly an intimate partner. Domestic violence follows people to work because work is the one place a target can be reliably located at a predictable time.

 

Essentially then, a program that only watches its own workforce is covering one of these four. Type II and Type IV threats arrive from outside the badge system entirely.

 

 

Top Indicators of Potential Workplace Violence

There is no profile of a violent employee, and the FBI study is explicit on this point. What exists instead is a set of behaviors that warrant assessment when they cluster and escalate. Any single item on the list below appears in plenty of people who will never harm anyone. The pattern is what carries the signal.

A grievance with a specific target

In the FBI sample, 79% of attackers appeared to be acting on some grievance. For 16%, that grievance stemmed from an adverse employment action. A grievance becomes a security concern when it stops being general frustration and acquires a name, a title, or a location.

Leakage

Leakage was observed in 56% of cases. It includes direct threats, but more often it looks like something else: a comment that a specific manager will 'get what is coming,' a social post about how a former employer will regret a decision, or a joke about an unusually detailed scenario. Leakage is the single most actionable indicator because it is intentional communication.

Escalation in interpersonal conflict

Problematic interpersonal interactions appeared in 57% of cases. Look for a change in trajectory rather than a snapshot. Conflicts that used to be resolved now recur, involve more people, and shift from disagreement to a grievance narrative.

Deterioration paired with externalized blame.

Declining work performance showed up in 46% of cases. Performance decline on its own is a management issue. Performance decline combined with a belief that the decline was caused by a hostile colleague or unfair supervisor is a different signal.

Fixation and target research

A person who begins gathering information about a specific individual, learning their schedule, their vehicle, or their home area, has moved from grievance to planning. In the FBI sample, 77% of attackers spent a week or longer planning.

Changes in relationship to weapons

Lawful ownership is not an indicator. New acquisition, a shift in how weapons are discussed, or the appearance of weapons in content directed at a grievance target is a change worth documenting.

Boundary and policy testing

 Repeated policy violations, refusal to accept supervision, and probing of access controls or after-hours entry all indicate someone testing what the organization will tolerate.

 

Other Indicators That Are Typically Overlooked

Most indicator lists are written for HR, which means they cover current employees and stop there. Security teams also have to account for people who never appeared on the payroll, or who left it years ago.

The former employee timeline

A grievance can outlast the job by years. Someone who felt their termination was unfair may still be carrying it long after the exit interview, and the day their badge gets deactivated is the day the company stops hearing about them. Managers no longer see them, and HR no longer takes reports. From that point, the only thing anyone can observe is what the person chooses to post publicly.

Third-party escalation

Customers, patients, tenants, litigants, and unsuccessful job candidates all generate grievances against organizations. These signals tend to sit in customer service logs, legal correspondence, and public review platforms, where security teams rarely look.

Domestic violence spillover.

The observable indicators usually come from the victim. You may see: an employee requesting a parking reassignment, unexpected visits to the lobby, a protective order that names the worksite. Cal/OSHA's plan requirements and most duty of care frameworks treat this as within scope.

Coworker avoidance behavior.

Increased absenteeism on a specific team, requests to transfer away from one individual, or reluctance to be scheduled alone with someone often precede any formal complaint. People adjust their behavior around a perceived threat before they report it.

The case that closed with no follow-up.

A concern that was investigated, deemed unsubstantiated, and closed is not the same as a concern that resolved. Without a scheduled review, the file becomes invisible while the underlying grievance continues.

Indicators split across departments

The performance write-up sits with HR. The demand letter from the terminated employee sits with legal, the odd after-hours badge activity with IT, and the parking lot argument with facilities. Nobody holding one of those pieces has much reason to call security about it on its own. They only mean something next to each other, and that is hard to arrange when they live in four separate systems.

Building Data With OSINT to Find Workplace Violence Triggers

Open-source intelligence contributes to workplace violence prevention by covering observation gaps that internal systems cannot reach, including, but not limited to, former employees, non-employee actors, and public expressions of grievance that have not yet been reported internally.

Effective collection begins with defined requirements rather than broad monitoring. A workable set of collection requirements for a workplace violence program includes:

  • Entities to watch. Facility addresses and informal site names, subsidiary and legacy brand names, the names of publicly visible leaders and site managers, and specific individuals tied to an open, documented case.
  • Language and behavior of concern. Grievance framing aimed at the organization, threat and violent-intent language, references to specific locations or people, and content indicating capability or preparation.
  • Sources that matter. Mainstream social platforms cover part of the picture. Grievance content frequently surfaces first on fringe forums, alternative platforms, review sites, and paste sites, which is why deep and dark web coverage belongs in the source list alongside mainstream monitoring.
  • Scope boundaries. This is the part that determines whether a program survives legal review. Collection should be limited to information the subject has already made public, tied to an articulated security concern, and documented with a rationale for its initiation. Persistent monitoring of employees without a specific, recorded concern is a different activity and should not be confused with threat intelligence work.

Requirements like these work best when written down and reviewed quarterly with HR, legal, and privacy teams. Documented scope is also what allows a program to answer the inevitable question about what it collects and why.

How to Use OSINT Data to Your Advantage

Most of the difficulty comes after the alert lands, in the days between finding something and deciding what to do about it.

Corroborate before escalating

An anonymous post that names one of your buildings is a lead and not much else. Somebody has to establish that the account belongs to a real person with a real connection to the organization before it goes any further. Identity resolution matters at this stage because escalating on a misidentified account can cost the wrong person their job.

Assess against a structured method.

Validated instruments such as WAVR-21 give a threat management team a common language and a defensible record. Structured assessment also protects against the two failure modes analysts know well, which are dismissing a credible concern because the person seems unremarkable, and overreacting to crude language from someone with no capability or intent.

Route to a standing team

A single analyst should not carry an assessment decision. Multidisciplinary threat management teams that include security, HR, legal, and counsel are the accepted model precisely because these cases require judgment from several disciplines at once.

Keep one record

Everything gathered on a case belongs in one file with a documented rationale, a decision log, and a scheduled review date. A case manager who holds the full timeline is what allows the next analyst to pick up a two-year-old concern and understand where it sat when it was last reviewed.

Feed findings back into collection

A closed case usually reveals which sources produced value and which produced noise. That knowledge should update the collection requirements.

Stopping Workplace Violence Early is Key

The runway is longer than most people assume. In the FBI study, the first observable concerning behavior occurred at least three months before the attack in roughly 90% of cases, and at least two years before in more than half. Attackers move through a process of grievance, ideation, planning, preparation, and action, and that process leaves observable traces at multiple points.

Intervention early in that sequence also has more options available to it. A grievance that surfaces at the ideation stage can sometimes be addressed through mediation, an EAP referral, a schedule change, or a documented conversation. Once someone has begun preparation, the available responses narrow to protective measures and law enforcement referral. BLS Census of Fatal Occupational Injuries data recorded 470 workplace homicides in 2024, with the majority involving a firearm, which is a reminder of how little margin the late stages leave.

Early intervention also produces better outcomes for the person of concern. The majority of these cases resolve without termination or arrest when someone notices and engages while the situation is still workable.

Building A Workplace Violence Prevention Program

Indicators are only useful inside a program that can receive, assess, and act on them. The components that consistently distinguish mature programs:

  1. A written plan. California's SB 553 has required most employers in the state to maintain a written workplace violence prevention plan since July 2024, and Cal/OSHA's general industry standard is due for adoption by the end of 2026. Organizations without a California footprint are still exposed under OSHA's general duty clause and through negligent retention claims.
  2. A standing threat management team. Named members, defined authority, a regular meeting cadence, and the ability to convene quickly.
  3. One intake channel that people trust. The FBI finding that observed leakage went unreported points to a reporting problem more than an observation problem. Anonymous options, clear anti-retaliation protection, and visible follow-through are what move the reporting rate.
  4. Manager training on escalation rather than diagnosis. Managers should not be asked to assess dangerousness. They should be able to recognize a change in trajectory and know exactly where to send it.
  5. Integrated internal and external visibility. Behavioral observations from HR and managers combined with threat monitoring of public sources gives the assessment team a fuller picture than either input provides alone.
  6. Documented intervention options short of termination. Teams that only have separation available tend to delay action until a case is severe, and separation itself can be a triggering event that requires its own risk planning.
  7. Case review and after-action discipline. Scheduled reviews of open and closed cases, plus honest after-action work on incidents and near misses, are what turn a policy document into a functioning capability.

The behaviors described throughout this post were visible in nearly every case the FBI examined. Building the connective tissue that lets an organization see them together, assess them consistently, and act on them early is the work that prevention actually consists of.

 

Frequently Asked Questions

 

How does Liferaft help organizations prevent workplace violence?

Liferaft gives security intelligence teams visibility into publicly available information that relates to a defined security concern. Teams use it to listen for grievance and threat language tied to their facilities, brands, and named personnel, to search deep and dark web sources where grievance content often surfaces first, to resolve online personas to real-world individuals during an investigation, and to keep the full timeline of a case in one record that a threat management team can work from. It supplements internal behavioral observation rather than replacing it, and it provides no covert access to private accounts, messages, devices, or location data.

What is OSINT data?

Open-source intelligence is information collected from publicly available sources and then analyzed to answer a specific question. In a corporate security context that includes social media, forums, news, public records, court filings, review platforms, and deep and dark web sources. The intelligence part is the analysis: raw public data becomes OSINT once it has been corroborated, assessed, and connected to a security requirement.

What else can I do with OSINT?

Corporate security teams apply the same collection and analysis discipline to executive protection, travel risk and duty of care, event and site security, brand and impersonation monitoring, insider risk, exposed credential detection, and geopolitical situational awareness. Most programs find that requirements built for one use case support several others.

Is workplace violence preventable?

Individual acts of violence cannot be predicted, and no reputable practitioner claims otherwise. Prevention is nonetheless achievable at the program level, because the pathway to violence unfolds over time and produces observable behavior along the way. Organizations that can collect those observations, assess them consistently, and intervene early do interrupt cases. The evidence base for threat assessment as a discipline rests on exactly that.