top of page

Before the Threat Is Spoken: Recognizing Emotional Leakage and Seepage in the Workplace

2 hours ago
7 min read
Business people at a table in a meeting room, one man standing with arms crossed.

At Incident Management Team (IMT), we spend our days helping organizations build the kind of behavioral threat management programs that catch trouble before it becomes tragedy. One of the most important lessons we teach our clients is this: violence is rarely announced. People moving toward a violent act do not usually walk up and say, "I'm going to hurt someone." Instead, their intent, grievance, or growing fixation tends to surface in smaller, easier-to-miss ways — a joke, a comment, a change in behavior that makes a coworker uneasy.


Behavioral threat assessment researchers have two terms for this: leakage and seepage. We build these concepts into every training program and policy we write, because organizations that understand them catch far more warning signs than organizations waiting for a direct threat.


The absence of a direct threat does not mean the absence of risk.

What We Mean by "Leakage"

Leakage happens when a person — intentionally or not — communicates thoughts, fantasies, attitudes, or intentions connected to violence to someone other than the intended target. Forensic psychologist Reid Meloy, whose research helped formalize the concept for the threat assessment field, describes leakage as communication of harmful intent that can travel through letters, journals, blog posts, videos, emails, voicemails, or conversation, and notes that it shows up in the majority of studied cases of attacks on public figures, mass murders, and school shootings because it typically signals a preoccupation with the target and may reflect research, planning, or rehearsal for an attack.


In our client trainings, we walk through examples like:

  • Jokes about harming a supervisor, coworker, or the organization

  • Statements that someone will "get what's coming to them"

  • Comments about making others "pay"

  • Increasingly violent or retaliatory language

  • Repeated references to weapons or past acts of targeted violence

  • Expressions of admiration for people who have carried out attacks

  • Statements suggesting violence is the only remaining solution

  • Messages implying farewell, finality, hopelessness, or revenge

  • Comments identifying with previous attackers

  • Sharing violent plans, images, writing, or fantasies with others


We're careful to tell clients that leakage is not a confession. Sometimes it's a test of how the audience reacts. Sometimes it's a bid for attention, a way to communicate distress, or an attempt to pull others into a grievance. The FBI has made a similar point in its own guidance for the private sector, noting that the behaviors associated with a person's movement toward targeted violence are often observable to others, and that a concern can only be assessed and managed once it actually reaches a team trained to evaluate it.


What We Mean by "Seepage"

If leakage is what comes out through what a person says, seepage is what starts to show through what a person does. Someone may insist that everything is fine while their behavior tells a different story — resentment, agitation, or fixation that becomes harder and harder to contain.


We coach supervisors and HR teams to watch for patterns like:

  • Noticeable agitation whenever a particular person or grievance comes up

  • Intense staring, glaring, posturing, or attempts to intimidate

  • Repeatedly showing up near the person who is the focus of a grievance

  • Withdrawal combined with resentment or hostility

  • Abrupt changes in how someone interacts with coworkers or presents themselves

  • Anger that seems disproportionate to the situation

  • Difficulty letting go of a perceived injustice

  • Repeated boundary violations

  • Rehearsal-like behavior, such as acting out a confrontation

  • Unusual monitoring of a person's office, entrance, schedule, or routine

  • A sudden shift from visible agitation to an oddly calm or "resolved" demeanor

  • Behavior coworkers describe as simply "not like them"


One thing we emphasize repeatedly in training: seepage is not about trying to read body language or catch someone in a lie. There is no single expression, posture, or mannerism that reliably signals violent intent. The value is in the pattern — what's changed, what it's connected to, and what else is happening around it — not in any one moment.


Why We Tell Clients "A Joke Is Not Always Just a Joke"

Humor gives people a socially acceptable way to say something they aren't ready to say directly. Someone might laugh right after a violent statement, or add, "I'm only joking." Often, that's exactly what's happening — dark humor is common and usually harmless.

But in our assessments, we teach teams not to let humor automatically close the inquiry, especially when a statement is:

  • Specific

  • Repeated

  • Directed at an identifiable person

  • Connected to an ongoing grievance

  • Becoming more detailed or graphic

  • Paired with other concerning behavior

  • Followed by efforts to gain information, access, or weapons

Our advice is never to assume that every inappropriate joke predicts violence — it's to preserve the information and route it to people trained to evaluate it in context.


We Train Teams to Look for a Pattern, Not a Single "Red Flag"

Threat assessment isn't a checklist exercise, and we don't run our client programs like one. A single odd comment or one tense interaction rarely tells the whole story on its own.


Here's a scenario we use in training: An employee is going through a disciplinary process. One coworker overhears him joke that his supervisor should "watch his back." Another notices him sitting in the parking lot after hours. The front desk fields repeated questions about the supervisor's schedule. HR already knows he's become fixated on the belief that management is deliberately ruining his life.


Individually, each of those observations is explainable. Together, they may point to an escalating grievance, boundary-testing, or movement toward something more serious. That's exactly why we push organizations to build formal reporting structures — no single coworker, manager, or security officer usually has the whole picture on their own.


Making a Threat vs. Posing a Threat

This distinction sits at the center of everything we do. Some people make threatening statements impulsively, with no plan or continuing intent to act. Others move toward violence without ever saying a threatening word out loud.


A proper threat assessment doesn't just ask whether threatening words were spoken — it asks whether someone may pose a threat, based on the full picture. When we assess a case for a client, we're working through questions like:

  • Is there an identifiable grievance or target?

  • Is the person increasingly fixated on that grievance?

  • Has their language or behavior escalated?

  • Have they discussed violent solutions?

  • Are they gathering information about a person or location?

  • Have they engaged in planning, preparation, rehearsal, or surveillance?

  • Do they have the means or access to carry out violence?

  • Have relationships, coping mechanisms, or other stabilizing factors broken down?

  • Are there protective factors or interventions available that could reduce the concern?


This framework mirrors what federal researchers have found in studying real attacks. The FBI's analysis of active shooter pre-attack behavior found that most active shooters engaged in behaviors prior to their attacks that were observable to others, and the Bureau's broader guidance for the private sector stresses that these behaviors create real opportunities for intervention — but only when someone reports them. Similarly, the U.S. Secret Service's National Threat Assessment Center, which has spent decades studying attacks directed at government officials, workplaces, schools, and other public spaces to identify individuals exhibiting threatening or concerning behavior, has consistently found that mass attacks are preventable when communities know how to recognize warning signs and act on them.


What We Tell Employees to Report

We don't ask employees to decide whether someone is dangerous — that's not their job, and it's not a fair thing to ask of them. We do teach them to report what they actually observed.

A useful report includes:

  • What the person said or did

  • When and where it happened

  • Who else was present

  • Whether it's happened before

  • Whether a specific person or location was named

  • What seemed to trigger it

  • Whether the behavior has changed or escalated

  • Any supporting messages, emails, posts, photos, or documents

  • Why it stood out to the person reporting it


"He's dangerous" is a conclusion, not a report. In our training, we push people toward something more like:

"During lunch on Tuesday, he said our supervisor would be sorry for humiliating him. He made a hand gesture resembling a gun and said Thursday's meeting might be her last. Two other employees heard it. He's made similar comments three times this month."

That level of detail is what actually lets a threat management team do its job.


What We Help Organizations Do With That Information

A report of leakage or seepage should never automatically trigger termination, punishment, or a call to law enforcement on its own. We've seen overly aggressive reactions backfire — they discourage future reporting and can even intensify the grievance driving the behavior in the first place.


Instead, we help clients build a structured process to:

  1. Receive the report without dismissing or overreacting to it

  2. Gather information from available, lawful sources

  3. Assess the behavior in context — pattern and trajectory, not a single incident

  4. Develop a management strategy suited to the specific situation

  5. Monitor and reassess as circumstances change


Depending on what's involved, that response might bring in management, HR, security, legal counsel, mental health resources, or law enforcement. The Secret Service's own guidance for building threat assessment programs recommends this kind of scalable, cross-functional approach — the same model we help our clients put in place, right down to designating a specific point of contact for concerning reports. If a situation suggests immediate danger, our guidance is always the same: contact emergency services and follow established emergency procedures without delay.


Why This Work Matters

Workplace violence prevention can't depend on waiting for someone to announce their intentions. In our experience, the earliest opportunity to intervene almost always shows up in fragments — a disturbing joke, a retaliatory comment, an escalating grievance, a change in behavior that no single person fully understands on their own.


Leakage tells us something about what a person may be communicating. Seepage tells us something about what may be emerging through behavior. Neither proves violent intent, and neither should ever be judged in isolation. Their real value is in prompting the right next step: report it, gather the facts, assess the pattern, and decide whether intervention is needed.


That's the program we build for every client — not one where employees are asked to predict violence, but one where they know how to recognize when something is worth sharing, and where that information reliably reaches people trained to act on it before a concerning situation becomes a crisis.


References

  1. Meloy, J. R. (2011). The Concept of Leakage in Threat Assessment. Behavioral Sciences & the Law. https://drreidmeloy.com/wp-content/uploads/2015/12/2011_theconceptofleakage.pdf

  2. Federal Bureau of Investigation. A Study of the Pre-Attack Behaviors of Active Shooters in the United States, 2000–2013. https://www.fbi.gov/file-repository/pre-attack-behaviors-of-active-shooters-in-us-2000-2013.pdf

  3. Federal Bureau of Investigation. Making Prevention a Reality: Identifying, Assessing, and Managing the Threat of Targeted Attacks. https://www.fbi.gov/file-repository/making-prevention-a-reality.pdf

  4. U.S. Secret Service, National Threat Assessment Center. Behavioral Threat Assessment Units: A Guide for State and Local Law Enforcement to Prevent Targeted Violence (2024). https://www.secretservice.gov/sites/default/files/reports/2024-10/Behavioral-Threat-Assessment-Units-A-Guide-for-State-and-Local-Law-Enforcement-to-Prevent-Targeted-Violence.pdf

  5. U.S. Secret Service, National Threat Assessment Center. Mass Attacks in Public Spaces: 2016–2020. https://www.secretservice.gov/newsroom/releases/2023/01/new-secret-service-research-examines-first-time-five-years-mass-violence

  6. U.S. Secret Service, National Threat Assessment Center overview and report archive. https://www.secretservice.gov/protection/ntac

This article is for general informational and training purposes and is not a substitute for a formal threat assessment conducted by qualified professionals.

 

bottom of page