Doxbin Admin Jailed for Encouraging Swatting

The Register Security · Medium sophistication
Last updated July 30, 2026

A Welsh Doxbin administrator, Callum Dare, was jailed after investigators linked him to encouraging and assisting others to place dangerous “swatting” hoax calls in the UK, US, and Canada. The hoaxes included false reports of bombs, hostages, shootings, and explosives, designed to trigger armed police responses and public evacuations.

How the attack worked

A Welsh Doxbin administrator, Callum Dare, was jailed for encouraging and assisting others to carry out swatting hoax calls in the UK, US, and Canada. Dare did not make the calls himself. Instead, he used Doxbin's "#deadnet" channel to motivate others and shared montage videos of police responses to encourage further attacks. The hoax calls themselves used extreme pretexts, including bomb threats, nail bombs, hostage situations, and claims of being armed with explosives, all designed to force an immediate, large-scale emergency response.

Why it succeeded

Each hoax call relied on urgency and violence to bypass normal verification. A caller with a fake Russian accent told the Los Angeles Police Department that bombs were placed under chairs in a University of California lecture theater, causing an evacuation. Another caller told a Western Mail journalist he was armed with nail bombs and holding hostages at a named Cardiff hotel, which led police to close off and evacuate the street. In a third case, a caller claimed to be at a private address, having shot a victim and taken hostages while armed with explosives. In all three cases, the recipient had no practical way to verify the caller's identity or confirm the threat before responding.

What to watch for

  • Callers who use extreme, violent claims (bombs, hostages, shootings) specifically to force fast action and prevent normal checks
  • Use of accents, invented identities, or claimed on-scene presence to sound more credible
  • Specific, verifiable-sounding location details (named buildings, hotels, addresses) used to maximize disruption
  • No callback number or way to confirm the caller's identity beyond the threat itself

How to build resistance

Organizations that could plausibly receive one of these calls, including university administration, campus security, newsrooms, corporate communications, and hospitality front desks, benefit from a written playbook for handling bomb, hostage, or shooting claims. This should define who takes the call, what details to record (exact wording, caller number, claimed location), and how to escalate to police without amplifying unverified information further than necessary.

Because swatting depends on knowing where to aim a false threat, reducing the amount of personally identifiable information, especially home addresses, posted publicly about staff and executives lowers the chance that a swatting call can be targeted at a real person's location. Doxbin itself is described as a platform used to expose personal information specifically to enable harassment and swatting, underscoring why limiting exposed PII matters as a defensive measure alongside call-handling training.

Key findings

  • Callum Dare, a Doxbin administrator, was convicted for encouraging/assisting others to carry out swatting hoax calls across the UK, US, and Canada.
  • Swatting pretexts included bomb threats, nail bombs, hostage situations, shootings, and claims of being armed with explosives, intended to trigger police and emergency responses.
  • Dare did not personally make the swatting calls, but investigators said he encouraged and assisted others via Doxbin’s “#deadnet” channel and shared montage videos of responses to motivate further attacks.
  • Investigators also found Dare possessed a phishing kit (“The Man in the Onion”), but the article states there is no suggestion it was used in real-world attacks.

Who’s being targeted

  • Commonly targeted roles: Front Desk / Reception, Security / Corporate Security, Executive Assistants, Corporate Communications / PR, Newsroom / Media staff, University administration / campus operations, HR (for employee privacy/doxxing hygiene).
  • Affected industries: Education (universities), Media/Journalism, Hospitality (hotels), Public sector / Emergency services, Individuals (private citizens).
  • Attack channels: vishing.
  • Impersonated: Unknown caller (using a fake accent to sound credible/foreign), Armed hostage-taker (false claim), Person at the victim’s address (false claim of being on-scene).

Red flags to watch for

  • Caller uses an accent/identity cue to manipulate urgency and credibility
  • High-pressure claim involving bombs intended to force immediate action
  • No verifiable callback information or confirmable details beyond the threat
  • Extreme threat designed to bypass normal verification steps
  • Specific public location named to maximize disruption
  • Unverifiable identity of caller combined with urgency and violence
  • Caller claims to be at an address that may belong to a targeted third party
  • Over-the-top violence details used to force immediate escalation
  • No ability for the recipient to validate the caller’s identity or location
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is swatting and how does it relate to social engineering?

Swatting is a hoax emergency call, such as a false bomb or hostage threat, designed to trigger an armed police response to a target's location. It relies on the same pressure and urgency tactics used in vishing attacks to bypass normal verification.

Who was Callum Dare and what was he convicted of?

Callum Dare was a Doxbin administrator convicted for encouraging and assisting others to carry out swatting hoax calls across the UK, US, and Canada, though he did not personally make the calls.

How did the swatting calls actually work?

Callers used pretexts like bomb threats, hostage situations, and claims of being armed with explosives, sometimes disguising their accent, to pressure police and organizations into immediate evacuation or armed response.

What can organizations do to prepare for swatting-style calls?

Build a written verification and escalation playbook for bomb, hostage, or shooting claims, train front-line staff to capture caller details without prolonged engagement, and reduce public exposure of employee addresses that could be used to aim an attack.

Read the video transcript

Imagine you pick up the phone and hear: “There are bombs under the chairs at a University of California lecture.” What do you do next? A Doxbin admin, Callum Dare, was jailed for encouraging swatting, fake bomb, hostage, and shooting calls, like a hoax nail‑bomb hostage threat at Cardiff’s Sandringham Hotel that shut down St Mary Street. Swatting calls use accents, extreme threats, and specific locations to force instant action: “I’m armed with nail bombs and holding hostages at Cardiff’s Sandringham Hotel on St Mary Street.” That’s social engineering by phone. Your move: if you ever get a bomb, hostage, or shooting call, follow our emergency call playbook on the intranet, capture exact words and location, then hand it straight to security or 999, nothing else.

MITRE ATT&CK techniques

Similar attacks

How Attackers Bypass MFA in the Real World

How Attackers Bypass MFA in the Real World

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay…

July 29, 2026
TikTok Resin Art “DM to Order” Scam

TikTok Resin Art “DM to Order” Scam

Scammers on TikTok are impersonating resin artists by reposting stolen videos and telling viewers to “DM to order.” After moving the conversation into direct…

July 24, 2026
FaceTime Spoof Calls Steal Codes and Money

FaceTime Spoof Calls Steal Codes and Money

Apple warns that scammers are using FaceTime calls, often with spoofed caller ID, to impersonate Apple or banks and pressure people into sharing passwords,…

July 17, 2026