In early September 2026, the U.S. Secret Service confirmed that it was aware of a video broadcast by Iranian state television discussing a potential plot to assassinate Barron Trump, the 20-year-old son of President Trump. The broadcast reportedly claimed that Barron was being monitored and alleged that a $10 million bounty had been offered for his killing. While these circumstances are extraordinary, the broader security lesson is not.

In previous installments of Staying Ahead of Hate, I’ve discussed the evolution of grievance – and particularly the point at which disagreement with a decision, a policy, an institution or an individual becomes personalized. I’ve also discussed the importance of recognizing when that grievance progresses toward fixation, leakage, planning, or mobilization. 

But another dimension of this progression deserves greater attention. What happens when the target itself begins to expand? 

A grievance may originate with one individual: a president, a judge, a corporate executive, or other decision-maker. But the resulting threat does not necessarily remain confined to that person or initial target. It can extend to a spouse or child, migrate to colleagues or employees, and sometimes the organization itself – along with the people and places associated with it – becomes the target. 

When the Family Becomes the Target 

The recent threat reportedly directed toward Barron Trump is a particularly stark example. Whatever the geopolitical motivations behind the Iranian broadcast, Barron Trump did not make the decisions underlying Iran’s grievance with the United States or with his father. His relevance to the threat appears to come principally from his relationship to the President. And unfortunately, history provides many other examples of this. 

In 2020, an attorney who had previously appeared before U.S. District Judge Esther Salas arrived at her New Jersey home posing as a delivery driver. Judge Salas’ 20-year-old son, Daniel Anderl, answered the door and was killed, and her husband was seriously wounded. 

But attacks in the judicial space extend well beyond one judge. A 2025 Reuters investigation identified at least 11 federal judges whose family members had been subjected to threats, doxxing, or harassment following controversial rulings. 

The implied message is not hard to understand; we know where you live, and we know where your family lives. 

When the Organization Becomes the Target 

The July 2025 attack at 345 Park Avenue in Manhattan expands this concept further. Authorities concluded that the gunman who entered the building appeared to have been targeting the National Football League, whose headquarters are located there. Investigators found a note in which he blamed the NFL for allegedly concealing the dangers of football-related brain injuries. 

He apparently intended to reach the NFL’s offices but took the wrong elevator bank. Four people were killed, and an NFL employee was seriously wounded. 

The individuals who died were not responsible for the grievance articulated by the attacker, and some did not even work for the NFL. They simply occupied a physical space that had become associated with the institution he blamed. 

The key factor here is that sometimes the target isn’t a person at all; it’s an organization. And once an organization becomes the object of a grievance, virtually anyone visibly associated with it can potentially become part of the exposure, including executives, employees, contractors, security personnel, visitors, or simply people who happen to occupy the same building. 

From the Protectee to the Ecosystem 

Protective operations understandably tend to organize around a protectee, focusing on who may be threatening a CEO, a judge, or an elected official. And while that focus remains essential, today’s threat environment requires us to look outward as well and ask: what other people, places, and organizations may have become connected to the grievance? 

As a retired Secret Service agent, I know first-hand that this concept is not new. The Secret Service has long understood that a threat environment that encompasses a President or another protectee can extend to family members as well, and protective operations have necessarily taken that wider exposure into account. 

What has changed, I believe, is the environment in which all of us now operate. The ability to identify family members, associates, workplaces, and locations has become dramatically easier, and grievance itself can spread quickly from an individual to the people and institutions associated with them. 

What was once principally a consideration for organizations like the Secret Service now needs to become part of how security professional’s writ large think about protection. 

Importantly, when we think of the potential target as not a single point, but as a wider ecosystem, then we can begin to see the implications for a spouse or child, colleagues and employees, offices and residences, and other places associated with the original target. 

And in our increasingly connected world, family relationships can be identified, and residences can be located. Photographs can reveal schools, places of worship, vehicles, and routines. Professional networks can identify colleagues and associates, corporate websites can identify executives and office locations, and social media can expose travel, events and patterns of life. 

Protective Intelligence Must Expand with the Target 

Thankfully, most people who experience grievances never threaten or commit violence, but when concerning behavior does surface, security professionals should look closely at what may have changed in the progression of that behavior. 

For example, has the online rhetoric changed from, “I hate what this CEO did,” to “This company needs to pay”? Has a subject begun naming specific employees or family members? Has someone begun researching a headquarters location, an event venue, hotel or school? 

None of these things by themselves means that violence will occur. But taken together with other concerning behavior, they can indicate that the protective intelligence picture has changed – and potentially that the grievance is moving toward planning or mobilization. 

And importantly, the change may not only be in behavior; the target itself may be changing. 

Protecting the Ecosystem 

All of this has practical implications for both public and private sector security organizations. Protective intelligence can’t exist in isolation from the many disciplines that comprise a comprehensive security program, including executive protection, workplace violence prevention, physical security and cybersecurity, to name a few. 

A concerning signal within any one of these disciplines may mean relatively little. But connected over time with information from the others, it may tell a very different story. The objective is not simply to identify threats, but to understand relationships, context and progression. 

Technology can assist in this regard, not by attempting to predict who will become violent, but by allowing security teams to connect information that might otherwise remain separate across multiple systems, departments and jurisdictions. 

The Expanding Target 

The threat reportedly directed toward Barron Trump is a timely reminder of something protective professionals have understood for generations: proximity to a consequential person can itself create risk. But today’s environment extends that concept considerably further. 

Family members can become proxies for public officials; employees can become proxies for executives; facilities can become proxies for organizations, and so on  

This means that the protective question can no longer be limited to, “Who is the target?” We increasingly need to ask, “How far has the target expanded, and do we recognize everyone and everything that is now inside it?” 

Because, by the time a grievance has moved beyond the individual, protecting only the principal may no longer be sufficient.