Saturday, September 19, 2026
US National News

The Digital Trail of an Assassin: Senate Documents Reveal Thomas Crooks’ Encrypted Emails, Snapchat Activity, and Extreme Isolation

Siti Muinah
Font Size:
FB X WA TG

Main Facts: The Digital Footprint of Thomas Matthew Crooks

New federal documents turned over to the United States Senate have shed light on the highly secretive digital life of Thomas Matthew Crooks, the 20-year-old Bethel Park, Pennsylvania resident who attempted to assassinate former President Donald Trump. The records, first reported by the New York Post and subsequently obtained and verified by Fox News Digital, provide an unprecedented look into the online habits, communication platforms, and operational security measures adopted by the gunman in the months leading up to the July 13, 2024, attack.

Among the key revelations in the federal investigative files is the discovery of a Snapchat account registered under the username "tom_crooks19." In addition to this social media presence, federal investigators located an active Amazon account, a primary Gmail address, and an account with Mailfence—a specialized, end-to-end encrypted email service based in Belgium.

According to forensic logs detailed in the documents, Crooks accessed his Mailfence account repeatedly between April 15, 2024, and July 8, 2024—the latter date being just five days before he climbed onto a rooftop in Butler, Pennsylvania, and opened fire on the former president.

The shooting resulted in the death of 50-year-old former volunteer fire chief Corey Comperatore and left two other rally attendees, David Dutch and James Copenhaver, critically injured. Former President Trump survived the attempt with a wound to his right ear. Crooks was neutralized at the scene by a Secret Service counter-sniper.

The newly disclosed documents highlight a stark paradox: while Crooks maintained an extremely sophisticated level of digital privacy and operational security, his physical and social life was characterized by absolute, near-total isolation.


Chronology: The Path to the Butler Campaign Rally

The timeline of Crooks’ activities, reconstructed through digital forensics and legislative disclosures, paints a picture of deliberate preparation masked by an unassuming daily routine in suburban Bethel Park.

Spring 2024: Establishing Encrypted Communications

  • April 15, 2024: Investigative logs show Crooks began systematically logging into Mailfence, an encrypted email platform known for its strict privacy protocols and resistance to standard law enforcement surveillance. This period marked the beginning of a heightened phase of digital operational security (OPSEC) for the 20-year-old.
  • Late Spring 2024: Alongside his encrypted email, Crooks maintained active use of his Amazon account and his "tom_crooks19" Snapchat account. Investigators believe these platforms were used to research tactical gear, procure materials, and potentially document his thoughts, though much of the social media data remains subject to ongoing forensic reconstruction.

Summer 2024: Final Preparations

  • Early July 2024: Crooks continued to access his Mailfence account, with his final recorded login occurring on July 8, 2024. During this same period, he conducted online searches regarding major political figures, including both Donald Trump and President Joe Biden, as well as the dates and locations of their upcoming public appearances.
  • July 13, 2024 (The Day of the Attack): Crooks traveled from Bethel Park to the Butler Farm Show grounds in Butler, Pennsylvania. Equipped with an AR-15-style rifle purchased legally by his father, Crooks bypassed local security perimeters, scaled the roof of an AGR International building roughly 400 feet from the stage, and fired multiple rounds into the crowd before being fatally shot.

Post-Incident Investigation and Congressional Oversight

  • Late 2024 – Mid-2025: The FBI’s cyber division worked alongside private tech firms to bypass encryption locks on Crooks’ personal devices, including his primary phone and computer hard drives.
  • Late Summer 2025: The FBI officially compiled its findings into a comprehensive dossier, which was subsequently turned over to the Senate Oversight Committee as part of a broader congressional inquiry into the security lapses surrounding the Butler rally.

Supporting Data: Forensic Analysis of Crooks’ Digital Life

The discovery of Crooks’ digital accounts provides federal investigators with crucial data points to analyze his state of mind and potential motives. Cyber-forensics experts emphasize that even platforms designed for privacy or ephemeral communication leave behind significant footprints.

Would-be Trump assassin Thomas Crooks had Snapchat, which may hold evidence 'treasure trove': former FBI agent

The Snapchat Account ("tom_crooks19")

The revelation of Crooks’ Snapchat account has drawn significant interest from law enforcement experts. Snapchat is widely known for its disappearing message feature, which appeals to users seeking temporary digital footprints. However, forensic experts note that the ephemeral nature of the app does not prevent law enforcement from recovering vital evidence.

Retired FBI Supervisory Special Agent Jason Pack explained to Fox News Digital that Snapchat accounts often serve as a "treasure trove" of metadata and cached information.

"When you snap and that picture goes away, [people think] that everything is gone, and that’s not true," Pack said. "When I’ve served search warrants, there’s been a treasure trove of information that has come back. It’s not like some people think when you’ve snapped, and then it goes away, it’s totally gone. That’s not entirely the case."

Pack noted that while some specific media content may be unrecoverable due to server-side deletion protocols, substantial user data remains accessible to investigators who serve federal search warrants to Snapchat’s parent company, Snap Inc. This data typically includes:

  • IP address login histories and geolocation logs.
  • Friend lists, user connections, and direct message metadata (timestamps and recipient IDs).
  • Saved media in the "Memories" vault or local device caches.
Thomas Crooks' Digital Footprint Profile:
│
├── Snapchat ("tom_crooks19") ── Used for ephemeral messaging and social networking.
│
├── Mailfence (Encrypted) ────── Active April 15 – July 8, 2024; chosen for privacy/OPSEC.
│
├── Gmail Account ────────────── Standard communications, registration of online services.
│
└── Amazon Account ───────────── Procurement of materials, packages picked up via secure methods.

Encrypted Email and Operational Security (OPSEC)

Crooks’ choice of Mailfence as a communication tool is highly telling. Based in Belgium, Mailfence operates under strict European Union privacy laws and offers end-to-end encryption, digital signatures, and keystroke logging protections.

Investigators point out that Crooks exhibited a pattern of behavior designed to avoid detection. He frequently used aliases—including the name of deceased former U.S. Senator "Bob Dole"—to purchase materials online and register accounts. Furthermore, he was highly meticulous about how he received physical deliveries, often taking measures to ensure he was not observed picking up packages.

"What you do see is a pattern of trying to hide things and using aliases," Jason Pack observed. "And, so, if he’s taking that much care to publicly not be seen picking up deliveries and those types of things, you have to assume he’s probably taken just as much diligence with his social media and with his digital footprint."

Would-be Trump assassin Thomas Crooks had Snapchat, which may hold evidence 'treasure trove': former FBI agent

Official Responses: Senate Testimony and the "Lone Wolf" Conclusion

The release of these documents coincided with high-profile testimony on Capitol Hill regarding the progress of the federal investigation.

FBI Testimony on Extreme Social Isolation

Testifying before the Senate Oversight Committee, FBI Director Kash Patel addressed the persistent questions surrounding whether Crooks acted alone or was part of a broader conspiracy. Patel emphasized that despite exhaustive forensic examinations of Crooks’ phones, computers, and online accounts, investigators have found absolutely no evidence of co-conspirators, foreign influence, or local accomplices.

"We found no evidence that that individual was literally even speaking to any other human being other than his parents, who he resided with," Patel testified.

This testimony paints a portrait of a young man existing in a complete social vacuum. According to the FBI documents, acquaintances and family members described Crooks as having been "emotionless since birth." He had no close friends, did not participate in local social organizations, and spent the vast majority of his free time in his bedroom or at a local shooting range.

Congressional Inquiries into Security Failures

The Senate Oversight Committee’s receipt of these documents is part of a bipartisan push to understand not only the shooter’s motives but also the systemic communication and tactical failures of the U.S. Secret Service and local law enforcement on the day of the rally.

Lawmakers have expressed frustration over the pace of the investigation and the difficulty in establishing a clear ideological motive for the shooting. Unlike many modern mass shooters or political assassins, Crooks did not leave behind a traditional manifesto, nor did he post political diatribes on mainstream public forums. His digital trail suggests an interest in the act of assassination itself rather than a specific partisan agenda.


Implications: The Challenges of Modern Threat Detection

The details emerging from the Senate’s investigation into Thomas Matthew Crooks have profound implications for counter-terrorism, threat assessment, and law enforcement operations in the digital age.

Would-be Trump assassin Thomas Crooks had Snapchat, which may hold evidence 'treasure trove': former FBI agent

The Paradox of the "Quiet OPSEC" Lone Wolf

Crooks represents a highly challenging profile for modern threat-detection systems: the self-radicalized, highly isolated "lone wolf" who practices strict operational security. Traditional counter-terrorism strategies rely heavily on intercepting communications, identifying networks of conspirators, or flagging radical rhetoric on public social media channels.

When an individual operates in complete physical isolation—communicating with no one—and utilizes end-to-end encrypted platforms like Mailfence, traditional tripwires fail to trigger. This has forced federal intelligence agencies to re-evaluate how they identify potential threats before they transition from online research to physical action.

The Encryption Debate Renewed

The disclosure of Crooks’ use of encrypted email services is expected to reignite the long-running political and legal debate over end-to-end encryption (E2EE). For years, law enforcement agencies have argued that "warrant-proof" encryption creates "going dark" scenarios, where investigators cannot access the communications of criminals and terrorists even with a court-ordered warrant.

Conversely, digital privacy advocates argue that maintaining strong encryption is vital for cybersecurity, protecting consumer data, and safeguarding dissent against authoritarian regimes. The case of Thomas Crooks will likely be cited by proponents of regulatory measures aimed at requiring tech platforms to provide lawful access pathways for federal investigators.

As the Senate Oversight Committee continues its review of the FBI’s findings, the digital profile of Thomas Crooks stands as a sobering reminder of the complexities of 21st-century security, where the most devastating threats can be planned in complete silence behind an encrypted screen.

Featured Articles