Newly disclosed Federal Bureau of Investigation documents turned over to the United States Senate have shed fresh light on the digital footprint of Thomas Matthew Crooks, the gunman who attempted to assassinate former President Donald Trump in July 2024. Among the findings included in the federal cache is a previously undisclosed Snapchat account tied directly to the shooter, alongside various other encrypted communication channels and online profiles that investigators have spent months analyzing.
The documents, first brought to light by the New York Post and subsequently reviewed by lawmakers and security analysts, indicate that federal law enforcement agents successfully located a Snapchat profile operating under the username "tom_crooks19." The discovery of this social media footprint comes nearly two years after the tragic shooting at a campaign rally in Butler, Pennsylvania, an event that fundamentally altered the American political landscape, upended the presidential election cycle, and triggered sweeping internal investigations into the security protocols of the United States Secret Service.
In addition to the Snapchat profile, the newly released FBI files catalog a broader array of online accounts utilized by the 20-year-old Bethel Park, Pennsylvania native. Investigators uncovered an active Amazon account linked to Crooks, as well as a profile with Mailfence, an encrypted email service known for its high-security privacy features. Forensic data recovered from the Mailfence account revealed that Crooks logged into the service multiple times between April 15, 2024, and July 8, 2024—just days before he opened fire on the presidential candidate. Furthermore, standard Gmail accounts were also identified as part of his digital ecosystem, prompting ongoing forensic examinations into his communication history, search queries, and potential online associations.
The July 13, 2024 Attack and Immediate Aftermath
The revelation of Crooks’ digital footprint revives intense public and legislative focus on the events of July 13, 2024. On that fateful afternoon, thousands of supporters had gathered at the Butler Farm Show grounds in Butler, Pennsylvania, to hear Donald Trump speak at a routine campaign rally. Shortly after the rally began, Crooks—positioning himself on the unsecure roof of a nearby agrarian building outside the official event perimeter—fired multiple rounds from a semi-automatic rifle toward the stage.

A bullet grazed Trump’s right ear, a fraction of an inch away from a catastrophic injury. Secret Service counter-snipers neutralized the shooter seconds later, ending the active threat. However, the tragedy resulted in severe casualties among the audience members. One rally attendee, 50-year-old former volunteer fire chief Corey Comperatore, was tragically killed while shielding his family from the gunfire. Two other attendees, David Dutch and James Copenhaver, sustained critical injuries and were rushed to regional hospitals in intensive care conditions.
The immediate aftermath was marked by shock, outrage, and immediate bipartisan demands for accountability. Questions instantly mounted regarding how an armed individual managed to scale a nearby roof with a rifle despite local law enforcement spotters noting suspicious behavior prior to the shooting. Congressional committees, independent panels, and the FBI launched massive parallel probes to reconstruct the timeline of the security failures and to dissect every facet of the gunman’s background, psychology, and preparation.
Unlocking Encrypted Platforms: Forensic Realities of Digital Evidence
The discovery of the Snapchat account has reignited discussions regarding the permanence of digital data and the forensic capabilities of federal law enforcement agencies when handling modern social media applications. Jason Pack, a retired FBI Supervisory Special Agent, weighed in on the technological realities of recovering evidence from ephemeral messaging platforms.
Addressing common misconceptions about applications designed to delete messages automatically, Pack explained that user perception often does not align with forensic recovery outcomes. "When you snap and that picture goes away that everything is gone and that’s not true," Pack noted in an interview with Fox News Digital. "When I’ve served search warrants, there’s been a treasure trove of information that has come back. It’s not like some people think when you’ve snapped and then it goes away, it’s totally gone. That’s not entirely the case."
While certain metadata, transient images, or expired chat logs may remain permanently inaccessible due to platform architecture and automatic deletion protocols, Pack emphasized that federal cyber-forensic teams frequently unearth a substantial amount of residual data. This can include cached files, server-side logs, account registries, contact lists, and cached media stored locally or within cloud backups.

Despite the potential evidentiary value, experts caution that Crooks appeared to be acutely aware of his digital footprint and took deliberate steps to mask his activities. Pack pointed out that Crooks demonstrated a distinct pattern of operational security, utilizing aliases and taking precautions to avoid public detection when ordering supplies, receiving deliveries, and moving about his community. This meticulous caution suggests he may have applied an equal level of digital hygiene to his social media usage, encrypted email accounts, and browsing history.
"What you do see is a pattern of trying to hide things and using aliases," Pack observed, "and so if he’s taking that much care to publicly not be seen picking up deliveries and those types of things you have to assume he’s probably taken just as much diligence with his social media and with his digital footprint."
Official Findings on Isolation and Radicalization
The release of these FBI files aligns closely with recent congressional testimony regarding Crooks’ social isolation. During a high-profile hearing before the Senate Oversight Committee, FBI Director Kash Patel provided critical updates regarding the bureau’s exhaustive investigative findings into whether Crooks acted as part of a larger conspiracy or foreign cell.
Director Patel testified under oath that, despite scouring terabytes of data, financial transactions, electronic communications, and personal effects, investigators found no credible evidence linking Crooks to any co-conspirators, radical organizations, or ideological handlers.
"We found no evidence that that individual was literally even speaking to any other human being other than his parents, who he resided with," Patel stated during the Senate hearing.

This portrait of extreme isolation has puzzled behavioral analysts and criminal profilers. Crooks was characterized by acquaintances as a quiet, academically competent young man who maintained a low profile, kept few close friends, and spent significant amounts of time online. The stark contrast between his quiet daily life in Bethel Park and the meticulous, lethal planning required to execute an assassination attempt has left investigators searching for the specific psychological triggers and online rabbit holes that may have motivated his actions.
Broader Implications and Ongoing Security Concerns
The ongoing drip of disclosures regarding Thomas Crooks’ background highlights the complex, prolonged nature of counter-terrorism and domestic threat investigations. As federal agencies continue to process encrypted communications, examine hardware devices, and brief congressional oversight committees, the case remains a focal point for discussions on domestic extremism, lone-actor radicalization, and the technical challenges of modern digital forensics.
Furthermore, the persistent threat environment surrounding political figures keeps the lessons of the Butler shooting sharp in the public consciousness. In the years following the July 2024 attack, security agencies have faced continued threats and subsequent security breaches targeting political leadership, reinforcing the reality that threat mitigation requires constant adaptation.
For lawmakers, the newly revealed documents—including the Snapchat account, Amazon profile, and Mailfence history—provide another piece of the puzzle in understanding how an isolated 20-year-old managed to plan an attack of this magnitude without leaving a traditional paper trail. While investigators continue to sift through the recovered digital artifacts, the findings serve as a stark reminder of the intricate challenges law enforcement faces when probing the digital lives of modern lone-actor threats.



