Full Breakdown
Hackers Expose Inner Workings of Flock Safety’s License-Plate Cameras
By Drooid · · How we work
The Breach and Its Findings
On September 16, a hacker collective called *stegan0gram* removed a Flock Safety camera, copied its storage, and recovered an on-device encryption key. The key unlocked thousands of videos and still images of vehicle detections. Analysis by 404 Media and WIRED shows the camera’s software reads license plates and also detects people, bicycles and other graphics. Over a 21-day period the device captured roughly 50,200 vehicles and generated about 1.6 million images—an average of 3,300 vehicles per day, peaking at 4,454. When a person entered the field of view, the software recorded the person’s location and a confidence score; no pedestrian images were recovered, likely because the camera is mounted above a busy roadway.
How Flock Cameras Operate
Each unit runs a customized Android system with about 20 Flock-built applications handling motion detection, image capture, object classification, data upload and remote updates. When motion is detected, the camera snaps a burst of photos (about 28 per typical vehicle, sometimes over 100). It captures multiple exposures to isolate the license plate, then crops and sends the selected frames to Flock’s cloud over a cellular network. The on-device software does not perform plate reading or vehicle-make identification; those analyses occur on the company’s servers. The camera also runs models that can flag people and bicycles and occasionally misidentifies graphics such as bumper stickers as a license plate.
Scale of Data Access
WIRED discovered that records from Alpharetta, Georgia, were searchable by more than 2,000 agencies, including police departments, colleges, airports and the Office of Inspector General for the General Services Administration. This national-network capability is a core selling point for Flock but has sparked privacy concerns, especially after 404 Media revealed that some officers used the system for Immigration and Customs Enforcement lookups and, in Texas, to track a woman who self-administered an abortion.
Official Statements & Responses
When asked about the recovered encryption key, the company emphasized its vulnerability-disclosure policy and noted that it had received no report through that channel.
Flock’s security blog, published January 6 2026 and updated July 24, asserted that the cloud platform “has not been hacked” and that no customer data had been exfiltrated, characterizing the breach as a physical-access issue rather than a cloud compromise.
Chief executive Garrett Langley remarked on November 5 2025 that “security is never done,” referencing a researcher white paper and CVE registration handling the disclosed flaws.
Criticism & Opposition
The hack has intensified opposition to mass-surveillance technology. Former Pawtucket police officer Noel Pichardo—now a vocal critic of Flock—argued that vigilantism could reinforce police belief in the tool’s necessity.
> “I think that type of vigilantism will only crystallize the police and the state at large in their belief that this tool is necessary,” — Noel Pichardo
Community activists have responded with protests, contract cancellations, and a police department that fabricated a 3D-printed camera case to lure vandals.
Conflicting Reports & Gaps
Flock maintains that on-device encryption protects stored footage, yet the hackers recovered an unencrypted “media” partition containing the encryption key, contradicting the claim of comprehensive protection. The company also states that its cameras do not perform facial recognition; both 404 Media and WIRED found no evidence of active face-recognition software beyond default Android capabilities. However, the camera’s ability to log precise person locations raises questions about the extent of personal-trait tracking that the company publicly denies.
