Drooid Logo
Back to story perspectives

Full Breakdown

Hack Exposes Flock Safety Camera Capabilities and Triggers Nationwide Backlash

By Drooid · · How we work

The breach and its revelations

Hackers removed a Flock Safety camera, copied its storage and recovered an encryption key that unlocked thousands of vehicle-detection images. The logs showed the device captures license plates, people, bicycles and even isolated graphics such as bumper stickers. A typical passing vehicle generated about 28 still images; the recovered logs recorded roughly 1.6 million images over 21 days. The camera runs about 20 proprietary apps for motion detection, image capture, object classification and cloud upload.

Background & context

Flock Safety markets its automatic license-plate readers (ALPRs) as “vehicle intelligence” tools and operates a national network that lets agencies query cameras beyond their own jurisdiction. The company says facial-recognition functions are disabled and images remain on the device only briefly before transmission. Prior to the breach, its vulnerability-disclosure policy noted no reported exploits.

Data and statistics

  • Over 50 000 vehicles logged in the 21-day period (?3 300 per day).
  • Approximately 1.6 million images generated, including 11 short video clips of motorcyclists.
  • The device logged more than 27 000 “no space left on device” errors and over 12 000 status messages.

Official statements & responses

Flock’s spokesperson called the unauthorized removal illegal and reiterated the company’s security commitment. The firm said it had not received a vulnerability report and could not assess the claims without more detail. Boston Police Department officials, after learning that data-sharing settings were mistakenly enabled during a 156-day pilot that began on April 1 2025, said the vendor was directed to disable the function and the city would cease using Flock services. Dallas Police Department representatives emphasized that the cameras are used only for investigatory purposes and do not employ facial-recognition technology.

Conflicting reports & gaps

Boston’s pilot report states data sharing was “off” by contract, yet the city discovered external agency access within three days of launch. Flock claims the error required physical access; city officials attribute it to a software fault. The trial recorded 77 agency requests (e.g., U.S. State Department, DEA), but the number granted and data retrieved remain unclear.

What’s next

  • Pennsylvania lawmakers are advancing bills that would require warrants for ALPR searches, limit data retention to seven days and give municipalities authority to ban the technology.
  • Boston has begun pilots with competing vendors (Motorola and Axon) and plans to delete all Flock data within 30 days of the trial’s end.
  • Several Massachusetts towns, including Westford, have declined to adopt Flock cameras after resident concerns voiced at a Select Board meeting on July 28.
  • The hacker collective stegan0gram released a guide to replicating the breach, prompting further security audits across the industry.