Members of the hacker group stegan0gram removed a Flock Safety camera from above a roadway and gained access to nearly all of its stored data, according to reporting by 404 Media and WIRED. The device had captured approximately 50,200 vehicles across 21 days of operation and includes capabilities to detect people. The breach coincided with an announcement by two members of Congress proposing legislation that would penalize states failing to restrict the use of such cameras.
"Why just destroy them when we can reverse engineer them and find the secrets of those spying on us?" one hacker told 404 Media.
The collective shared its extracted files with 404 Media and the nonprofit Distributed Denial of Secrets, which subsequently provided them to WIRED. Both outlets jointly analyzed the data and published their investigation on 16 September. The hackers indicated they would also release technical documentation detailing their methods, enabling others to replicate the extraction process.
Encryption key discovered on device
Flock has marketed its cameras as featuring on-device encryption protections. However, the hackers reported accessing the camera's Android operating system and discovering multiple unencrypted partitions labeled "vendor" and "media."
The "media" partition contained an encryption key capable of unlocking a separate storage section holding the majority of video and photographic content captured by the device. According to the joint analysis, much of the camera's most sensitive data remained encrypted. In 2025, security researcher Jon Gaines had previously reverse engineered a Flock reader and identified vulnerabilities that could enable root access, findings that Flock acknowledged while noting they required physical device access and that images remained on the camera only briefly before uploading.
Recording capabilities and data collection
The camera's processor resembles those found in mid-range smartphones and runs approximately 20 applications developed by Flock. These applications manage motion detection, image capture, object classification, data uploads and remote system updates.
Upon detecting movement, the camera captures a rapid sequence of photographs. A typical vehicle passing through the frame generated around 28 images, though some instances produced more than 100. The camera does not appear to perform license plate reading or vehicle identification; these functions occur on Flock's servers instead.
The recovered activity logs spanned approximately 21 days, during which the camera recorded roughly 50,200 vehicles and generated about 1.6 million images. The device's peak day logged 4,454 vehicles. The software also identifies people, vehicles, license plates and bicycles. Upon detecting a person, it records their position within the frame and a confidence score. When WIRED analyzed 27,321 short video clips extracted from the camera, it identified people in 11 clips, all involving motorcyclists.
The license plate detection system occasionally misidentified bumper stickers and dealership frames as plates. In one instance, it flagged an American flag patch on a motorcyclist's saddlebag. The outlets found no evidence of facial recognition functionality beyond default Android features, which appeared inactive. Flock maintains that its cameras do not perform facial recognition.
The logs also revealed more than 27,000 "no space left on device" errors. Approximately every two minutes, a system check logged the message "Who's a good boy?!"
Flock's statement and operations
"The unauthorized removal and tampering of a Flock camera is illegal," a Flock spokesperson told 404 Media. The company stated it had not received a report through its public vulnerability disclosure process and lacked sufficient detail to evaluate the claims. It requested that the hackers submit their findings through the proper disclosure channel.
Flock operates a national network enabling police departments to search camera footage across multiple jurisdictions. WIRED previously documented that in Alpharetta, Georgia, more than 2,000 agencies held access to the city's camera records. In August, Flock introduced an AI-powered search tool for law enforcement and reduced its data retention period to seven days.
Congressional response and the No FLOCK Act
Representatives Raja Krishnamoorthi, an Illinois Democrat, and Michael Cloud, a Texas Republican, announced plans to introduce legislation on 16 September. The No FLOCK Act, standing for Federal License-Plate Observation and Camera Keeping, would direct the US transportation secretary to withhold 10% of a state's annual federal highway, road and bridge funding if the state fails to restrict the cameras.
The bill text permits only five uses for license plate readers:
- Toll enforcement
- Locating stolen vehicles
- Finding missing or endangered people
- Identifying vehicles registered to individuals with felony warrants
- Locating vehicles involved in felonies
Should the bill become law this year, states failing to comply would begin losing federal funding in October 2028. The legislation does not ban the cameras outright and does not prevent agencies from sharing license plate data.
Krishnamoorthi stated that an investigation into Flock had revealed "serious gaps in oversight." Cloud declared that "Flock cameras are enabling mass surveillance of Americans, infringing on the Fourth Amendment."
President Donald Trump stated on 13 September that the cameras assist law enforcement, according to WIRED. Flock did not immediately provide comment on the proposed bill. The legislation follows recent state-level action, with Florida and Texas both moving against Flock cameras earlier in September. Flock's network has expanded significantly across the United States this year, and the company's product line now extends to police response drones, which Stockton, California approved in June.
Source: The Next Web



