Hackers physically removed a Flock Safety camera from above a roadway, extracted its data, and recovered an encryption key that unlocked videos of thousands of vehicle detections, according to a joint investigation by 404 Media and WIRED published this week. The breach reveals that software running on the device explicitly detects people as well as vehicles, license plates, and bicycles—a capability typically overlooked in public discussions about the automatic license plate reader system. The hackers, from a collective calling itself stegan0gram, shared the material with journalists and the transparency nonprofit Distributed Denial of Secrets, and say they're publishing details on how they obtained the software in hopes others will copy them.
The camera's logs captured roughly 21 days of activity across several periods, during which the device photographed about 50,200 vehicles and generated approximately 1.6 million images, the analysis found. On a typical day, it logged around 3,300 vehicles, with a peak of 4,454. A typical passing vehicle generated about 28 images, though some produced more than 100. The camera uses different exposures to capture both the license plate and the wider scene, then scans the images, selects and crops useful frames, and sends them with other data to Flock over the cellular network. When the software's models were run against 27,321 short video clips stored on the camera, they detected people in 11 of the clips, all of them riding motorcycles. The license plate detector sometimes mistook bumper stickers, dealership frames, and other graphics for license plates—in one video of a passing motorcycle, it cropped an American flag patch on the rider's saddlebag as if it were a plate. The camera's logs also recorded more than 27,000 "no space left on device" errors while trying to save full-resolution images, along with tens of thousands of related errors, crashes, and reboots.
The hackers said they were able to access the Android system on the camera and found several partitions, a few of which were unencrypted, including one called "media" that contained an encryption key unlocking another part with much of the videos and stills the camera took. "Why just destroy them when we can reverse engineer them and find the secrets of those spying on us?" one of the hackers said in an interview. A Flock spokesperson responded that "the unauthorized removal and tampering of a Flock camera is illegal," and when asked about the encryption key stored on the device, said the company "received no report through that process, and based on the limited information provided, we do not have enough detail to assess the claims being made." The investigation found no evidence of any face-recognition capabilities in the camera's software beyond ones included by default in the Android operating system, which did not appear to be enabled or in active use.
The breach exposes how Flock's national network has become a source of controversy, with records from individual cameras accessible to thousands of agencies nationwide—in Alpharetta, Georgia, for example, the investigation found that records from the city's Flock cameras were accessible to more than 2,000 agencies, including police departments, colleges, airports, and the Office of Inspector General for the federal General Services Administration. Previous reporting revealed that local cops were performing lookups in the national network on behalf of Immigration and Customs Enforcement, including in areas that banned working with immigration authorities or transferring license plate data out of state, and that a cop in Texas searched Flock cameras nationwide for a woman who self-administered an abortion. Noel Pichardo, a former Pawtucket, Rhode Island, police officer who became an outspoken critic of Flock, worries that sabotaging devices could ultimately strengthen the case for them. "I think that type of vigilantism will only crystallize the police and the state at large in their belief that this tool is necessary," Pichardo says. "The longer the state continues to ignore the groanings of their constituents who are against this type of surveillance, the more this will happen." The physical breach demonstrates that some activists aren't content with just destroying or removing cameras—they're reverse engineering them to expose what they see as surveillance overreach. For vendors and agencies alike, the incident highlights a tension between operational security claims and the vulnerabilities inherent in distributed hardware systems.

