Hackers Reveal What Flock Cameras Can See Beyond License Plates

A modern surveillance camera powered by solar energy mounted on a street pole.

A group of hackers wanted to know what was hidden inside a Flock Safety camera. Instead of simply destroying the device, they removed one from a roadway and dug into its software.

What they found gave a rare look at how an AI-powered surveillance camera captures, processes, and sends information about vehicles moving through public spaces.

The investigation by 404 Media and WIRED revealed that one camera recorded around 50,200 vehicles over roughly 21 days, producing about 1.6 million images. The analysis also found that the software running on the device could detect people, vehicles, bicycles, and license plates.

The findings have added fresh debate around automated license plate readers, privacy, and how much data these systems collect.

Hackers Removed A Flock Camera And Extracted Its Data

The hacking group involved in the incident identified itself as stegan0gram. The group removed a Flock Safety camera mounted above a roadway and accessed a large portion of the device’s stored information.

The hackers shared the recovered files with 404 Media and the transparency nonprofit Distributed Denial of Secrets, which also provided material to WIRED. The two outlets analyzed the data as part of a joint investigation into how Flock’s technology operates.

According to the investigation, the hackers were able to copy storage from the camera and recover an encryption key stored on the device. That key allowed access to a significant amount of captured media, although some of the most sensitive storage remained encrypted and inaccessible.

The incident provided researchers and journalists with a closer look at a device that Flock has previously described as using on-device encryption.

One hacker from stegan0gram explained the group’s reasoning behind taking the camera apart rather than simply damaging it.

“Why just destroy them when we can reverse engineer them and find the secrets of those spying on us?” the hacker said.

The hacker also stated, “We liberated hardware in the field, disarmed them, and proceeded with reverse engineering of the cameras and associated solar equipment.”

Flock responded by saying unauthorized removal and tampering with its cameras is illegal. The company also pointed to its vulnerability disclosure process, saying researchers can report security concerns directly.

A Flock spokesperson told The Hill that the company had not received a report through that process and said it did not have enough information to evaluate the claims being made by the hackers.

The Camera Captured Millions Of Images From Passing Vehicles

The recovered data showed that the camera was constantly processing traffic passing through its view.

During the periods that could be recovered, the device recorded:

  • Vehicles detected: About 50,200 vehicles
  • Images generated: Around 1.6 million images
  • Average daily vehicle count: About 3,300 vehicles
  • Highest daily vehicle count: 4,454 vehicles
  • Typical images per vehicle: Around 28 images

The numbers came from recovered logs covering approximately 21 days of activity. Researchers noted that the figures should not be considered representative of every Flock camera because traffic volume depends heavily on location.

The camera was likely operating for longer than the recovered period. Older logs may have been overwritten or were no longer available.

Unlike a traditional camera that simply records a continuous video feed, Flock’s system appears to work through rapid bursts of images triggered by movement.

When a vehicle enters the camera’s view, the device captures multiple images. The software then processes those images, selects useful frames, and sends information to Flock’s servers through a cellular connection.

A typical vehicle generated around 28 images, but some produced more than 100 images during a single encounter.

The investigation found that the camera itself does not appear to read license plates or determine details such as vehicle make, model, and color. That analysis appears to happen after the images reach Flock’s servers.

Flock Cameras Run Software Designed To Identify Objects

The recovered files revealed that the camera is more than a simple license plate reader.

According to WIRED and 404 Media’s analysis, the device runs around 20 Flock-built applications that handle different tasks, including motion detection, image capture, object classification, uploading data, and receiving software updates.

The camera’s processor was described as being similar to those found in midrange smartphones.

The recovered software showed that the system detects multiple types of objects:

  • Vehicles
  • License plates
  • Bicycles
  • People

The ability to detect people became one of the most discussed findings from the investigation.

When the software identifies a person, it records where that person appears in an image and assigns a confidence score to the detection. However, the investigation did not find evidence that Flock cameras were actively using facial recognition.

Flock has stated that its cameras do not perform facial recognition. WIRED and 404 Media reported that they found no evidence of active facial recognition capabilities being used beyond features included by default in the Android operating system.

The distinction between detecting a person and identifying a person is significant. A system can recognize that a human figure appears in an image without knowing who that individual is.

To test the recovered software, WIRED extracted the computer vision models from the camera and ran them against stored images and videos.

The models detected people, including a reporter’s selfie used for testing.

Researchers also examined 27,321 short video clips stored on the device. People appeared in 11 of those clips, and all involved motorcycle riders. The limited number was consistent with the camera’s position above roadways, where pedestrians are less likely to appear.

The System Sometimes Mistook Objects For License Plates

The investigation also uncovered examples where the camera’s computer vision system struggled to correctly interpret what it saw.

During testing, the license plate detector sometimes identified unrelated graphics as possible plates. The software cropped bumper stickers, dealership frames, and other images as if they contained license plate information.

One example involved a motorcycle rider’s saddlebag. The system detected an American flag patch and treated it as though it was a license plate.

The finding shows the limitations of automated image analysis. A detection system can locate patterns that resemble a target object, but that does not guarantee the identification is correct.

The recovered data provided a rare opportunity to examine these mistakes because researchers could directly test the software running on the camera.

For communities using automated license plate readers, the findings raise questions about how these systems interpret images and how much information is generated before data reaches a company’s servers.

Flock’s Nationwide Network Has Drawn Previous Scrutiny

Flock cameras are part of a larger network that allows agencies to search vehicle records collected through the company’s technology.

The cameras capture passing vehicles and send information to Flock’s servers, where the system can create searchable records containing details such as license plate numbers and vehicle characteristics.

Those records can then be accessed by agencies that have permission to use the system.

The investigation highlighted the size of that network. In one example examined by WIRED, records from Flock cameras in Alpharetta, Georgia, were accessible to more than 2,000 organizations, including police departments, colleges, airports, and other agencies.

Supporters of the technology argue that sharing information across jurisdictions can help law enforcement investigate crimes and locate vehicles connected to investigations.

Critics have raised concerns about the amount of movement data collected and how broadly that information can be searched.

Previous reporting has examined cases where law enforcement agencies used Flock’s network in controversial ways. Those reports have contributed to wider discussions about automated license plate readers and public surveillance.

The latest investigation added another layer to that debate by revealing details about the hardware itself and the software operating inside it.

Security Questions Grew After Hackers Found Access To The Device

The Flock camera breach has renewed attention on the security of hardware used in public spaces.

While the investigation did not show that every Flock camera operates in the same way, it provided a detailed look at one device and revealed how physical access could expose parts of the system.

The hackers said they recovered an encryption key stored on the camera itself. That discovery raised questions about how surveillance hardware protects sensitive information when someone gains physical access to the device.

The incident also followed previous research into Flock’s hardware security.

In early 2025, security researcher Jon “GainSec” Gaines reverse engineered a Flock license plate reader and documented vulnerabilities that could potentially allow root-level access to the device.

Flock acknowledged those findings but argued that exploiting the issues required physical access to the camera. The company also said that accessing the device would not necessarily provide access to footage because images were only stored locally for a limited period before being transmitted to the cloud.

The latest incident differed because the hackers claimed they were able to recover stored media from the device.

The findings have created a new discussion around whether surveillance equipment deployed across communities needs stronger protections against unauthorized physical access.

Recovered Logs Revealed Storage Problems Inside The Camera

Beyond the surveillance capabilities, the recovered files also revealed technical problems inside the device.

The camera’s logs showed thousands of errors connected to storage limitations. According to the investigation, the device recorded more than 27,000 instances of “no space left on device” while attempting to save full-resolution images.

The logs also showed additional crashes, reboots, and system errors.

Some of the most unusual discoveries came from the camera’s internal messages. A system process repeatedly checked whether the camera was still running and logged the phrase “Who’s a good boy?!”

That message appeared more than 12,000 times in the recovered logs.

Another message appeared after a reboot: “A reboot was requested! ¡Adios Amigos!”

The unusual entries offered a glimpse into the everyday operation of the hardware behind the surveillance network.

Although the messages themselves were harmless, the logs showed that the device was managing large amounts of image data while dealing with storage and stability issues.

The investigation found that the camera’s software was constantly performing multiple tasks at once, including capturing images, analyzing objects, communicating with servers, and receiving remote updates.

The Camera Debate Has Divided Lawmakers And Communities

The Flock camera network has become a major point of debate among lawmakers, police departments, and privacy advocates.

Supporters of the technology say automated license plate readers can help investigators identify vehicles connected to crimes and improve the speed of police investigations.

Critics argue that large-scale collection of vehicle movement data creates concerns about privacy, access, and potential misuse.

Some officials have questioned how much tracking is acceptable when cameras collect information from millions of vehicles traveling through public areas.

Florida Gov. Ron DeSantis previously expressed concerns about surveillance technology, saying he worried the state could become a “digital AI surveillance state where everything we’re doing is being tracked at all times.”

Rep. Thomas Massie (R-Ky.) also introduced the Flock-Off Act, a bill aimed at restricting the use of federal funds for automated license plate reader cameras and biometric surveillance cameras.

President Donald Trump has publicly supported Flock cameras, arguing they can assist law enforcement.

“No, I sort of like them [Flock cameras] because of that, because of law enforcement. But some people don’t. They think it’s an infringement,” Trump said.

The disagreement reflects a larger question facing communities using these systems: how to balance crime prevention tools with concerns about data collection and government access.

Flock Defended Its Security Practices After The Breach

Flock responded to the investigation by emphasizing that removing and tampering with its cameras is illegal.

The company said it maintains a public vulnerability disclosure policy that allows security researchers to report potential issues directly.

A Flock spokesperson said the company had not received a report through that process and did not have enough information to evaluate the claims made by the hackers.

The company encouraged anyone who believed they had identified legitimate vulnerabilities to submit technical findings through its reporting system.

Flock’s response focused on the method used to obtain the information, while the investigation centered on what the recovered data revealed about the device’s capabilities.

The difference highlights a recurring challenge in cybersecurity: companies often rely on responsible disclosure processes, while some researchers and activists choose public exposure to draw attention to potential risks.

In this case, the leaked information gave journalists access to technical details that were previously difficult for outsiders to examine.

The Breach Shows How Much Happens Before Data Reaches The Cloud

The investigation revealed that a Flock camera is not simply recording traffic and sending one image to a database.

Instead, the device performs several steps before information reaches Flock’s servers.

When movement triggers the camera, it captures multiple images under different exposure settings. The software then selects useful frames, crops areas of interest, and sends information through a cellular connection.

The camera acts as the first stage in a larger surveillance system.

The processing continues after the data reaches Flock’s servers, where the company’s systems can analyze vehicle characteristics and create searchable records.

That separation between hardware, software, and cloud processing makes it harder for the public to understand exactly how these systems operate.

The hacker investigation provided a rare look at the device level, showing what software was running and what objects the camera was designed to detect.

It also showed the limitations of automated systems, including cases where the software incorrectly identified objects.

For security researchers, the findings raised questions about encryption practices and the protection of surveillance devices installed in public areas.

For communities, the investigation provided more information about what these cameras can capture and how much data one device can generate.

The Flock Camera Fight Is Now About More Than The Cameras

The hacking incident began with the removal of one device, but the questions it raised extend beyond a single camera.

The investigation showed that modern surveillance systems rely on a combination of hardware, artificial intelligence, cloud databases, and broad information-sharing networks.

That combination has made Flock cameras attractive to law enforcement agencies while also creating concerns among people who worry about constant data collection.

The breach did not prove that every camera in the network works exactly the same way, and researchers noted that the recovered information came from one device.

However, it provided one of the clearest public examinations of how these systems function behind the scenes.

As more communities consider adopting AI-powered surveillance tools, the debate will likely continue around security, transparency, and the limits of tracking technology.

The most important discovery from the hacked camera may not have been a hidden feature. It was the fact that a device sitting quietly above a roadway can collect, process, and transmit far more information than many people realize.

Loading…


Leave a Reply

Your email address will not be published. Required fields are marked *