
Most people who dislike Flock Safety's license-plate cameras vandalize them. A hacker collective calling itself stegan0gram did something slower and, for the company, more damaging: it removed a camera from above a roadway intact and cloned the data on its hard drive.
The group gave copies to 404 Media and WIRED, along with the transparency archive Distributed Denial of Secrets. The outlets published a joint investigation into the findings this week.
It's the closest look outsiders have gotten at how one of the country's most widely deployed surveillance systems actually works on the inside, and it comes at an already tense moment for Flock, whose cameras have become a magnet for both grassroots protest and legislative scrutiny.
What the teardown found
Flock's roadside units, the hackers discovered, run on a stripped-down Android system. Inside, 404 Media and WIRED counted roughly twenty Flock-built applications handling everything from motion detection and image capture to object classification and remote software updates.
The bigger issue sat in the storage itself. While most of the drive was properly locked down, one partition, labeled "media," was left unencrypted.
Sitting inside that partition was the encryption key needed to unlock the camera's own video and image archive. Stealing the box, in other words, was enough to open everything it had recorded.
The code also confirmed something Flock has been cagey about publicly: the cameras don't just log plates. When a person walks into frame, the software records where they appear in the image and a confidence score for the detection.
Both outlets, however, said they found no evidence the system performs facial recognition.
By the numbers:
1.6M+ | images captured |
50,200 | vehicles logged |
21 | days of footage on the device |
Flock's response
Flock did not dispute the technical findings so much as the method. A company spokesperson told the outlets that "the unauthorized removal and tampering of a Flock camera is illegal."
Asked specifically about the unencrypted key, the company pointed to its public vulnerability disclosure process, and noted it had received no report through that channel before the story broke.
That's partly by design on the hackers' side. The stegan0gram member who spoke to WIRED said the group deliberately avoided contacting Flock directly, wary of drawing legal attention to a project that involved physically removing company hardware from public poles.
Emma Best, co-founder of Distributed Denial of Secrets, put it more bluntly: mass-surveillance hardware that's out in the world will always be vulnerable to exactly this kind of physical tampering.
Part of a wider pattern
This comes amid a broader backlash against Flock's network. Towns across the U.S. have canceled contracts with the company, and outright vandalism, cutting cameras down, disabling them, even selling 3D-printed covers to block the lens, has become common.
Some police departments have even started baiting vandals with fake decoy units.
The teardown also isn't the only security question Flock is facing. Separately, U.S. Senator Ron Wyden and Representative Raja Krishnamoorthi wrote to the Federal Trade Commission urging an investigation into a different problem: Flock's reported failure to require multi-factor authentication on the police accounts that access its camera network, which lawmakers say has left the system open to compromise via stolen logins.
It's a different vulnerability than the encryption key, but it points in the same direction Wyden and Krishnamoorthi have already raised: that Flock has consistently failed to secure a system built to watch millions of people.
Why it matters
The core lesson here is an old one in security engineering: encryption is only as strong as the key management behind it. Storing the key on the same device it's meant to protect, where anyone who gets inside the box can find it, undercuts the whole idea of "on-device encryption," no matter how strong the underlying cipher is.
It also complicates the bigger fight over Flock's cameras. That debate has mostly been about whether ALPR networks should exist at all.
This teardown adds a second question: even if you accept the premise, can a system logging tens of millions of vehicle and person sightings a year actually be trusted to keep that data secure once it's collected?
Based on reporting from 404 Media, WIRED, and Distributed Denial of Secrets, September 2026
Sources
Hackers Stole Flock's Camera Software, Revealing How It Tracks Cars and People (404 Media)
Hackers Got Inside a Flock Camera. Its Data Shows How the System Works (WIRED)
Flock ALPR camera data release (DDoSecrets)
Hackers rip down Flock camera, steal its data, share findings with media (The Hill)
Lawmakers say stolen police logins are exposing Flock cameras to hackers (TechCrunch)
Comments (0)
Join the discussion by logging into your account.