Hackers Expose Flock Safety's Surveillance Capabilities, Revealing Deeper Tracking Than Advertised
A collective of hackers, stegan0gram, has publicly released data and methods after physically compromising a **Flock Safety** camera. Their actions provide an unprecedented look into the device's inner workings, revealing that the cameras explicitly detect and log people in addition to vehicles, challenging previous assertions about their capabilities and data security.
A group of hackers, identifying themselves as **stegan0gram**, has taken direct action against **Flock Safety**'s controversial surveillance cameras. By physically removing a camera, copying its internal data, and publishing their findings with journalists from **404 Media** and **WIRED**, they've offered an unparalleled glimpse into the technology's operational scope.
This breach directly contradicts **Flock Safety**'s claims of robust on-device encryption. The hackers successfully copied the camera's storage and recovered an encryption key, unlocking videos of thousands of vehicle detections.
### Beyond License Plates: Detecting People and More
While some sensitive data remained encrypted, the joint analysis by **404 Media** and **WIRED** revealed that the camera's software explicitly identifies people, vehicles, license plates, and bicycles. Over several weeks of recovered logs, the device generated more than a million images, sometimes isolating bumper stickers and other graphics, including an American flag patch on a motorcyclist's saddlebag.
**stegan0gram**'s motivation extends beyond mere vandalism. "Why just destroy them when we can reverse engineer them and find the secrets of those spying on us?" a hacker from the collective stated. "We liberated hardware in the field, disarmed them, and proceeded with reverse engineering of the cameras and associated solar equipment."
### The Expanding and Contentious Flock Network
**Flock Safety** cameras capture images of passing vehicles, sending them to company servers where license plates and vehicle characteristics are identified. This data then becomes searchable by local agencies and, controversially, often by other police departments nationwide through **Flock**'s expansive network.
For instance, **WIRED** previously reported that in Alpharetta, Georgia, data from **Flock** cameras was accessible to over 2,000 organizations, including police departments, colleges, airports, and even the federal **General Services Administration**'s Office of Inspector General.
This national network has been a significant point of contention. **404 Media** exposed instances of local police performing lookups for **Immigration and Customs Enforcement (ICE)**, even in jurisdictions that prohibit cooperation with immigration authorities. Another report by **404 Media** detailed a Texas officer using **Flock** cameras nationwide to track a woman who sought an abortion. These revelations have fueled a national debate about the presence and use of automatic license plate readers.
### Unpacking the Device: Encryption and Android OS
The hackers gained access to the camera's Android system, discovering unencrypted partitions labeled "vendor" and "media." The "media" partition contained an encryption key, which subsequently unlocked a section holding many of the captured videos and stills.
This incident follows earlier research by **Jon "GainSec" Gaines**, who in early 2025 reverse-engineered a **Flock** device and documented flaws that could grant root-level access. Although **Flock Safety** acknowledged Gaines's findings, they downplayed the severity, arguing that physical access was required and that footage would remain inaccessible because images are only briefly stored on the device before cloud transmission.
Analysis of the camera's contents revealed a processor similar to those in midrange smartphones, running approximately 20 **Flock**-built applications for motion detection, image capture, object classification, data upload, and remote updates.
### Deep Dive into Image Capture and Data Volume
When motion is detected, the camera rapidly captures a series of photos. A typical passing vehicle generated around 28 images, though some produced over 100. The camera uses varying exposures to capture both license plates and broader scenes, then processes and sends relevant frames to **Flock**'s servers via cellular networks. The actual license plate reading and vehicle identification appear to occur server-side.
The analyzed logs showed about 21 days of activity, during which the device photographed approximately 50,200 vehicles and generated about 1.6 million images. On an average day, it logged around 3,300 vehicles, peaking at 4,454. The number of logs would vary based on camera placement and traffic volume.
Crucially, the camera's software explicitly detects people. When a person is spotted, the system records their position in the image and the confidence level of the detection. Tests conducted by **WIRED** confirmed that the camera's models readily detected people, even in reporter selfies and in 11 out of 27,321 short video clips from the device, primarily showing motorcyclists.
The tests also highlighted the broad interpretation of the license plate detector, which sometimes mistook bumper stickers, dealership frames, and other graphics for license plates, cropping them accordingly. In one instance, an American flag patch on a motorcyclist's saddlebag was cropped as if it were a plate.
**Flock Safety** maintains that its cameras do not perform facial recognition. **WIRED** and **404 Media** found no evidence of active face-recognition capabilities beyond those included by default in the Android operating system, which did not appear to be enabled or in use.
This incident underscores the ongoing tension between public safety technology and privacy concerns, highlighting the need for transparency and robust security in ubiquitous surveillance systems.