Flock camera hack reveals it tracks people, not just cars

Flock camera hack reveals it tracks people, not just cars

Hackers from a collective calling itself stegan0gram removed a Flock Safety automatic license-plate-reader camera from above a roadway, made a near-complete copy of the data stored inside it, and passed the files to 404 Media and the transparency nonprofit Distributed Denial of Secrets, which shared them with WIRED. The two outlets then ran a joint analysis of the recovered material.

Flock has described its cameras as protected by on-device encryption. The hackers found the device's Android storage split into partitions, two of which, called 'vendor' and 'media,' were unencrypted. The 'media' partition held an encryption key that unlocked the rest of the stored videos and stills, letting the hackers view footage that was supposed to stay locked down.

The recovered logs and code show the camera's software explicitly detects people as well as vehicles, license plates, and bicycles, something Flock's public description of the product does not emphasize. Over several weeks of logs the camera generated more than a million images; a typical passing vehicle produced about 28 images, some more than 100. Across roughly 21 days of activity spread over several periods, the camera photographed about 50,200 vehicles and generated about 1.6 million images, averaging around 3,300 vehicles a day with a high of 4,454. The computer-vision software also sometimes cropped bumper stickers and other graphics as if they were plates, in one case an American flag patch on a motorcyclist's saddlebag.

WIRED extracted the camera's own detection models and tested them on footage recovered from the device, including 27,321 short stored video clips (1,024 by 768 pixels, one to two seconds each). The models readily detected people, including a selfie of a WIRED reporter, and picked up people in 11 of the 27,321 clips, all of them motorcyclists, which the outlets attribute to the camera's downward angle over traffic rather than to the software missing pedestrians generally. WIRED and 404 Media found no active face-recognition capability beyond what ships by default in Android, and it did not appear enabled.

The breach lands inside a wider controversy over Flock's national network, which lets other agencies query cameras far from where they are installed: in Alpharetta, Georgia, records were accessible to more than 2,000 agencies, and 404 Media has previously reported local police running network searches on behalf of immigration authorities and, in one case, in Texas, for a woman who had self-administered an abortion. Some communities have responded by dropping Flock's cameras entirely, and multiple people have been arrested for tampering with the devices; one police department went as far as installing a fake 3D-printed camera housing to catch vandals.

This is not the camera's first disclosed weakness. In early 2025, security researcher Jon 'GainSec' Gaines reverse engineered a Flock reader and documented flaws giving root-level access; Flock acknowledged the findings but downplayed them, saying they required physical access and that footage does not stay on the device. Responding to the new breach, a Flock spokesperson called the removal and tampering 'illegal' and said the company had received no vulnerability report through its disclosure process, adding that it lacks enough detail to assess the claims. Noel Pichardo, a former Pawtucket, Rhode Island, police officer turned Flock critic, said he understands the frustration but worries that sabotaging cameras will only convince police and the state that the tool is necessary.

The recovered logs also caught the camera struggling with itself: more than 27,000 'no space left on device' errors while trying to save full-resolution images, plus a status check every two minutes that logged 'Who's a good boy?!' more than 12,000 times, and a final message on restart reading 'A reboot was requested! Adios, Amigos!'

Key facts

  • Hackers from the collective stegan0gram physically removed a Flock license-plate camera, copied its stored data, and shared it with 404 Media, Distributed Denial of Secrets, and WIRED for a joint investigation.
  • Unencrypted 'vendor' and 'media' partitions on the device let the hackers recover an encryption key and unlock footage, despite Flock's claim that on-device encryption protects the cameras.
  • The software explicitly detects people as well as vehicles, plates, and bicycles; over 21 days of recovered logs it photographed about 50,200 vehicles and generated about 1.6 million images, up to 4,454 vehicles in a single day.
  • WIRED ran the camera's own extracted detection models against 27,321 stored video clips and found people in 11 of them, all motorcyclists, and no active face recognition beyond Android's stock, unenabled capability.
  • Flock's national network made one Georgia city's camera records accessible to more than 2,000 agencies; Flock called the hackers' actions illegal and says it received no formal vulnerability report.

Why it matters

Flock has marketed its automatic license-plate readers as vehicle-focused and protected by on-device encryption. A physical breach that recovered the encryption key and showed the software also explicitly detects people undercuts both claims at once, and does so with an independently verified copy of the device's own data and code rather than a secondhand allegation.

Who it affects

Anyone living, working, or driving near one of the thousands of Flock cameras deployed by US police departments; the more than 2,000 agencies that can already query shared camera networks like the one in Alpharetta, Georgia; Flock itself, now facing renewed scrutiny of its security claims; and the stegan0gram hackers, who removed and dismantled a live device and say they will publish how they obtained the software.

How to use it

There is no product here to adopt, but the disclosure gives two groups something concrete to act on: residents and local officials who want to know what a nearby Flock camera actually records can point to this account of unencrypted 'vendor' and 'media' partitions, and researchers can expect stegan0gram's promised technical writeup on how they extracted the software. Some towns have already responded by dropping Flock cameras outright; one police department instead installed a fake 3D-printed camera housing to catch vandals rather than remove real hardware.

How solid is it

This is a joint investigation by two outlets, 404 Media and WIRED, working from a near-complete physical copy of one camera's storage, its logs, and its own machine-learning models, which WIRED extracted and re-ran against the recovered footage to check what the software actually does rather than relying on the hackers' description of it. Flock was given a chance to respond and did, disputing that it has enough information to assess the claims rather than disputing the recovered facts themselves.

Risks and caveats

The source does not name any stegan0gram member, give the camera's exact location beyond 'above a roadway,' or explain how the encryption key was technically extracted from the media partition. The people-detection results are also uneven: WIRED's test found people in only 11 of 27,321 stored clips, a low count the piece attributes to the camera pointing down at traffic rather than at pedestrians, not to a general failure of the detection software. Older logs beyond the recovered roughly 21 days had been overwritten and could not be checked at all.

“Why just destroy them when we can reverse engineer them and find the secrets of those spying on us?”

— one of the hackers, from the collective stegan0gram