Technology

Hackers expose the internal mechanics of Flock Safety cameras revealing how the company tracks vehicles and pedestrians

In a significant breach of digital security and physical infrastructure, a collective of hackers operating under the name stegan0gram has compromised a Flock Safety automated license plate reader (ALPR) unit. By removing the device from its post above a public roadway, the group managed to extract, decrypt, and distribute its internal data, offering the public an unprecedented look into the proprietary software and surveillance capabilities of one of the nation’s most prolific law enforcement technology providers. The data, which has been analyzed by 404 Media and WIRED, confirms that these devices are capable of far more than just recording license plates; they are sophisticated edge-computing tools designed to track human movement and classify diverse environmental features in real-time.

The Anatomy of a Surveillance Breach

The incident began when hackers physically accessed a Flock camera, an act that has become increasingly common as public backlash against automated surveillance grows. Upon disassembling the hardware, the group bypassed on-device security measures that Flock Safety had previously touted as robust. By accessing the device’s internal Android-based operating system, the hackers were able to locate unencrypted partitions containing system logs and encryption keys. These keys provided the access necessary to unlock a repository of captured video and still imagery.

The recovered data represents a high-resolution window into the daily operations of the device. Over a period of several weeks, the single camera unit generated approximately 1.6 million images and logged tens of thousands of vehicle detections. The analysis of these files indicates that the camera operates as a "smart" sensor rather than a simple recording device. It utilizes a suite of approximately 20 custom applications to process raw visual input, identify motion, crop relevant frames, and categorize objects—including people—before transmitting this metadata to centralized servers for long-term storage and cross-referencing.

Chronology of the Surveillance Expansion

The rise of Flock Safety has been meteoric, transforming the landscape of American law enforcement. Founded in 2017, the company initially focused on residential security, but it quickly pivoted to providing "crime-solving" tools for police departments. By 2025, the network had expanded to encompass thousands of jurisdictions.

Hackers reveal how Flock cameras really track cars and people
  • 2017: Flock Safety is founded, introducing a camera system designed for neighborhood associations.
  • 2022-2023: The company aggressively expands its "National Hotlist" program, allowing disparate police agencies to share plate data across state lines, creating a massive, interconnected surveillance web.
  • 2025: Security researcher Jon "GainSec" Gaines publishes findings detailing vulnerabilities in the company’s "Falcon" and "Sparrow" hardware, noting that physical access could lead to root-level exploits.
  • 2026 (April): The stegan0gram collective successfully exfiltrates data from a field unit, proving that the theoretical risks highlighted by researchers were practical realities.

Despite the warnings issued by researchers like Gaines, Flock Safety maintained that its encryption protocols and data management policies were sufficient to protect privacy. The company famously argued that because images are transmitted to the cloud and stored only briefly on the device, the physical theft of a camera would yield little sensitive information. The recent breach directly contradicts this narrative, proving that the device stores substantial amounts of visual data and, more importantly, the keys required to decode it.

Technical Capabilities and Human Detection

One of the most controversial revelations from the analysis of the hacked data is the camera’s ability to detect and track human beings. While Flock Safety has frequently marketed its devices as tools for tracking vehicles—specifically to assist in locating stolen cars or identifying suspects in transit—the software running on the device is explicitly configured to identify people.

In the recovered video clips, the device’s computer-vision models successfully identified pedestrians and motorcyclists. While the camera was mounted high above a road, making pedestrian capture infrequent, the presence of these models confirms that the hardware is pre-programmed for human detection. Furthermore, the analysis revealed the device’s tendency to "over-detect," often mistaking inanimate objects for license plates. Items such as dealership decals, bumper stickers, and even patches on clothing were frequently cropped and processed as if they were identification data, illustrating the broad, indiscriminate nature of the image-capture algorithms.

Official Responses and the Security Gap

In response to the breach, a spokesperson for Flock Safety emphasized the illegality of the act, noting that "the unauthorized removal and tampering of a Flock camera is illegal." The company stated that it maintains a formal vulnerability disclosure policy, inviting researchers to report flaws through official channels rather than through illicit activity. Flock noted that they had not received a report regarding the specific vulnerabilities utilized by the stegan0gram collective.

However, the hackers argue that their actions were a form of "liberation," intended to demystify the technology that tracks citizens without their explicit consent. "Why just destroy them when we can reverse engineer them and find the secrets of those spying on us?" a representative of the collective remarked. This sentiment reflects a growing divide between private security firms and privacy advocates who believe that the deployment of AI-driven surveillance has outpaced public oversight and legislative regulation.

Hackers reveal how Flock cameras really track cars and people

Implications for Law Enforcement and Privacy

The implications of this breach extend far beyond the compromised hardware. The national network maintained by Flock has faced intense scrutiny regarding how data is accessed and used. Previous investigations have shown that police departments have used the system to conduct unauthorized searches, including instances where officers tracked individuals for reasons unrelated to criminal investigation—such as monitoring access to reproductive healthcare or assisting federal immigration authorities in jurisdictions that have formally opted out of such cooperation.

The technical discovery that the cameras are capable of such granular tracking raises fundamental questions about the "searchability" of the modern American street. When a camera can log 3,300 vehicles per day and simultaneously scan for human presence, it essentially creates a permanent, searchable record of movement that functions as a digital dragnet.

Moreover, the technical logs recovered from the device revealed a system under constant stress. The "no space left on device" errors, occurring over 27,000 times, suggest that the hardware is being pushed to its operational limits, often leading to frequent reboots. The inclusion of peculiar, humorous code comments—such as "Who’s a good boy?!" and "¡Adiós, Amigos!"—in the error logs provided a surreal contrast to the serious nature of the surveillance data being processed.

As the debate over automated surveillance continues, the incident serves as a stark reminder of the risks inherent in the "security-as-a-service" model. By centralizing the visual record of public life, firms like Flock Safety have created high-value targets for both hackers and those who believe the technology is a fundamental threat to civil liberties. With police departments increasingly reliant on these networks to solve crimes, the pressure to maintain both the security of the devices and the trust of the public will only increase. Whether this breach leads to stricter regulation or simply encourages further vigilantism remains an open question in an increasingly monitored society.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button