All stories
AI

Security Flaw Exposes Over 300,000 Flock Safety Surveillance Devices Nationwide

A researcher uncovered an unauthenticated vulnerability on Flock Safety's website, revealing the precise locations and details of its vast network of surveillance cameras and other devices across the U.S., raising severe privacy and national security concerns.

By TECH NEWS Editorial·Source:Tom's Hardware·6 min read·9h ago

✨ This content was summarized and interpreted by AI; it may contain errors — please verify accuracy with the original sources. Learn more

Share

Listen to this story

0:00 / 0:00
Security Flaw Exposes Over 300,000 Flock Safety Surveillance Devices Nationwide

A security researcher has exposed the locations and detailed descriptions of over 300,000 Flock Safety surveillance devices across the United States, revealing an unauthenticated flaw on the company's website that allowed access to a third-party mapping provider. Joshua Michael, the researcher, leveraged an access token, obtainable without login credentials, to query ArcGIS—a geographic information system platform utilized by Flock—and retrieve a comprehensive database of camera placements in December 2025. His "Flock Surveillance Map" details more than 170,000 cameras and an additional 130,000 supplemental devices, including acoustic detection units, illustrating an expansive and granular network of interconnected surveillance infrastructure. Michael promptly informed Flock Safety of the vulnerability in November 2025, but after multiple unacknowledged attempts, the company eventually responded with a generic acknowledgment before issuing a trademark infringement complaint to force the map's removal. This incident, alongside other recent security failures and widespread concerns about misuse, casts a harsh light on the true scope and inherent risks of mass surveillance technology.

The revelation of Flock's extensive camera network, derived directly from the company's own records, underscores profound implications for individual privacy and national security. Michael explicitly warned that such a pervasive system could be exploited to track key personnel, including military members, federal agents, and politicians, to and from sensitive locations. The dataset accompanying his map even includes individual camera names, frequently detailing street addresses and other identifying characteristics, creating a dangerously precise mosaic of movement patterns. This level of detail transforms public spaces into zones of continuous monitoring, challenging the very notion of a reasonable expectation of privacy, even when individuals are in plain sight.

This specific vulnerability is not an isolated incident but rather the latest in a series of alarming disclosures. Just this month, a hacker collective known as "stegan0gram" physically removed a Flock camera in Wisconsin, reverse-engineered it, and successfully extracted approximately 1.6 million images and 27,000 video clips captured over a 21-day period. Their findings revealed the camera was running an outdated Android 8.1 operating system with a security patch level from 2018, despite a June 2025 build date, leaving it vulnerable to known exploits. Furthermore, this stolen device demonstrated the cameras' ability to detect not only vehicles and license plates but also people, raising additional privacy concerns. Separately, another security researcher, YouTuber Benn Jordan, recently uncovered dozens of Flock cameras streaming live, unencrypted footage to the open internet without requiring passwords, exposing views of playgrounds, residential driveways, and police vehicles. While Flock characterized these as "configuration errors" and maintained its broader cloud network was not compromised by the stolen camera incident, critics argue these repeated failures highlight fundamental security shortcomings within a system designed for pervasive data collection.

Flock Safety, founded in 2017, has rapidly become a dominant force in the surveillance landscape, operating in over 6,000 communities across 49 U.S. states and performing more than 20 billion vehicle scans monthly as of July 2026. Its business model involves leasing AI-powered automated license plate recognition (ALPR) cameras and other surveillance hardware to law enforcement agencies, homeowner associations, and private entities on a subscription basis. Unlike some competitors who primarily target law enforcement, Flock's strategy of engaging private customers creates a dense, interconnected surveillance network that effectively enlists communities into a centralized government-accessible system. The company’s technology, built on AI and cloud integration, analyzes captured data for actionable insights, including vehicle make, model, color, and even unique identifiers like bumper stickers. This continuous innovation, as highlighted by Flock's own timeline of product launches including gunshot detection (2021) and solar-powered fixed video cameras (2024), underscores its ambition to create an ever-more comprehensive surveillance ecosystem.

However, this aggressive expansion comes at a significant cost to civil liberties. Critics, including the ACLU and EFF, have consistently described Flock's system as mass surveillance, arguing that it creates enormous databases of innocent motorists' location information, retained for years or indefinitely, with insufficient privacy safeguards. The sheer volume of data allows for the reconstruction of highly personal movement patterns, such as visits to medical facilities or places of worship, transforming vehicle data into deeply personal profiles. Compounding these architectural risks are documented instances of severe misuse by law enforcement. A review of media reports since 2024 by the Institute for Justice found 28 cases of officers abusing ALPR systems, including Flock's, to stalk former romantic partners. In August 2026, the Savannah Police Department fired six employees for misusing the system to search for friends and family. Furthermore, investigations have revealed instances of local police searching Flock's database to assist federal immigration enforcement without proper authorization, even in cities with non-cooperation policies. The Electronic Frontier Foundation (EFF) has directly accused Flock of misleading or lying about its business practices and commitment to privacy, concluding that abuses stem from the system's architecture itself, rather than just individual agency misuse. Even Flock's "Nova" platform, initially designed to integrate data from breaches and public records to track individuals without warrants, faced backlash and was scaled back.

The cumulative effect of these revelations is a growing public and governmental backlash. Cities like Mountain View, California, have already terminated their contracts with Flock after discovering unauthorized federal agency access to local camera data. The legal landscape is also shifting, with lawsuits like the one filed by the EFF and ACLU of Northern California in November 2025 challenging warrantless ALPR searches under constitutional privacy rights. These legal challenges, combined with increasing public scrutiny, suggest a future where the legality and ethical implications of pervasive ALPR networks will be rigorously tested.

In response to mounting criticism, Flock Safety announced operational changes in August 2026, including reducing its default data retention period from one month to one week, with an "Evidence Mode" for longer retention tied to specific case numbers. However, privacy advocates largely view these as superficial public relations maneuvers rather than fundamental shifts away from a problematic business model. The company's recent offer of a voluntary separation program for employees in September 2026, reportedly due to low morale, further signals internal challenges amidst the controversies.

The road ahead for Flock Safety and the broader surveillance technology industry will be defined by an escalating tension between public safety claims and fundamental privacy rights. Expect continued calls for stringent regulation, demanding greater transparency regarding data collection, retention, and sharing policies. The legal "mosaic theory," which suggests that continuous tracking through interconnected ALPRs could constitute a constitutional search requiring a warrant, will likely gain traction as these networks grow denser. Ultimately, the long-term viability of companies like Flock may hinge not just on their technological prowess, but on their ability to genuinely address, rather than merely mitigate, the profound privacy concerns inherent in their mass surveillance infrastructure.