At least 60 Flock Safety surveillance cameras were found streaming live video to the open internet — no password, no encryption, thirty days of archived footage viewable in any browser by anyone who stumbled onto the URL, according to researchers cited by PetaPixel and deflockilm.org. That alone would be alarming. Flock isn’t some neighborhood doorbell operation, though. The company operates over 100,000 AI-powered license plate readers across the United States, feeding a centralized cloud database that logs where your car goes, when, and how often. The security failures run from the hardware all the way up to the architecture itself.
Thirty Seconds to Root Access
Physical exploits make these cameras trivially easy to compromise — and what comes next is worse.
Security researchers Jon Gaines of GainSec and filmmaker Benn Jordan demonstrated something genuinely unsettling: pressing a specific button sequence on the back of a Flock camera activates a diagnostic Wi-Fi hotspot, often protected by the default password “security.” Root access via ADB — Android Debug Bridge, a standard developer tool — follows in under 30 seconds. Once inside, an attacker can pull footage, install malware, exfiltrate credentials, or repurpose the camera as a device that silently intercepts and alters data passing through it. A public safety tool becomes a spy device. Documented vulnerabilities and misuse cases tell the fuller story:
- 60-plus cameras streaming live with zero authentication, accessible via browser URL
- Root access demonstrated in under 30 seconds through physical button press and default password
- Compromised devices allow footage alteration, credential theft, and full weaponization
- A Texas sheriff’s officer searched more than 83,000 Flock cameras across multiple states to track a woman suspected of self-administering an abortion, according to reporting compiled by the Institute for Justice
- Flock’s contract language permits data disclosure based on the company’s own “good faith belief” — no warrant required
The EFF called Flock’s system “designed to enable mass surveillance and susceptible to grave abuses,” according to its 2025 investigation summary.
Who’s Watching Your Commute
Federal agencies accessed local camera data — often without the cities that paid for it knowing.
Flock’s “national lookup” feature lets a single query touch tens of thousands of cameras when toggled on. Florida records obtained by WUFT showed officers logging searches as “Assist ICE” and “immigration” — directly contradicting Flock’s public FAQ claiming ICE has no access to its systems. According to TechTimes, 53 cities have now canceled or refused Flock deployments over unauthorized federal data sharing.
Flock maintains that all data is encrypted via AWS and that customers control access. The ACLU counters that Flock’s move to integrate commercial surveillance app data brokers — specifically to “jump from LPR to person” — makes earlier assurances that plate data wasn’t personally identifiable look, at best, outdated. Washington state’s SB 6002, effective March 2026, now imposes strict ALPR use, sharing, and retention limits with civil and criminal penalties. That law exists because the status quo had become genuinely uncontrolled.
Your daily route — church, clinic, rally, gun range — is logged, searchable, and accessible to agencies you never authorized. Those are terms you never signed. Washington’s law is a start. It covers one state.





























