Flock Pressured to Remove Map of Its 300,000-Device Surveillance Network

Researcher’s map of 300,000 Flock devices drew a trademark complaint one day after a Senate surveillance hearing

Alex Barrientos Avatar
Alex Barrientos Avatar

By

Image: The Intercept

Key Takeaways

Key Takeaways

  • Researcher maps 300,000 Flock Safety devices, doubling the company’s publicly cited camera count.
  • Flock-related location data was accessible via unauthenticated endpoints for months before exposure was fixed.
  • Trademark complaint targeting the map arrived one day after a Senate surveillance hearing.

A cybersecurity researcher built the most detailed public map of Flock Safety’s surveillance app infrastructure using location data reportedly retrieved from publicly accessible, unauthenticated endpoints and described as originating in Flock’s own records. The map documented roughly 300,000 devices, a figure that dwarfs the company’s publicly cited camera count. One day after a Senate hearing scrutinizing Flock’s nationwide network, a trademark complaint arrived demanding the map come down.

What the Map Actually Found

The gap between 120,000 and 300,000 is not a rounding error.

Joshua Michael’s Flock Surveillance Map identified more than 170,000 cameras and approximately 130,000 supporting devices. Those include Falcon cameras, Picard processing units, networking equipment, third-party camera integrations, and roughly 27,000 acoustic detection devices. Flock publicly reports operating more than 120,000 cameras across 49 states, generating approximately 20 billion vehicle scans per month.

The dataset’s detail goes well beyond camera counts. One entry, labeled “FBI Pilot Camera,” appears at the coordinates of the J. Edgar Hoover Building in Washington, D.C. Another, tagged “C-F-23 FOXTROT MALE HOLDING 2/SHOWERS,” is mapped at coordinates corresponding to the Silverdale Detention Center in Chattanooga, Tennessee. Roughly 860 devices are shown near the Rosemont Public Safety Department, close to Chicago O’Hare International Airport. To spot-check Michael’s data, The Intercept visited six randomly selected locations in Arizona; a Flock camera was present at each one, though that check does not independently validate the full dataset.

The map’s methodology sets it apart from crowdsourced projects like DeFlock:

  • Data sourced from a December 2025 snapshot of Flock-related records, not community submissions
  • Access token discovered in November 2025 on a publicly accessible, unauthenticated endpoint
  • Token allowed queries to ArcGIS, a geographic-information platform used in the process, for device-location data
  • Michael emailed Flock on November 13, 2025; after three contact attempts, received one reply promising follow-up, then silence
  • Exposed access reportedly appears to have been fixed after Michael published his technical findings in January 2026

These cameras form a nationwide surveillance network that tracks where everyone drives.

Joshua Michael, cybersecurity researcher, as quoted by The Intercept

A “Breach” by Any Other Name

Flock says it has never been hacked; Michael argues that claim deserves scrutiny.

In a January 2026 blog post, Flock stated it has “never been hacked” and that its cloud platform has not experienced a data breach. Michael’s interpretation is that retrieving device-location data from an unauthenticated endpoint constitutes a security incident, regardless of whether core systems were penetrated. That dispute remains unresolved, with no independent legal or technical ruling classifying the event either way.

On Thursday, Michael received a trademark complaint from Doppel, an AI social-engineering defense company that claimed to act on Flock’s behalf. The complaint alleged unauthorized use of the “FLOCK SAFETY” trademark and risk of customer confusion, and it requested the site be taken down. Michael’s site carried a disclaimer stating no affiliation with Flock, and The Intercept reported that Flock did not immediately respond to a request for comment. A secretly tracking users pattern has drawn parallel scrutiny in other government-linked contexts.

Congressional Scrutiny Arrived the Day Before the Takedown Attempt

The Senate hearing and the trademark complaint landed less than 24 hours apart.

The Senate Judiciary Subcommittee on Crime and Counterterrorism held a hearing titled “Always Watching: Flock’s Nationwide AI Surveillance Network” on September 23, 2026. Flock’s CEO, along with the CEOs of Axon Enterprise, Motorola Solutions, and Verkada, were invited to testify; all reportedly declined to appear. Senators questioned whether Flock’s systems enable warrantless vehicle tracking, how data is shared across agencies, and whether existing oversight is adequate. San José Has a Flock Problem at the local level, where civic resistance to the network has also been building.

Flock has since announced it will reduce its standard data-retention period from 30 days to seven days. Officers will also reportedly be required to enter a justification and case number before running searches, according to UPI and NextGov. The American Civil Liberties Union has characterized Flock as misleading the public about its practices, safety record, and privacy commitments; that assessment belongs to the ACLU and has not been independently adjudicated.

The map identifies more devices than Flock’s publicly cited camera count suggests exist. The location data was reportedly accessible from publicly reachable endpoints from at least November 2025 until around the time of publication. The map that made all of this visible is now under takedown pressure following a trademark complaint, and what ultimately gets erased, and what stays visible, is worth watching closely.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →