Hackers Cracked a Flock Camera. Here Is What Was Inside.

One physical camera removal exposed 50,200 vehicles, 1.6 million images, and encryption keys stored on the device itself

Al Landes Avatar
Al Landes Avatar

By

Image: Deposit Photos

Key Takeaways

Key Takeaways

  • Hackers recovered 1.6 million images from one Flock camera, exposing weak on-device encryption.
  • Flock camera records reach over 2,000 agencies, enabling cross-jurisdictional surveillance without local consent.
  • Flock’s OS Investigate tool merges plate data with Social Security numbers, arrest records, and movement patterns.

One camera. Twenty-one days of logged activity. Roughly 50,200 vehicles photographed and approximately 1.6 million images generated. That is what a single Flock Safety license plate reader produces in three weeks, according to data recovered by a hacker collective and analyzed jointly by 404 Media and WIRED.

Flock cameras now operate in more than 6,000 communities across the United States, feeding a national network accessible to thousands of agencies. Until this hack, the internal mechanics were entirely opaque to the public.

How the Hack Happened

Physical access to one roadside camera was enough to expose the encryption model Flock had publicly defended.

A group calling itself stegan0gram physically removed a Flock Safety camera from above a roadway, copied its internal storage, and shared the data with 404 Media and the transparency collective Distributed Denial of Secrets, which then provided it to WIRED for joint analysis.

The camera runs Android across multiple storage partitions. Two of them, labeled “vendor” and “media,” were unencrypted. The “media” partition contained an encryption key that unlocked a separate encrypted partition holding the camera’s videos and still images.

That finding directly contradicts Flock’s public position that on-device encryption protects footage even if someone gains physical access, because the key was recoverable from the device itself, according to 404 Media.

Earlier in 2025, security researcher Jon “GainSec” Gaines had already documented root-level access vulnerabilities in a Flock camera. Flock downplayed the severity at the time, arguing stored footage remained out of reach. The stegan0gram dump challenges that claim.

Inside the Camera: What the Data Shows

The recovered files reveal a sophisticated on-device computer-vision pipeline that Flock’s marketing materials do not fully describe.

The device runs roughly 20 custom Flock-built Android apps, covering motion detection, image capture, object classification, cellular upload, and remote firmware updates. Its processor is comparable to a midrange smartphone.

Each time something moves into frame, the camera fires a burst of photos, typically around 28 images per passing vehicle, with some events generating more than 100. It uses different exposure settings within each burst to optimize both plate legibility and broader scene capture.

The on-device software explicitly detects people, recording their location in the frame and a confidence score when a person appears. Researchers found people detected in 11 short video clips from the recovered data, all motorcycle riders, likely because the camera’s angle was aimed at road traffic rather than sidewalks.

The license plate detection model casts a wide net. Tests by WIRED and 404 Media found it misclassifying bumper stickers, dealer frames, and decorative graphics as plates. In one instance, an American flag patch on a motorcycle saddlebag was cropped as if it were a license plate.

Full plate reading and vehicle attribute identification, including make, model, and color, happen on Flock’s servers after upload, not on the camera itself. Flock maintains that its cameras do not perform facial recognition, and the joint analysis found no evidence of active face-recognition components beyond default Android libraries that did not appear to be enabled.

The logs also offer a window into the system’s internal culture. A watchdog process logged “Who’s a good boy?!” more than 12,000 times as it checked that the camera was still running. On reboot, a service signed off with “A reboot was requested! Adiós, Amigos!” The informal tone of the code contrasts sharply with the scale of law-enforcement use the system supports.

A National Network, Thousands of Agencies

Camera records installed by one local agency can be searched by thousands of others across the country.

Once images are uploaded, Flock’s system creates timestamped records linking a vehicle to a specific camera location, with plate, color, make, and model attached. In many deployments, that data is not confined to the local agency that owns the camera.

In Alpharetta, Georgia, camera records were reportedly accessible to more than 2,000 agencies, according to WIRED. That list included police departments, colleges, airports, and the Office of Inspector General for the General Services Administration.

Reporting by 404 Media has documented local police using the national network to conduct searches on behalf of Immigration and Customs Enforcement. This occurred even in jurisdictions that formally prohibit transferring license plate data out of state. In one case, a Texas officer searched nationwide Flock cameras for a woman who self-administered an abortion.

Separately, WIRED obtained frontend code for Flock’s AI tool OS Investigate, previously called Nightshift. The tool merges camera records with police case files, 911 logs, arrest records, ballistics data, and commercial identity databases including Social Security numbers, birth dates, and known relatives. It ships with 69 pre-written AI prompts and supports movement-pattern searches, meaning officers can secretly tracking users look for people without starting from a known plate or name.

stegan0gram has framed its work as activist reverse engineering, arguing that the goal is exposure rather than destruction. One member told reporters that being investigated is a “legitimate concern” and that the group works carefully to stay low-profile.

Multiple people across the country have been arrested for allegedly tampering with Flock cameras, and some towns have ended their contracts. At least one police department deployed a 3D-printed decoy camera shell to catch vandals.

The architecture is now documented. The encryption model has been tested and found wanting. What communities and agencies choose to do with that information is the question that remains unanswered.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →