At first glance, a Flock Safety camera is just another piece of hardware perched above a roadway—a sleek, unblinking box designed to read license plates and log every passing car. To its manufacturer, it is a precision crime-fighting tool, protected by encryption and carefully attuned to local privacy rules. But a group of hackers has forced a closer look. They tore a Flock camera down from its pole, made a near-complete copy of the data inside it, and handed those files to 404 Media and WIRED through the transparency nonprofit Distributed Denial of Secrets. The collective behind the operation, calling itself stegan0gram, says it is also publishing the technical details of how it cracked the camera, hoping that other people will follow the same path. What emerged is an unusually detailed view of a surveillance system that Flock Safety has long described as protected by on-device encryption. The hackers recovered an encryption key stored directly on the device, unlocked videos and stills of thousands of vehicle detections, and shared the material with journalists who then analyzed it as part of a joint investigation. The camera produced a mountain of images, and the findings challenge the company’s carefully polished story. “Why just destroy them when we can reverse engineer them and find the secrets of those spying on us?” one of the hackers asked. “We liberated hardware in the field, disarmed them, and proceeded with reverse engineering of the cameras and associated solar equipment.” Because Flock’s cameras are wired into a national network, the significance of this breach reaches far beyond a single stolen device. It raises questions about a system that quietly watches millions of drivers and passengers, and about whether the company’s security claims hold up when the hardware is in hostile hands.
The technical reality the hackers uncovered is messier and more revealing than Flock’s marketing suggests. The camera runs on Android, and once the hackers gained access to its file system they found several partitions—distinct sections of its storage. A few of these were unencrypted, including one labeled “vendor” and another labeled “media.” That second partition contained a critical piece of the puzzle: an encryption key that unlocked another storage area, where the camera kept much of the material it had recorded. What was inside? A stream of images and logs documenting vehicle movements in granular detail. According to the recovered files, the software running on the device explicitly detects people as well as vehicles, license plates, and bicycles. It can capture dozens of stills of a single passing car, and over a period of several weeks the logs show it generated more than a million images. The software also isolated bumper stickers and other graphics—including, in one case, an American flag patch sewn onto a motorcyclist’s saddlebag. That kind of attention goes well beyond reading a plate; it suggests the device is constantly making decisions about what in the world around it is worth recording. To be fair, the most sensitive parts of the device’s storage remained encrypted and inaccessible, so the full architecture of Flock’s backend is still hidden. But the fact that a camera on a pole is quietly building a picture of people and their belongings, not just plates, is exactly the kind of detail stegan0gram wanted to expose. It also shows that the actual behavior of these cameras is more expansive than the public pitch might lead people to believe. The images on the device were not abstract data points; they were fragments of ordinary life, captured without consent and stored in a box that the company promised was locked tight.
For Flock’s critics, this kind of breach has been a long time coming. Across the country, multiple people have been arrested for tampering with or otherwise sabotaging Flock cameras. Some towns have announced that they are going to stop using Flock’s cameras altogether, and in one case, a police department even made a fake, 3D-printed Flock camera case in order to bait potential vandals. But stegan0gram represents a different ethos. Rather than simply smashing a camera or spray-painting its lens, they wanted to understand it, dismantle it, and share what they found. Their stated hope is that other people will follow the same trail, turning isolated acts of vandalism into a broader movement of reverse-engineered resistance. The distinction matters. Destroying one camera is a protest; publishing the way to break into all of them is a challenge to the entire surveillance apparatus. The hackers’ decision to release their methods means that police departments and the company itself will have to respond not just to one stolen device, but to the idea that Flock’s hardware can be cracked open and displayed for public inspection. It also hands ordinary people a set of technical facts that Flock would probably prefer remain obscure—starting with the uncomfortable truth that protection relies on an encryption key that sits on the very device the company is trying to secure. The company’s hoped-for image of hardened infrastructure crumbles somewhat when the emergency hatch is literally on the outside, waiting for someone with enough curiosity to open it. That may be the most important lesson of the entire operation: surveillance is not invincible, and the more complex it becomes, the more ways there are to look inside.
Understanding why this matters requires understanding how Flock works. The cameras take photos of passing vehicles and send them to Flock’s servers. There, Flock’s system presumably reads the license plate and analyzes characteristics like color, make, and model. Those time-stamped records are then made searchable for the local agency that installed the cameras. But Flock also sells access to a national network, meaning cameras in one city can be searched by police departments all over the country. In Alpharetta, Georgia, for example, the records from that city’s Flock cameras were accessible to more than 2,000 agencies—not just local police, but colleges, airports, and, for reasons nobody could quite explain, the Office of Inspector General for the federal General Services Administration. That nationwide reach has become a central selling point for Flock: a single camera becomes a node in a huge, interlocking system of surveillance that can follow a vehicle across state lines without any single officer leaving their desk. It is also a source of deep controversy, because it means that the data captured by one community’s cameras doesn’t really belong to that community. It belongs to a network, and that network is available to an enormous range of law enforcement and government entities, many with no obvious connection to the roadway where the camera sits. The privacy implications are staggering: a car that drives through a small town in Georgia could be logged, retained, and searched months later by an agency in a different state, for reasons the driver will never know. Flock has tried to frame this as a benefit—more eyes, more safety—but the more details emerge, the more it looks like an unaccountable, distributed surveillance net thrown over ordinary life.
The controversy is not theoretical. Investigative reporting has already shown how the national network can be abused. 404 Media revealed that local police officers were performing license plate lookups on behalf of Immigration and Customs Enforcement, including in jurisdictions that had explicitly banned working with immigration authorities or transferring plate data out of state. In another case, a police officer in Texas used Flock’s national search tools to look for a woman who had self-administered an abortion. These incidents are not small glitches; they are examples of how a tool originally marketed as a simple license plate reader can become a means of tracking individuals in deeply invasive ways. They helped ignite a national conversation about whether automatic license plate readers—and Flock cameras in particular—belong in American communities. Some people argue that the cameras solve real crimes and return stolen property; others see an infrastructure of suspicion that treats every driver as a potential suspect. For the hackers at stegan0gram, the answer is unmistakably no. Their actions turned that no into something more than a slogan. By pulling a camera down and exposing the assumptions built into it, they showed that surveillance systems are not inevitable pieces of infrastructure. They are objects, placed by people, with weaknesses, and they can be taken apart—both physically and intellectually. That is an uncomfortable proposition for a company whose business model depends on the public coming to see its cameras as innocuous parts of the roadside. The more people know about what these boxes actually do, the harder it becomes to sell them as neutral tools.
What ultimately remains after this breach is a complicated picture. Flock’s cameras are not invincible: the device relies on an encryption key stored in its own memory, and once someone with enough determination gets physical access, that key is there for the taking. At the same time, the cloud-based backend that makes Flock’s national network possible remains closed, and the most sensitive layers of the system were not exposed. But that may not matter. The hackers have already demonstrated that a single camera can be pulled down, copied, and turned into evidence in the court of public opinion. They have shown that a device which police describe as a crime-fighting tool can just as easily be described as a spy post on a street corner, watching vehicles and people and even the patches on their saddlebags. The files shared with 404 Media and WIRED are now part of a public record, and the hackers say their instructions for replicating the process will be published too. Whether that leads to more attacks, more arrests, more town council debates, or more honest conversations about how much surveillance we want, the ground has shifted. Flock can no longer assume that its hardware is opaque. The next person who looks at one of those cameras on a pole might not just be annoyed by it. They might be imagining what is inside—and, after this hack, they may be right to do so. The camera above the roadway was supposed to be watching. But for one moment, at least, the watchers were watched, and the machinery designed to track movement was shown to be just another piece of technology that people can understand, dismantle, and refuse.