Hackers Extract Flock Camera Data, Reveal People-Tracking Code
Activists reverse-engineered a stolen surveillance camera and published encryption keys, exposing software that explicitly detects pedestrians alongside vehicles.
Surveillance camera torn down and reverse-engineered
A hacker collective calling itself stegan0gram physically removed a Flock Safety camera from above a roadway, extracted nearly all data stored on the device, and shared the files with journalists and transparency advocates. The breach offers the most detailed public look yet at how Flock's automated license plate readers function—and what they actually detect.
The group recovered an encryption key stored directly on the camera, which unlocked videos showing thousands of vehicle detections. They shared the material with 404 Media and the nonprofit Distributed Denial of Secrets, which provided it to WIRED. The two outlets jointly analyzed the recovered files, according to details first reported by WIRED and 404 Media.
"Why just destroy them when we can reverse engineer them and find the secrets of those spying on us?" one member of stegan0gram said in an interview with the outlets.
Software explicitly detects people, not just plates
Analysis of the camera's code revealed that Flock's software actively detects people in addition to vehicles, license plates, and bicycles. When the system spots a person, it records their location in the frame and assigns a confidence score to the detection.
During roughly 21 days of logged activity, the camera photographed approximately 50,200 vehicles and generated about 1.6 million images. A typical passing vehicle triggered 28 photos, though some produced more than 100 frames. The device's computer-vision software also isolated bumper stickers and other graphics—in one case cropping an American flag patch on a motorcyclist's saddlebag as if it were a license plate.
WIRED tested the detection models against footage recovered from the device. The models identified people in 11 of 27,321 short video clips stored on the camera, all showing motorcycle riders. The low detection rate likely reflects the camera's overhead position, where pedestrians rarely appear.
No face-recognition capabilities were found beyond default Android system features, which did not appear to be active.
National network controversy deepens
Flock cameras send images to company servers, where the system reads plates and identifies vehicle characteristics. These time-stamped records become searchable by the owning agency—and often by thousands of other departments nationwide through Flock's national network.
In Alpharetta, Georgia, WIRED found that records from city cameras were accessible to more than 2,000 agencies, including police departments, colleges, airports, and federal offices.
This data-sharing has sparked controversy. Previous reporting revealed that local police performed searches on behalf of Immigration and Customs Enforcement, including in jurisdictions that banned such cooperation. In another case, a Texas officer searched Flock cameras nationwide for a woman who self-administered an abortion.
Why it matters
The breach demonstrates that Flock's on-device encryption can be bypassed with physical access, contradicting the company's security assurances. More significantly, the explicit people-detection capability has been largely absent from public discussions about these cameras, which are typically framed as license plate readers only. As communities debate whether to deploy or remove Flock systems, this technical evidence shows the surveillance extends beyond vehicle tracking. The hackers published their methodology hoping others will replicate their work—a direct challenge to the expanding network of automated surveillance cameras.
Company response and ongoing sabotage
Flock said the unauthorized removal and tampering is illegal. The company stated it takes security seriously and maintains a vulnerability disclosure policy, but received no report through that process. Flock added it lacks enough detail to assess the claims and encouraged the hackers to submit technical findings through official channels.
The incident follows a pattern of camera sabotage nationwide. Multiple people have been arrested for allegedly tampering with Flock devices. Some towns have stopped using the cameras entirely, while one police department created a fake 3D-printed camera case to catch vandals.
Security researcher Jon Gaines reverse-engineered a Flock reader in early 2025 and documented flaws allowing root-level access. Flock acknowledged those findings but downplayed their severity, noting they required physical access.
Details of the hack and analysis were first reported by WIRED and 404 Media.
This is an original analysis by the Omega editorial team. Source reporting: WIRED.
Want systems like this working for your business?
Book a Call
