Security

Hackers reverse-engineer Flock camera, expose mass image capture

Security researchers extracted data from a surveillance device, revealing it generated 1.6 million images from 50,000 vehicles in three weeks.

Omega Editorial· September 16, 2026· 3 min read

Hackers dissect Flock surveillance camera to reveal data collection scale

A group of security researchers physically removed a Flock automated license plate reader camera and reverse-engineered its hardware, uncovering the extent of data collection performed by the widely deployed surveillance technology.

The hacking collective stegan0gram shared their findings with Wired and 404 Media, which conducted a joint investigation into the camera's operation. The analysis revealed that over a 21-day period, a single camera photographed approximately 50,200 vehicles and generated roughly 1.6 million images.

According to the investigation, the camera typically captures around 28 images from each vehicle encounter, though some instances produced more than 100 images per vehicle. The device transmits photos and associated data to Flock's servers via cellular network, where the actual vehicle identification and license plate reading analysis occurs.

Technical capabilities exceed basic plate reading

The camera runs approximately 20 Flock-developed applications, including motion detection and data upload software. The investigation documented the system's ability to capture granular details beyond license plates—in one case, the camera detected an American flag patch on a motorcyclist's saddlebag.

Flock's technology combines license plate readers, video cameras, and audio detection devices into an AI-powered database. The system logs not only plate numbers but also vehicle characteristics including make, model, color, and identifying features like bumper stickers. Local law enforcement agencies can share this data across jurisdictions, creating an interconnected surveillance network.

"We liberated hardware in the field, disarmed them, and proceeded with reverse engineering of the cameras and associated solar equipment," one hacker affiliated with stegan0gram told the outlets. "Why just destroy them when we can reverse engineer them and find the secrets of those spying on us?"

Company responds, political debate intensifies

A Flock spokesperson told The Hill that "the unauthorized removal and tampering of a Flock camera is illegal." The company emphasized it maintains a public Vulnerability Disclosure Policy for security researchers to report potential vulnerabilities directly, and stated it received no report through that process. The spokesperson added that based on limited information provided, the company lacks sufficient detail to assess the claims.

The technology has sparked political controversy. Florida Governor Ron DeSantis expressed concern earlier this month that his state could become a "digital AI surveillance state where everything we're doing is being tracked at all times." Representative Thomas Massie introduced legislation called the Flock-Off Act aimed at restricting federal funding for automated license plate readers and biometric surveillance cameras.

President Trump voiced support for the technology, stating, "I sort of like them because of that, because of law enforcement. But some people don't. They think it's an infringement."

Why it matters

The reverse-engineering effort provides rare technical insight into how widely deployed surveillance infrastructure actually operates. While Flock markets its cameras as license plate readers, the findings demonstrate these devices function as comprehensive vehicle tracking systems generating millions of images and detailed vehicle signatures. As hundreds of jurisdictions deploy this technology, the scale of data collection and cross-agency sharing raises questions about surveillance oversight that extend beyond traditional license plate reading.

Details of the investigation were first reported by Wired and 404 Media.

#flock cameras#license plate readers#surveillance technology#reverse engineering#privacy#law enforcement technology

This is an original analysis by the Omega editorial team. Source reporting: AI Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

Attacker Hijacks AI Coding Assistant, Deploys Worm Across 100 Repos

Mandiant documents first known case of an adversary taking control of an active AI assistant session to poison dependencies and spread malware.

Via AI Watch · Sep 16, 2026
Security· 2 min read

GitHub AI Scan Now Works Without CodeQL Default Setup

The security feature expands to more repositories as GitHub removes a key configuration requirement for Advanced Security customers.

Via AI Watch · Sep 16, 2026
Security· 3 min read

OX Security Launches Cloud Platform With Live AI Agent Monitoring

New CNAPP combines traditional posture management with real-time detection of autonomous agents and non-human identities in production environments.

Via AI Watch · Sep 16, 2026