Key Takeaways
- A hacker collective called stegan0gram pulled a Flock Safety license-plate camera off a roadside pole and recovered an encryption key sitting unprotected on the device — but much of the camera's most sensitive storage stayed locked, so only a slice of what it recorded was actually exposed.
- The alleged unlocked data covered just 21 days: about 1.6 million images and 27,321 video clips of roughly 50,200 vehicles, plus evidence the camera scores people and bicycles even though no working facial-recognition tool was found.
- Flock Safety, now valued at roughly $8.3 billion, calls the camera's removal illegal and says no one reported the flaw through its official disclosure channel; a bipartisan bill in Congress and a stalled FTC request are both pushing back on the company's security record from separate directions.
A hacking collective calling itself stegan0gram climbed a utility pole, unbolted a Flock Safety license-plate camera, and copied nearly everything stored inside it. What they allegedly found was an encryption key sitting in an unprotected section of the device's storage — a key that unlocked roughly three weeks of the footage Flock has spent years telling police departments and city governments was safe from exactly this kind of tampering. The group shared its haul with 404 Media and WIRED, which spent weeks combing through the files before publishing their joint findings on September 16.
The timing is not incidental. Flock's cameras now sit in more than 6,000 U.S. communities, and the company has spent the past several months fending off contract cancellations, officer-misuse scandals, and a fresh wave of state and federal legislation aimed squarely at how license-plate readers are allowed to operate.
What the Hackers Reportedly Actually Got Their Hands On
The camera's internal storage, investigators found, is split into several partitions. Two of them — nicknamed "vendor" and "media" — turned out to carry no encryption whatsoever. Tracing the failure to the "media" partition, the team found it was holding the exact key needed to unlock a separate, supposedly protected vault of recorded video and photos, according to a breakdown of the leaked files by Gadget Review. In practice, that meant physical possession of the hardware was enough to defeat a safeguard the company had defended publicly for years.
Not the Whole Vault — A Distinction That Matters
What didn't happen is just as important as what did. The joint analysis found that the device's most sensitive encrypted storage stayed out of reach, and nothing in the reporting suggests the hackers ever touched Flock's cloud systems, where the bulk of the company's nationwide footage archive actually lives. This was a breach of one physical device's local cache, not a demonstrated compromise of Flock's central network — a distinction Flock itself has leaned on in response, even as it concedes the local flaw is real.
Once inside the device, the reporters catalogued roughly 20 in-house Android applications running on hardware no more powerful than a mid-tier smartphone — code for detecting motion, snapping photos, classifying objects, pushing images out over a cellular connection, and pulling down remote updates. A single passing vehicle could trigger dozens of frames, averaging 28 shots per car and occasionally exceeding 100. Notably, the vision software doesn't stop at plates: it tags people and bicycles with a location and a confidence score, a capability largely absent from public conversation about these devices until now. Flock maintains its cameras don't perform facial recognition, and the analysis found no active face-recognition components running — but the object-detection net is wider than most residents likely assume. In one case, it mistook an American flag patch on a motorcyclist's saddlebag for an actual license plate, according to NewsNation's coverage of the findings.
The device's age compounds the concern: the camera runs on Android 8.1, an operating system that stopped receiving security patches in 2021 — meaning the hardware has been running for years without updates to a foundation Google itself no longer maintains.
One Camera, a National Search Network
The compromised unit fed directly into Flock's national search feature — the capability the company markets hardest to police departments. In Alpharetta, Georgia, a city of roughly 67,000 people, earlier WIRED reporting found local camera footage reachable by more than 2,000 outside agencies, including police departments, universities, airports, and even a federal inspector general's office. DDoSecrets co-founder Emma Best, whose organization received a copy of the leaked data alongside the two news outlets, argued the episode exposes a structural flaw rather than a one-off mistake: hardware deployed in public is "inescapably vulnerable to physical or electronic interference and intrusion."
This Wasn't the First Warning Flock Received
Independent security researcher Jon Gaines had already flagged root-level access flaws on a Flock device back in 2025, though the company argued at the time that stored footage stayed out of reach regardless of physical access. Gaines returned to the issue the day after the WIRED/404 Media story broke, publishing an updated assessment that found 23 of his previously disclosed findings remained unremediated more than a year later. One stegan0gram member framed the group's actions as protest rather than theft, telling reporters: "We liberated hardware in the field, disarmed them."
Flock's Response — and Washington's Move
Flock has called the camera's removal illegal and said no one reported the vulnerability through its formal channel for security researchers, asking the hackers to submit their findings there instead. The company had already begun tightening its practices before this story broke: in August, it cut default footage retention from 30 days to seven and rolled out an AI-powered search tool for police that can cross-reference plate data against arrest records, case files, and other personal information.
Congress, separately, is moving on its own timeline. The day before the hack story became public, Reps. Raja Krishnamoorthi (D-IL) and Michael Cloud (R-TX) introduced the bipartisan No FLOCK Act, which would withhold a share of a state's federal highway funding unless it restricts license-plate readers to a narrow set of approved uses. And in a separate, older effort, Sen. Ron Wyden and Rep. Krishnamoorthi sent a letter to the FTC in November 2025 urging an investigation into Flock's lack of mandatory multi-factor authentication for police accounts — a request the agency has not publicly acted on.
The Business Behind the Cameras
Flock traces its origin to 2017, when Garrett Langley, frustrated by a string of unsolved break-ins in his own Atlanta neighborhood, decided the traditional license-plate readers on the market — which ran roughly $25,000 apiece — were priced out of reach for most communities. Building cheaper, solar-powered, cloud-connected cameras with co-founders Matt Feury and Paige Todd, Langley turned that idea into a company now valued at roughly $8.3 billion. This week's teardown suggests that lower price point came with a security trade-off the company is now being forced to answer for in public.