Tech

Flock camera breach exposes scale of vehicle and people tracking

Analysis by WIRED and 404 Media found one camera generated about 1.6 million images of 50,200 vehicles over 21 days and shared access extended to more than 2,000 agencies.

Editorial persona
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: WIRED · View original source
Collage of surveillance cameras, traffic footage, binary code, programming text, and red-yellow graphic elements.
SURVEILLANCE

A hacker collective allegedly removed a Flock Safety camera, copied much of its stored data and recovered an encryption key held on the device, giving WIRED and 404 Media access to videos, logs and software from the automatic number plate reader.

The joint analysis found that the camera recorded roughly 1.6 million images involving about 50,200 vehicles across 21 recovered days. A typical passing vehicle generated about 28 images, while some produced more than 100. Older logs had been overwritten or were unrecoverable, meaning the camera likely recorded more activity than the recovered material shows.

The camera’s software explicitly detected people, bicycles, vehicles and number plates. In testing, WIRED found people in 11 of 27,321 short video clips, all involving motorcyclists. The analysis also found instances in which bumper stickers, dealership frames and other graphics were mistaken for number plates, including an American flag patch on a motorcycle’s saddlebag.

Flock cameras photograph passing vehicles and send images and associated data to the company’s servers, where number plates and vehicle characteristics appear to be identified. The company’s national network allows other agencies to search records beyond the jurisdiction that owns a camera. Recovered material indicated that records from cameras in Alpharetta, Georgia, were accessible to more than 2,000 agencies, including police departments, colleges and airports.

The findings add to scrutiny of Flock’s surveillance network, following earlier reporting that searches had been conducted on behalf of US Immigration and Customs Enforcement and in an abortion investigation. WIRED and 404 Media found no evidence that face recognition was active in the camera’s software, beyond capabilities included by default in Android.

The recovered logs also recorded more than 27,000 “no space left on device” errors, alongside crashes and reboots. Flock said the unauthorised removal and tampering of its camera was illegal, and that it had received no vulnerability report and lacked enough information to assess the claims.

Continue reading

More from Tech

Read next: WIRED updates 2026 Android phone buying guide with Pixel, Galaxy and Fairphone picks
Read next: Breville’s Eye Q toaster puts colour sensors ahead of the timer
Read next: Sony introduces PlayStation Pulse headsets with planar magnetic drivers