Tech

Flock Safety’s Unexecuted Rideshare Data Plan and Water Utility Hacks Mark Security Week

Linxi News reviews the latest developments in corporate surveillance, critical infrastructure threats, and digital rights rulings.

Author
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: WIRED · original
Flock’s Plans for Rideshare Dashcams and Coaching Police, Revealed
Former employee alleges direct ICE access; cyberattacks expand to 12 states as US court strikes down cell tower data dumps.

Flock Safety proposed a controversial partnership with dashcam manufacturer Nexar to harvest license plate data from rideshare and delivery vehicles, a plan the company maintains was never implemented. According to a sales presentation obtained by 404 Media, the agreement would have utilised approximately 350,000 devices to create a "roving collection" network, shifting from Flock’s traditional fixed-pole surveillance. The company stated it did not proceed with the deal, which would have operated without driver knowledge, while Uber, Lyft, and Nexar declined to comment on the matter.

Compounding the scrutiny, former government affairs manager Jonathan Paz alleged that Flock had provided direct camera access to US Immigration and Customs Enforcement (ICE) and Customs and Border Protection (CBP) through a pilot program. Paz, who resigned in July 2025, claimed the company internally denied such cooperation while actively sharing feeds. Additionally, 404 Media obtained a coaching guide provided by Flock to police, instructing officers to privately brief city councils and frame arguments around the "cost of unresolved crime" rather than installation costs.

In the critical infrastructure sector, cyberattacks on US water utilities have expanded to at least 12 states, according to CBS News. The Clayton County Water Authority in Georgia experienced pressure drops and issued a boil-water advisory following an intrusion by suspected Iran-backed hackers. While service was restored within hours, several utilities lost remote control of their systems, forcing operators to manage pumps and valves manually. Federal agencies have advised disconnecting industrial controllers from the internet.

Corporate security disclosures highlighted a breach at IEH Corporation, a Brooklyn-based supplier of defence components. The company reported that a phishing email containing a fake Microsoft file-sharing link compromised its Microsoft 365 environment. The intruder accessed engineering documentation and customer correspondence, including technical data potentially subject to US export controls. IEH, which supplies components for the Patriot air-defence system and AMRAAM missiles, reported no evidence of data exfiltration but noted the breach was discovered on August 4.

In legal and enforcement developments, a US federal judge ruled that cell tower dumps violate the Fourth Amendment. US District Judge Carlton Reeves held that the practice, which compels carriers to hand over records of every device connected to a tower, is unconstitutional. Separately, Maksim Silnikau, the operator of the Ransom Cartel ransomware group, was sentenced to 16 years in prison. Silnikau, who fled Spain before arrest in Poland, ran an operation that targeted at least 18 companies between 2021 and 2023.

Continue reading

More from Tech

Read next: Open-source tool claims 97 per cent token savings for AI agents
Read next: Valvoline Unveils August 2026 Promotional Offers for Service and Retail Buyers
Read next: Developer Antirez releases native MiniMax H3 inference engine for Apple Silicon