Hackers Take Apart a Flock Safety Camera

A group of hackers has physically removed and reverse-engineered a roadside camera made by Flock Safety, the company behind one of the largest automated license plate reader (ALPR) networks operating across American roads. According to the reporting, the hackers recovered an encryption key from the device along with internal data that shows exactly how these cameras capture vehicles, detect people, and process the footage they collect. The find is notable because Flock Safety has publicly stated that its cameras have never been hacked. This incident, whatever its scale, directly challenges that claim and opens a rare window into a surveillance system that most drivers encounter daily without ever seeing how it actually works.

Flock cameras are mounted along streets and highways in thousands of communities, quietly photographing license plates and, as the recovered data reportedly shows, also detecting people in frame rather than just vehicles. That detail matters. Flock has long marketed its technology as a license plate tool for law enforcement, but data pulled from the hacked device suggests the system's capabilities extend further into identifying and logging individuals, not just cars.

How the Flock Camera Network Actually Works

Understanding why this matters requires understanding what Flock cameras are designed to do. Each unit captures images of passing vehicles, reads license plates, and feeds that information into a searchable database that law enforcement agencies can query. Because the cameras are networked, a single search can theoretically trace a vehicle's movement across multiple jurisdictions over time, effectively building a travel history without a warrant tied to any specific investigation.

The hackers' reverse-engineering effort matters because it exposes the technical guts of that process. Recovering the encryption key that protects data on the device suggests the security protecting this footage was not as robust as the company has claimed. When encryption meant to protect sensitive surveillance data can be cracked by outside researchers pulling a single unit off a pole, it raises legitimate questions about how well the broader network, and the millions of records it generates, is actually protected from unauthorized access.

It also raises a bigger question that has followed license plate reader technology for years: who else could access this data, and under what oversight? Mass surveillance infrastructure built for law enforcement doesn't exist in a vacuum. Once a network is built and proven vulnerable to tampering, the conversation shifts from theoretical privacy concerns to concrete security failures that citizens have no way to detect or opt out of.

What This Means For You

Most people don't choose to interact with a Flock camera. They simply drive past one, often without ever knowing it captured their plate, their location, and now apparently images of them as a person. That passive, unavoidable nature of ALPR surveillance is exactly what makes this disclosure significant. Unlike signing up for an app or accepting a cookie banner, there's no consent mechanism here. The infrastructure exists on public roads and captures anyone who passes.

The revelation that a single camera could be physically removed and its encryption defeated should prompt a broader look at how surveillance vendors secure the data they collect, not just how they market their crime-fighting benefits. It's a pattern that echoes other stories about how state-linked or state-adjacent surveillance tools can be turned against ordinary people when security is treated as secondary to functionality. Reporting on Iran's Telegram-based spyware campaigns targeting journalists and dissidents shows a similar dynamic: tools built for monitoring can become instruments of broader intrusion once their protections fail or are deliberately weakened.

For everyday drivers, there isn't a simple way to avoid ALPR cameras entirely since they are embedded in public infrastructure across many communities. But awareness is still useful. Knowing that this kind of surveillance exists, how it's supposed to work, and how it can fail gives residents a basis for asking local officials and law enforcement agencies harder questions about data retention policies, access controls, and whether encryption and security audits are actually being enforced rather than just advertised.

Key Takeaways

This incident is a reminder that mass surveillance systems are only as trustworthy as the security engineering behind them. A company's public assurance that its devices have never been compromised means little once independent researchers demonstrate otherwise. Readers concerned about ALPR networks in their area can look into whether their local police department has a public policy on Flock Safety camera data retention and sharing, since many jurisdictions publish this information upon request. It's also worth staying informed about ongoing privacy and civil liberties investigations into automated license plate readers, as oversight and legal challenges continue to evolve. Ultimately, stories like this one underscore why independent security research matters: it's often the only way the public learns how surveillance technology actually behaves once it's deployed at scale.