Hackers Stole Flock's Camera Software and Exposed How It Tracks Cars and People Nationwide
404 Media and WIRED analyzed firmware from a stolen Flock Safety ALPR camera. Recovered logs show about 50,200 vehicles and 1.6 million images over about 21 days, plus on-device people detection.

404 Media (Joseph Cox and Dhruv Mehrotra, 16 September 2026) and WIRED published a joint investigation of firmware and data taken from a physically removed Flock Safety automatic license plate reader. A collective calling itself stegan0gram pulled a roadway camera down, copied its storage, and shared the haul with 404 Media, Distributed Denial of Secrets, and WIRED.
This is a joint investigative report. It is not a CVE advisory, and it is not a Flock product launch.
The hackers recovered an encryption key from an unencrypted on-device partition labeled "media" and used it to unlock detection videos and stills. Much of the camera's most sensitive storage stayed encrypted or inaccessible. The published analysis covers what could be opened.
On-device software explicitly detects people as well as vehicles, plates, and bicycles. 404 Media and WIRED found no evidence of face recognition beyond unused Android defaults. People detections in recovered roadway clips were rare because the camera pointed down at traffic, not because people-detection code is missing.
Recovered logs cover about 21 days of activity windows. In those windows the device photographed about 50,200 vehicles and generated about 1.6 million images. A typical day logged about 3,300 vehicles, with a high of 4,454. A typical pass produced about 28 images.
The camera runs an Android-like stack with about 20 Flock-built apps. Plate OCR and make, model, and color appear to run in Flock's cloud, not on the device. Logs also recorded more than 27,000 "no space left on device" errors and a heartbeat message, "Who's a good boy?!", about every two minutes.
In Alpharetta, Georgia, WIRED found city Flock records searchable by more than 2,000 agencies. Prior 404 Media reporting, separate from this dump, tied national-network lookups to ICE and to an out-of-state abortion search.
Flock said unauthorized removal and tampering is illegal, that it lacked enough detail through its vulnerability disclosure policy, and that researchers should file there. Critics of ALPR networks disagree on whether sabotaging cameras helps or hurts the policy fight. Physical theft remains illegal either way.
Related privacy and tracking tape includes Meta's invasive kid prompts, the US military disabling ad trackers on issued devices, and the suspected IDScan leak of 153 million IDs.
Cities and agencies renewing Flock contracts should demand written limits on national search sharing and on-device key storage, and treat "plates only" marketing as incomplete given explicit people detection in the software.
Subscribe to Techpresso
Free daily newsletter, read in 5 minutes.
Subscribe free