ZeroHour
Story · 2 sources · 2 articlesfirst updated ()

Hackers Rip Down a Flock Safety Camera, Exposing Its Unencrypted Encryption Key and the Scale of Vehicle Surveillance

mediumData breachexploited in the wildimportance 60
What's new: First merged summary for this story. The newly dumped camera software and data, shared with 404 Media, WIRED, and Distributed Denial of Secrets as of 2026-09-16, reveals an encryption key stored unencrypted on the device (contradicting Flock's on-device encryption claims), quantifies the camera's surveillance output (roughly 1.6 million images of about 50,200 vehicles over 21 days per WIRED), and…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Hacker collective stegan0gram stole a Flock Safety license plate reader, copied its storage, and recovered an encryption key stored in an unencrypted partition, unlocking roughly 1.6 million images of about 50,200 vehicles captured over 21 days and revealing…

Hackers from the collective stegan0gram physically removed a Flock Safety automatic license plate reader from a roadway, copied its storage, and shared the files with 404 Media, WIRED, and Distributed Denial of Secrets. Analysis found an encryption key stored in an unencrypted 'media' partition that unlocked videos of thousands of vehicle detections, despite Flock's claims of on-device encryption protection. Per WIRED, the camera generated roughly 1.6 million images of about 50,200 vehicles over 21 days, or about 3,300 vehicles photographed daily (404 Media's log analysis put it at more than 1 million images in weeks). The on-device computer vision detects people, bicycles, and bumper stickers in addition to license plates, while plate and vehicle identification happen on Flock's servers, not the camera; the device runs about 20 Flock-built apps. Records from the camera's city, Alpharetta, Georgia, were searchable by more than 2,000 agencies nationwide, including federal offices (WIRED); 404 Media reported the access included ICE-linked lookups. The dump follows 2025 research by Jon 'GainSec' Gaines documenting flaws enabling root-level access to Flock cameras, which Flock downplayed.

  • Hacker collective stegan0gram physically removed a Flock Safety license plate reader camera from a roadway and copied its storage, sharing the data with 404 Media, WIRED, and Distributed Denial of Secrets.
  • An encryption key stored in an unencrypted 'media' partition unlocked videos of vehicle detections, despite Flock's claims of on-device encryption protection.
  • WIRED: the camera generated roughly 1.6 million images of about 50,200 vehicles over 21 days, roughly 3,300 vehicles photographed daily; 404 Media's analysis of the logs put the total at more than 1 million images in weeks.
  • On-device computer vision detects people, bicycles, and bumper stickers in addition to license plates.
  • Plate and vehicle identification happen on Flock's servers, not the camera; the device runs about 20 Flock-built apps.
  • Flock camera records in Alpharetta, Georgia were searchable by more than 2,000 agencies nationwide, including federal offices (WIRED); 404 Media reported the lookups included ICE-linked access.
  • The findings follow 2025 research by Jon 'GainSec' Gaines documenting flaws enabling root access to Flock cameras, which Flock downplayed.

Coverage timeline

  1. · 1h ago
    WIRED · Security· 60
    Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works

    Hackers stole a Flock Safety camera, copied its storage, and recovered an encryption key exposing vehicle surveillance data and system internals.

  2. · 1h ago
    404 Media· 48
    Hackers Stole Flock’s Camera Software, Revealing How the Company Tracks Cars and People

    Hackers who removed a Flock Safety license plate camera dumped its data, revealing person-detection capabilities and an encryption key stored unencrypted on the device.