Hackers removed a Flock camera from above a roadway and copied its internal data, sharing the recovered files with 404 Media and WIRED. The device was designed to watch passing traffic, and it kept everything it saw.
The breach exposes a simple truth about surveillance hardware: it is not inert. Cameras record, but they also process, store, and transmit data. When that chain breaks, the secret is out.
The Data Recovery
The hackers recovered an encryption key stored on the device. That key unlocked videos of thousands of vehicle detections. The camera detected vehicles, license plates, bicycles, and people. Its computer-vision software also isolated bumper stickers and other graphics, including an American flag patch on a motorcyclist’s saddlebag.
The recovered logs spanned about 21 days of activity. The camera photographed roughly 50,200 vehicles and generated about 1.6 million images, with a daily high of 4,454 vehicles. The device took a rapid series of photos when something moved into view, generating about 28 images per vehicle, though some produced more than 100.
The camera’s processor resembles those in midrange smartphones. It runs about 20 Flock-built apps handling detection, image-taking, object classification, data upload, and remote updates. The camera’s logs recorded about 21 days of activity.
“Why just destroy them when we can reverse engineer them and find the secrets of those spying on us?”
That question came from a hacker from a collective called stegan0gram. The hackers are publishing details on how they obtained the software to encourage others to copy their methods.
The Data Chain
Flock’s cameras photograph passing vehicles and send images and data to the company’s servers, where the license plate is read and vehicle characteristics like color, make, and model are identified. The national network allows searches by more than 2,000 agencies, including police departments, colleges, airports, and the Office of Inspector General for the federal General Services Administration in Alpharetta, Georgia.
Security researcher Jon “GainSec” Gaines reverse-engineered a Flock license-plate reader in early 2025, documenting flaws that could grant root-level access. Flock acknowledged the flaws but downplayed their severity, saying they required physical access and that images remained on the device only briefly before transmission to the cloud.
The breach exposes the gap between design and reality. The device held more than a million images over several weeks of recovered logs.
The National Network
Flock’s national network is a feature, not a flaw. The company sells visibility across thousands of agencies. The breach also raises questions about the data itself. What happens to the millions of images when they are shared?
The recovered logs show weeks of data stored in place, not long-term retention.
What Happens Next
The hackers are publishing their methods. That is a deliberate act, not an accident. They want others to copy what they did.
The security community now has a working example of how to break into a Flock camera. The company’s response to the Gaines research was dismissive.
The breach also raises questions about the data itself. What happens to the millions of images when they are shared?
| Stage | Detail |
|---|---|
| Breach | Hackers removed a Flock camera from above a roadway |
| Key recovery | Encryption key recovered, unlocking videos of thousands of detections |
| Data analysis | 404 Media and WIRED analyzed recovered files |
| Log timeline | About 21 days of activity, 1.6 million images |
| Daily high | 4,454 vehicles in a single day |
The breach is a reminder that surveillance hardware is not neutral. It watches, but it also stores, processes, and transmits. When that chain breaks, the secret is out.
The paper notes that Flock’s national network is a feature, not a flaw, and that 404 Media has exposed ICE lookups and searches tied to abortion cases. The hack exposes both sides’ stakes: Flock loses its claim of secure devices, while critics lose their claim that cameras are merely passive recorders.
Where the paper stands
The paper backs citizens and local groups pushing back against surveillance hardware like Flock cameras, and is against the vendors lobbying to keep such systems in place. The breach exposed the gap between how Flock designs its cameras and how they actually work — storing millions of images for weeks before transmitting them. That gap undercuts the company’s claims about security and privacy.
The paper supports the hackers’ efforts to publish their methods, seeing it as a deliberate pushback against surveillance vendors. It also tracks Flock’s record on privacy, including prior reporting of ICE lookups and searches tied to abortion cases through the company’s systems.
Readers should watch for how Flock responds to this breach. The company previously dismissed similar findings from security researcher Jon “GainSec” Gaines, downplaying the severity of flaws that could grant root-level access. A repeat of that dismissal would show the same pattern of dismissing independent scrutiny.
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

