📷🔐 Stolen Flock camera unlocks 50,200 vehicles' plate data
One stolen Flock camera captured 50,200 vehicles in 21 days—and handed hackers the unencrypted key to its own footage.🔐 Hackers pried it down on Sep 18 and found the "media" partition held the key unlocking sensitive data. Flock says it needed physical access, not a network breach—but local attackers still won. Now the No FLOCK Act could withhold up to $100M/year in highway funding from states that won't restrict deployments. How safe is your plate data from one stolen device? 📷
On the morning of September 18, 2026, a hacker collective calling itself stegan0gram did something most attackers rarely bother attempting: they climbed up to a roadside Flock Safety camera, tore it down, and walked away with it. Physical theft of surveillance hardware is almost unheard of in the modern threat landscape, where criminals prefer silent remote breaches. But what the group extracted from that single device has ignited a policymaking firestorm and forced a reckoning over how America's biggest license-plate surveillance network actually protects the data it collects.
A 21-Day Window, Compressed Into Evidence
The math is what gives regulators pause. In just 21 days, that one camera generated approximately 1.6 million images—capturing roughly 50,200 vehicles—alongside 27,321 short MP4 video clips at 1024×768 resolution. Packages of 404 Media and WIRED, working with the data-leak clearinghouse Distributed Denial of Secrets, found the footage included not just vehicle detections but computer-vision identifications of people, bicycles, and even bumper stickers.
When the collective pried open the device, they discovered two storage partitions—one labeled "vendor," one labeled "media"—that were not encrypted. The "media" partition contained the encryption key that unlocked a third, encrypted partition holding the sensitive footage. Flock's marketing has long claimed end-to-end encryption; the incident indicates the algorithm protecting at-rest data could be bypassed locally once physical access was obtained, revealing a device running roughly 20 Flock-built applications spanning motion detection and automated uploading.
What Flock Says—and What Critics Found
Flock confirmed the encryption is in place but stressed the exploit required physical access, not a network intrusion. Critically, the hackers did not breach Flock's central servers, and some sensitive storage tiers remained encrypted. The company also noted that images are retained only briefly on-device before being forwarded to the cloud.
But the separate findings are more difficult to wave away. The theft built directly on research by security analyst Jon Gaines—known as "GainSec"—who had documented root-level access vulnerabilities in Flock cameras back in November 2025. And the precursor record is more damning still: in July 2026, researchers found unsecured Flock AI cameras with default credentials, granting attackers root access in under 30 seconds and enabling real-time remote viewing of vehicle movements. The scale of aggregation raises structural concerns: Flock's network spans more than 6,000 U.S. communities, interlinking license-plate data across 2,000-plus organizations. The OS Investigate AI tool can merge camera records with police and civilian databases, enabling cross-agency and even immigration-enforcement searches.
The Legislative Response
On September 16, two members of Congress introduced the "No FLOCK Act," which proposes withholding 10% of federal highway funding from states that fail to restrict Flock camera deployments—cuts of roughly $10 million to $100 million annually per state beginning October 2028. The bill lands amid documented civilian harm: police officers have reportedly used Flock to stalk romantic partners, and several towns have terminated contracts or wrapped cameras in makeshift covers after public backlash, with at least 53 U.S. cities rejecting the network outright.
What Comes Next
The exposure points to a hardening checklist for edge deployments:
- Encryption keys should be kept separate from the storage media they unlock
- Unattended devices need active tamper detection and rapid alerting
- Local CPU should not retain full decryption capability for stored recordings
- Retention windows must be tight, given how quickly a single device aggregates 1.6M images
For Flock and similar vendors, the incident demonstrates that "end-to-end encrypted" and "physically safe" are not the same promise. And for the estimated 50,200 vehicle owners captured in that one 21-day window, the footage now sits in the hands of strangers—a reminder that the strongest argument for tightening surveillance-device security begins with a single stolen camera.
Comments ()