Skip to content
Live Intelligence
Clash Report
World

Hackers Expose How Flock Mass Surveillance Works

Hackers removed and reverse-engineered a Flock roadside camera, recovering an encryption key and data showing how the device captures vehicles, detects people, and generates about 1.6 million images over several weeks.

Clash Report
A Flock camera on the road - NYT
16 Sept 2026 · 14:36 GMT · 3 MIN READ
Google Search

Choose Clash Report as a preferred source and see our reporting first in Top Stories.

Hackers who removed a Flock Safety camera from above a roadway have extracted much of its software and stored data, offering a detailed look at how the device captures vehicles and detects people.

The group, calling itself stegan0gram, recovered an encryption key stored on the camera and used it to unlock videos and images covering thousands of vehicle detections.

The group shared the files with 404 Media, WIRED, and Distributed Denial of Secrets.

Their analysis showed that while some sensitive storage remained encrypted, they could recover large amounts of material on the device.

“Why just destroy them when we can reverse engineer them and find the secrets of those spying on us?” one member of stegan0gram said.

1.6 Million Images

About 21 days of recoverable logs showed the camera recording roughly 50,200 vehicles and generating about 1.6 million images.

A typical day produced around 3,300 vehicle detections, while the highest recorded daily figure was 4,454. Older logs had either been overwritten or were no longer recoverable.

Rather than taking a single photograph, the camera captured vehicles in rapid bursts.

A typical passing vehicle generated about 28 images, although some triggered more than 100. The system used different exposures to capture both license plates and the wider scene.

The software then selected and cropped useful frames before transmitting them, along with other data, to Flock over a cellular connection.

Analysis indicated that the camera itself did not appear to read license plate numbers or determine vehicle make, model, and color.

Those functions appeared to take place on Flock's servers.

Software Detects People

The recovered software also showed that Flock's camera explicitly detects people alongside vehicles, plates and bicycles.

When it identifies a person, the system records where they appear in an image and assigns a confidence score to the detection.

WIRED extracted the camera's computer-vision models and tested them on images and recovered footage. The models could identify people, including in a reporter's selfie.

They also ran the models against 27,321 short video clips stored on the device. People were detected in 11 clips, all involving motorcycle riders.

The small number was attributed to the camera's position above a roadway, where pedestrians were unlikely to pass through its field of view.

Flock has said its cameras do not carry out facial recognition. The analysis found no evidence of active facial-recognition functions beyond capabilities included by default in Android.

Detector Misidentified Graphics

The software's license plate detector also sometimes classified other objects as plates.

Bumper stickers, dealership frames and graphics were occasionally isolated and cropped.

In one motorcycle video, the system treated an American flag patch attached to a saddlebag as though it were a license plate.

The recovered code showed that the camera ran about 20 Flock-built applications responsible for functions including motion detection, photography, object classification, uploading data, and receiving remote updates.

Its processor was similar to those used in midrange smartphones.

Encryption Key Recovered

The hackers said they gained access to the camera's Android system and examined its storage partitions.

Some areas were unencrypted, including partitions labeled “vendor” and “media.”

The latter contained an encryption key that unlocked another section holding much of the camera's video and image material.

The findings follow earlier research by security researcher Jon “GainSec” Gaines, who reverse-engineered a Flock license-plate reader in early 2025 and identified flaws that could provide root-level access.

Flock acknowledged those findings but said physical access was required and that an attacker “would still not be able to gain access to footage” because images remained on the device only briefly after transmission.

The material recovered by stegan0gram included stored videos and still images.

Flock Responds

“The unauthorized removal and tampering of a Flock camera is illegal,” a Flock spokesperson said.

The company said it had not received a vulnerability report from the hackers and lacked sufficient information to assess the claims involving the encryption key.

“Flock takes security seriously and maintains a public Vulnerability Disclosure Policy for security researchers to report potential vulnerabilities directly to us,” it said.

The hackers said they planned to publish details of how they accessed the system, hoping others could reproduce the work.

The recovered logs also showed repeated storage problems. More than 27,000 “no space left on device” errors appeared while the camera tried to save full-resolution images, along with large numbers of crashes and reboots.

A monitoring process checking whether the camera was functioning repeatedly logged the message: “Who’s a good boy?!”

About the Author

Ahmet Koçak

Clash Report

Ahmet Koçak is a news editor at Clash Report based in Istanbul. He previously served as Deputy Managing Editor at Türkiye Today, helping launch the digital news platform in 2023, and spent three years as Senior Editor at Daily Sabah. His work focuses on breaking news, geopolitics, international affairs, and digital journalism.

Google Search

Choose Clash Report as a preferred source and see our reporting first in Top Stories.

0:00
0:00
Now playing · ClashPoint
EP 147

When the front line moves overnight

Guest: Daniel Reyes
0:00
0:00