A reported physical compromise of one Flock Safety camera exposed local videos, still images and an on-device encryption key—but it did not establish a breach of Flock Safety’s centralized cloud platform. The camera had been removed from above a roadway, and the recovered storage revealed how much data one installation could capture over roughly 21 days.
Flock Safety says its cloud infrastructure has never been compromised and that no customer data was accessed or exfiltrated through a cloud attack. That statement addresses a different part of the system from the storage physically recovered from the camera.
What the recovered Flock camera revealed
The device ran Android and contained about 20 Flock-built applications for motion detection, image capture, object classification, uploads and remote updates. Two local partitions, named “vendor” and “media,” were described as unencrypted. The “media” partition reportedly contained a key that unlocked stored videos and still images.
Much of the most sensitive storage remained encrypted and inaccessible. The recovered material therefore offers a substantial view of one camera’s operation, not a complete copy of everything it had ever stored.
The camera generated rapid bursts of still images as vehicles passed. A typical vehicle produced about 28 images, while some produced more than 100. Separate MP4 clips were generally one to two seconds long, measured 1,024 by 768 pixels and contained no audio.
| Observed feature | Reported result | Scope or condition |
| Local operating system | Android | Recovered camera |
| Typical images per vehicle | About 28 | Passing vehicles; some generated more than 100 |
| Recovered short clips | 27,321 MP4 files | Generally one to two seconds; 1,024 × 768 pixels; no audio |
| Person detections | 11 clips | All 11 involved motorcycle riders |
| Storage errors | More than 27,000 | “No space left on device” messages in the recovered logs |
| Status messages | More than 12,000 | Included “Who’s a good boy?!” |
The camera appeared to capture, select, crop and transmit imagery. Plate reading and the identification of vehicle make, model and color appeared to take place on Flock Safety’s servers. In other words, the roadside hardware and the cloud service performed different jobs—and compromising one does not automatically mean compromising the other.
How much data was captured?
During the recovered activity windows, the camera photographed roughly 50,200 vehicles and generated approximately 1.6 million images over about 21 days. A typical day included around 3,300 vehicle detections, with a peak of 4,454.
Those figures describe one camera operating in one location. Traffic volume and camera placement vary, so they cannot be treated as totals for Flock Safety’s wider network.
The volume also explains why a single vehicle could produce so many files. The system used rapid image bursts with different exposures, capturing both the license plate and a wider view of the scene rather than taking one conventional snapshot.
Person detection is not face recognition
The camera software explicitly detected people, vehicles, license plates and bicycles. It also classified some graphics as possible plates, including bumper stickers and dealership frames. In one reported example, an American flag patch on a motorcyclist’s saddlebag was cropped as if it were a plate.
Testing found people in 11 of 27,321 recovered short clips. All 11 detections involved motorcycle riders, and the camera’s downward angle over roadway traffic shaped what appeared in the footage.
That is person detection: identifying a human-shaped subject in an image or clip. It is not the same as recognizing a person’s face or matching that face to an identity. Active face recognition was not established in the analyzed camera software.
What the incident does—and does not—show about Flock’s security
The reported findings show that physical access to one deployed camera led to the recovery of local media and a key that reportedly unlocked some of it. They do not show that Flock Safety’s centralized cloud database was breached, nor do they establish that every Flock camera stores an accessible key in the same way.
Flock Safety called the unauthorized removal and tampering of a camera illegal. The company also said it had not received a vulnerability report through its public disclosure process and did not have enough information to assess the technical claims.
The distinction matters because “the cloud was not breached” does not mean that local hardware is irrelevant. A system can protect its central service while still exposing sensitive material at a device deployed in the field. Conversely, a local compromise does not by itself prove access to the company’s cloud platform.
Earlier security context
In June 2025, Jon “GainSec” Gaines published research describing root-shell access to a Flock Safety Falcon Sparrow automatic license-plate reader after physical access to the device. That earlier work concerned device access and preceded the later recovery of local camera data.
The September investigation was also separate from a January 2026 exposure involving a different Flock product line: Condor cameras with an unsecured debug interface. Treating those incidents as one breach would blur distinct hardware, access paths and system boundaries.
For readers concerned about surveillance infrastructure, the practical consequence is straightforward: securing the cloud is only one layer of the problem. The camera on the pole, its local storage and the software handling captured imagery all deserve scrutiny—especially when one device recorded roughly 1.6 million images in a little over three weeks.