The Flock camera incident was a physical compromise of one deployed device, not a demonstrated breach of Flock Safety’s centralized cloud platform. On September 16, 2026, findings from the recovered hardware showed that its local storage contained videos and still images, while an encryption key on the camera unlocked some of that media.
The hacker collective stegan0gram said it removed the camera from above a roadway and copied much of its local storage. Some of the most sensitive storage remained encrypted and inaccessible. Flock Safety said its cloud infrastructure had never been compromised and that no customer data had been accessed or exfiltrated through a cloud attack.
What the recovered Flock camera revealed
The camera ran Android and contained about 20 Flock-built applications for tasks including motion detection, image capture, object classification, uploads and remote updates. Two partitions named “vendor” and “media” were described as unencrypted. The “media” partition reportedly contained the key used to unlock stored videos and still images.
The recovered files showed a camera designed to collect more than a single plate snapshot. It captured rapid bursts of still images with different exposures, covering the license plate and the wider scene. A passing vehicle typically generated about 28 images; some generated more than 100.
| Observed feature | What was found | Scope or condition |
| Local operating system | Android | The analyzed camera |
| Stored media | Videos and still images were unlocked with a key found in the “media” partition | Some storage remained encrypted and inaccessible |
| Short video clips | 27,321 MP4 files, generally one to two seconds long | 1,024 × 768 pixels, without audio |
| Detected categories | People, vehicles, license plates and bicycles | Some graphics, including bumper stickers and dealership frames, were also classified as plates |
| Processing split | The camera captured, selected, cropped and transmitted imagery | Plate reading and vehicle make, model and color identification appeared to occur on Flock’s servers |
That division matters. The camera’s local hardware handled image capture and selection, while at least some of the interpretation happened after transmission. A local compromise could therefore expose raw or partially processed imagery without being the same event as an intrusion into the cloud service.
The scale of one camera’s recorded activity
Recovered logs covered about 21 days of activity across several periods. During those windows, the camera photographed roughly 50,200 vehicles and generated approximately 1.6 million images. A typical day contained about 3,300 vehicle detections, with a peak of 4,454.
Those figures describe one camera and its particular traffic environment. They do not establish the volume generated by every Flock installation. The logs also contained more than 27,000 “no space left on device” errors, a sign of how aggressively the device was handling its local storage.
The camera’s software included object-detection functions for people as well as vehicles, plates and bicycles. In testing, people appeared in only 11 of the 27,321 recovered short clips, and all 11 detections involved motorcycle riders. The downward view over roadway traffic shaped what the camera could see.
Person detection is not face recognition
The presence of person detection does not amount to active facial recognition. The analyzed camera software identified people as an object category, but the investigation found no evidence that face-recognition capabilities were enabled or actively used on the device.
The system also sometimes treated visual graphics as license plates. One reported example involved an American flag patch on a motorcyclist’s saddlebag being cropped as if it were a plate. That behavior points to broad image classification; it does not establish facial recognition.
What the findings show about Flock’s security
The central security issue is the boundary between the camera in the field and the cloud platform behind it. Flock Safety’s statement that its cloud infrastructure has never been compromised addresses the centralized service. The recovered key and media came from storage on a camera that had been physically removed.
Flock Safety said the unauthorized removal and tampering were illegal. The company also said it had not received a report through its vulnerability-disclosure process and lacked enough information to assess the hackers’ technical claims.
The incident followed earlier research by Jon “GainSec” Gaines, who documented root-level access flaws in a Flock Safety Falcon Sparrow automatic license-plate reader. Gaines published that research on June 19, 2025. The later recovery showed why physical access to deployed hardware can raise a different security question from access to a company’s online platform: data can remain exposed at the edge even when the central service has not been breached.
Flock Safety CEO Garrett Langley has described the company’s security posture as an ongoing commitment, while the company continues to distinguish its cloud infrastructure from the hardware installed beside the road.