The Flock camera incident was a physical compromise of one deployed device, not a demonstrated breach of Flock Safety’s centralized cloud platform. On September 16, 2026, findings from the recovered hardware showed that its local storage contained videos and still images, while an encryption key on the camera unlocked some of that media.

The hacker collective stegan0gram said it removed the camera from above a roadway and copied much of its local storage. Some of the most sensitive storage remained encrypted and inaccessible. Flock Safety said its cloud infrastructure had never been compromised and that no customer data had been accessed or exfiltrated through a cloud attack.

What the recovered Flock camera revealed

The camera ran Android and contained about 20 Flock-built applications for tasks including motion detection, image capture, object classification, uploads and remote updates. Two partitions named “vendor” and “media” were described as unencrypted. The “media” partition reportedly contained the key used to unlock stored videos and still images.

The recovered files showed a camera designed to collect more than a single plate snapshot. It captured rapid bursts of still images with different exposures, covering the license plate and the wider scene. A passing vehicle typically generated about 28 images; some generated more than 100.

Observed featureWhat was foundScope or condition
Local operating systemAndroidThe analyzed camera
Stored mediaVideos and still images were unlocked with a key found in the “media” partitionSome storage remained encrypted and inaccessible
Short video clips27,321 MP4 files, generally one to two seconds long1,024 × 768 pixels, without audio
Detected categoriesPeople, vehicles, license plates and bicyclesSome graphics, including bumper stickers and dealership frames, were also classified as plates
Processing splitThe camera captured, selected, cropped and transmitted imageryPlate reading and vehicle make, model and color identification appeared to occur on Flock’s servers

That division matters. The camera’s local hardware handled image capture and selection, while at least some of the interpretation happened after transmission. A local compromise could therefore expose raw or partially processed imagery without being the same event as an intrusion into the cloud service.

The scale of one camera’s recorded activity

Recovered logs covered about 21 days of activity across several periods. During those windows, the camera photographed roughly 50,200 vehicles and generated approximately 1.6 million images. A typical day contained about 3,300 vehicle detections, with a peak of 4,454.

Those figures describe one camera and its particular traffic environment. They do not establish the volume generated by every Flock installation. The logs also contained more than 27,000 “no space left on device” errors, a sign of how aggressively the device was handling its local storage.

The camera’s software included object-detection functions for people as well as vehicles, plates and bicycles. In testing, people appeared in only 11 of the 27,321 recovered short clips, and all 11 detections involved motorcycle riders. The downward view over roadway traffic shaped what the camera could see.

Person detection is not face recognition

The presence of person detection does not amount to active facial recognition. The analyzed camera software identified people as an object category, but the investigation found no evidence that face-recognition capabilities were enabled or actively used on the device.

The system also sometimes treated visual graphics as license plates. One reported example involved an American flag patch on a motorcyclist’s saddlebag being cropped as if it were a plate. That behavior points to broad image classification; it does not establish facial recognition.

What the findings show about Flock’s security

The central security issue is the boundary between the camera in the field and the cloud platform behind it. Flock Safety’s statement that its cloud infrastructure has never been compromised addresses the centralized service. The recovered key and media came from storage on a camera that had been physically removed.

Flock Safety said the unauthorized removal and tampering were illegal. The company also said it had not received a report through its vulnerability-disclosure process and lacked enough information to assess the hackers’ technical claims.

The incident followed earlier research by Jon “GainSec” Gaines, who documented root-level access flaws in a Flock Safety Falcon Sparrow automatic license-plate reader. Gaines published that research on June 19, 2025. The later recovery showed why physical access to deployed hardware can raise a different security question from access to a company’s online platform: data can remain exposed at the edge even when the central service has not been breached.

Flock Safety CEO Garrett Langley has described the company’s security posture as an ongoing commitment, while the company continues to distinguish its cloud infrastructure from the hardware installed beside the road.