CRBC News
Security

Hackers Reverse-Engineer Flock Camera, Reveal Massive Vehicle Tracking and 1.6M Images

Hackers Reverse-Engineer Flock Camera, Reveal Massive Vehicle Tracking and 1.6M Images
Flock security camera (Credit: Flock security camera | Photo courtesy: commercepros / Shutterstock.com)

Hackers who dismantled a Flock Safety camera report the device photographed about 50,200 vehicles and produced roughly 1.6 million images over 21 days. Typical vehicle passes yielded about 28 images, and some encounters generated over 100 images. Investigators say license-plate recognition and vehicle analysis appear to run on Flock's servers, not on the camera. The findings have intensified privacy concerns and prompted political scrutiny, including a congressional inquiry and calls for tighter oversight.

Hackers who removed and reverse-engineered a Flock Safety surveillance camera say their hardware and software analysis reveals the extensive scale of vehicle data the system collects. The group, calling itself stegan0gram, shared its findings with Wired and 404 Media after dismantling the device in the field.

Over a 21-day period, the researchers report the camera photographed roughly 50,200 vehicles and produced about 1.6 million images. A typical vehicle pass generated about 28 images, while some encounters produced more than 100 images. The camera transmits photographs and related telemetry over a cellular connection to Flock's systems.

Where Analysis Happens

Investigators found that license-plate recognition and deeper vehicle analysis appear to occur on Flock Safety's servers rather than on the camera itself, meaning the edge device primarily captures and forwards large volumes of imagery and metadata for remote processing.

"Why just destroy them when we can reverse engineer them and find the secrets of those spying on us?" a member of stegan0gram told Wired and 404 Media. "We liberated hardware in the field, disarmed them, and proceeded with reverse engineering of the cameras and associated solar equipment."

Company Response and Legal Concerns

A Flock spokesperson told The Hill that "the unauthorized removal and tampering of a Flock camera is illegal." Benzinga reported that the company did not immediately respond to a separate request for comment. The disclosures come amid broader scrutiny of Flock Safety, which uses Automated License Plate Recognition (ALPR) systems in its cameras.

Political and Privacy Fallout

An OpenSecrets analysis cited in reporting found Flock spent nearly $2 million on lobbying since 2025, including roughly $1.3 million on federal lobbying and about $1 million at statehouses. The company has retained former government officials as lobbyists, a detail highlighted by critics concerned about oversight and influence.

Lawmakers have expressed concern over the technology. Sen. Josh Hawley (R-Mo.) opened an investigation into Flock's nationwide license-plate camera network over access to Americans' vehicle data and potential abuses. Sen. Bernie Sanders (I-Vt.) described the system as "AI mass surveillance," warning it could be used to track citizens' movements. Rep. Greg Steube (R-Fla.) urged lawmakers to ban the devices, arguing they threaten Fourth Amendment protections.

Why It Matters

The reverse-engineering disclosure adds concrete detail to debates about how ALPR-equipped cameras gather, process, store and share vehicle data. Key concerns include the volume of images collected per encounter, how long images and metadata are retained, who can access the data, and what safeguards exist to prevent misuse by private companies or law enforcement.

As cameras and AI-based analysis tools proliferate, the incident underscores the need for clearer policy on data minimization, transparency, retention limits and independent oversight for systems that can capture extensive information about people’s movements.

Reporting: Wired, 404 Media, The Hill, Benzinga; image courtesy commercepros / Shutterstock.com.

Help us improve.

Related Articles

Trending