A clandestine group of hackers has successfully removed a Flock Safety automated license plate reader (ALPR) from a public roadway, performed a comprehensive forensic dump of its internal storage, and shared the resulting data with researchers and media outlets. This act of hardware liberation, carried out by a collective identifying itself as stegan0gram, has peeled back the curtain on the proprietary technology used to track vehicles and individuals across the United States. The breach provides a rare, granular look into the internal mechanics of a surveillance system that the company has long characterized as secure and protected by robust, on-device encryption.

The incident, which involved the physical extraction of a camera followed by the recovery of encryption keys stored on the device, has yielded over a million images and thousands of video clips. This forensic analysis, conducted jointly by 404 Media and WIRED, challenges the narrative of technical invulnerability surrounding the widespread adoption of AI-enabled surveillance.

Chronology of the Breach and Discovery

The vulnerability of Flock’s hardware has been a subject of mounting interest among security researchers throughout 2025. In June 2025, security researcher Jon “GainSec” Gaines published a detailed breakdown of his efforts to reverse-engineer a Flock Falcon/Sparrow ALPR. Gaines successfully achieved root-level access to the device, documenting architectural flaws that could theoretically be exploited by individuals with physical access to the units.

Following the disclosure, Flock Safety issued a statement acknowledging the existence of the research but sought to minimize the threat. The company argued that the necessity of physical access rendered the vulnerabilities low-risk, asserting that even with root access, an attacker would be unable to retrieve stored footage because such data is transmitted to the cloud and purged from the device shortly thereafter.

The actions taken by the stegan0gram collective appear to directly refute these assurances. By extracting the device’s physical storage, the hackers bypassed the cloud-based security model. They successfully navigated an Android-based operating system partitioned into several segments. While some partitions remained encrypted, the hackers discovered that a "media" partition contained the very encryption keys necessary to unlock the device’s extensive collection of captured videos and still images. This suggests that the physical hardware remains a critical point of failure in the company’s broader security architecture.

Technical Analysis: What the Camera Sees

The forensic analysis of the recovered data reveals that the camera acts as a sophisticated, autonomous data-gathering node. The hardware, which utilizes processors comparable to those found in mid-range smartphones, runs roughly 20 proprietary applications. These apps manage tasks ranging from motion detection and object classification to data transmission and remote system updates.

Contrary to the common perception that the cameras perform real-time plate recognition at the edge, the logs indicate that the device focuses on rapid-fire image capture. When motion is detected, the camera generates a burst of images—typically around 28 per vehicle, though some events triggered over 100 frames. The system utilizes varying exposures to ensure both the license plate and the surrounding environment are clearly visible. These images are then cropped and uploaded via cellular networks to Flock’s central servers, where the heavy-duty computer vision processing occurs.

Perhaps most significant is the camera’s ability to detect humans. The software includes explicit models for identifying people, tracking their position within a frame, and assigning a confidence score to those detections. While Flock has maintained that its systems do not perform facial recognition, the presence of these detection models underscores the potential for repurposing the technology beyond simple license plate cataloging. In testing, the software was able to identify people in various scenarios, including individuals on motorcycles, highlighting that the "privacy by design" narrative is complicated by the inherent capability of the hardware to distinguish human subjects.

Data Volume and System Performance

The recovered logs offer a window into the sheer scale of the surveillance network. Over a 21-day period of recorded activity, the single device photographed approximately 50,200 vehicles, resulting in roughly 1.6 million images. Daily logs averaged 3,300 vehicle detections, with peak traffic days reaching over 4,400.

Interestingly, the logs also reveal a system struggling under the weight of its own operations. The device repeatedly encountered "no space left on device" errors, resulting in tens of thousands of crashes and system reboots. Interspersed among these critical failure logs were lines of code that appeared to be developer-inserted commentary, including the recurring phrase "Who’s a good boy?!" and a final, sarcastic sign-off during reboots: "¡Adiós, Amigos!" These internal logs paint a picture of a system that, while technologically advanced, is frequently pushed to its hardware limits.

Official Response and Legal Implications

Flock Safety has responded to the breach by characterizing the unauthorized removal of their property as a criminal act. A spokesperson for the company emphasized that they maintain a formal Vulnerability Disclosure Policy (VDP) intended for security researchers to report flaws in a controlled, legal manner. The company stated that no report regarding these specific vulnerabilities was filed through their official channels and that they require more technical detail before they can fully assess the claims made by the hackers.

"The unauthorized removal and tampering of a Flock camera is illegal," the company’s statement read. "If the individuals identified legitimate vulnerabilities, we encourage them to submit their technical findings through our vulnerability reporting process."

However, the hackers have expressed little interest in coordinating with the company. A member of stegan0gram stated that their objective was to "liberate hardware in the field" and uncover the secrets of a system they believe is being used for mass surveillance. The group remains concerned about law enforcement investigations but maintains that their actions are a form of political protest against the rapid, unchecked expansion of the "national network" of cameras.

The Broader Impact on Privacy and Public Trust

The incident comes at a time of intense scrutiny regarding the role of private companies in public law enforcement. Flock’s network is not merely a collection of local cameras; it is an interconnected ecosystem that allows agencies to share data across jurisdictions. Investigations by 404 Media and WIRED have previously shown how this network can be accessed by thousands of disparate organizations, including entities as varied as airport authorities and federal inspectors.

The controversy is further fueled by instances of misuse. Reports have documented police officers using the network to track individuals for reasons unrelated to the investigation of violent crime, such as monitoring access to abortion services or assisting federal immigration authorities in states that have sought to limit such cooperation.

Noel Pichardo, a former police officer and a vocal critic of the expansion of surveillance technology, warns that this act of sabotage may have unintended consequences. While he acknowledges the public frustration that drives such acts, he argues that vandalism may ultimately provide the state with a justification for increased security measures or more aggressive policing of the hardware itself.

"I think that type of vigilantism will only crystallize the police and the state at large in their belief that this tool is necessary," says Pichardo. "The longer the state continues to ignore the groanings of their constituents who are against this type of surveillance, the more this will happen."

As the debate over automated surveillance intensifies, the stegan0gram incident serves as a stark reminder of the fragile balance between public safety and the right to privacy. By treating the surveillance camera not as an untouchable government asset, but as a piece of reverse-engineerable hardware, the hackers have forced a public conversation about the security, capabilities, and ultimate reach of the systems that now monitor the nation’s roadways. Whether this leads to increased transparency or a new arms race of hardware hardening remains to be seen.

By