A recent, unprecedented breach of public surveillance infrastructure has ignited a firestorm of controversy regarding the privacy and security standards of Flock Safety, the provider of widespread automated license plate reader (ALPR) systems. A collective of hackers known as stegan0gram physically removed a Flock camera from its mount above a public roadway, performed a comprehensive data dump, and successfully reverse-engineered the device’s internal software. The resulting investigation, conducted in collaboration with 404 Media and WIRED, reveals that these cameras track far more than just vehicles, utilizing sophisticated computer-vision algorithms to identify pedestrians, cyclists, and even specific graphic patterns on personal property.

The breach serves as a watershed moment in the growing movement against ubiquitous municipal surveillance. By bypassing the company’s touted "on-device encryption," the hackers gained access to thousands of high-resolution images and logs, providing a granular look at the data collection practices that have previously been opaque to the public.

The Anatomy of the Breach and Data Recovery

The incident began when members of stegan0gram physically liberated a Flock camera from its installation site. Once in their possession, the hackers bypassed the device’s security protocols by exploiting the Android-based architecture powering the unit. While Flock Safety has consistently marketed its cameras as being protected by robust, end-to-end encryption, the hackers discovered that several critical system partitions—specifically those labeled "vendor" and "media"—remained unencrypted.

Within the media partition, the hackers identified an encryption key that granted them access to the device’s primary storage. This allowed for the extraction of internal logs covering roughly 21 days of operation. During this three-week window, the single camera captured approximately 50,200 vehicles and generated 1.6 million images. The logs also revealed a history of hardware instability, with the device recording over 27,000 "no space left on device" errors, indicating that the hardware often struggled to manage the massive volume of data it was tasked with processing.

Technical Capabilities: Beyond License Plates

One of the most significant findings from the forensic analysis is the camera’s capability to detect and track entities other than vehicles. While the company frequently frames its mission as a tool for public safety—specifically for the identification of license plates and stolen vehicles—the software analysis confirms that the device is programmed to detect pedestrians and bicyclists as well.

The computer-vision models extracted from the device were tested against the recovered dataset. They successfully identified people in multiple video clips, including a motorcyclist whose saddlebag featured an American flag patch, which the software erroneously tagged as a potential license plate. This tendency to misidentify non-vehicle objects as license plates highlights the potential for "false positives" in the system, which could lead to unnecessary scrutiny of innocent citizens whose property or clothing features patterns resembling vehicle tags.

Crucially, the analysis suggests that the actual heavy lifting of plate recognition occurs on Flock’s centralized servers rather than the camera itself. The device functions as a high-frequency capture node, taking rapid bursts of images—sometimes exceeding 100 photos per vehicle—which are then uploaded via cellular networks to the cloud for processing and storage.

A Chronology of Security Concerns

This incident is not the first time Flock Safety’s infrastructure has been scrutinized for its security architecture. The timeline of public concern regarding these devices has accelerated over the past year:

  • Early 2025: Security researcher Jon "GainSec" Gaines released a comprehensive report detailing how to gain root-level access to the "Falcon" and "Sparrow" models of Flock’s license plate readers.
  • Mid-2025: Following Gaines’ disclosure, Flock Safety acknowledged the potential for physical tampering but minimized the risks, claiming that unauthorized access would not grant an intruder access to stored footage.
  • August 2025: Investigative reporting reconstructed parts of Flock’s "OS Investigate" (formerly "Nightshift") software, revealing how the system integrates with other police databases to map the movement of citizens across cities and states.
  • Late 2025: The stegan0gram breach occurred, providing physical evidence that contradicts the company’s previous claims regarding the security of on-device data.

The National Network and Public Controversy

The hardware breach comes at a time when the "National Network" of Flock cameras—which allows police agencies across the country to share and search data—is facing severe legislative and ethical pushback. The network has grown to include over 2,000 organizations, ranging from local law enforcement and college police departments to entities as disparate as federal inspectors general.

The integration of these cameras into a national database has enabled controversial cross-jurisdictional surveillance. Previous reports have documented instances where police officers used the network to track individuals on behalf of Immigration and Customs Enforcement (ICE) in cities that had officially prohibited such cooperation. In another documented case, a Texas law enforcement officer utilized the network to track a woman who had traveled out of state to obtain an abortion. These incidents have sparked a national debate over the necessity and the potential for abuse of such a powerful, interconnected surveillance apparatus.

Official Responses and Industry Defense

In a statement provided following the disclosure of the breach, a spokesperson for Flock Safety emphasized the illegality of the act, stating: "The unauthorized removal and tampering of a Flock camera is illegal." Regarding the security flaws, the company maintained that they operate a formal Vulnerability Disclosure Policy (VDP) intended for researchers to report issues through official channels. "We received no report through that process," the company added, "and based on the limited information provided, we do not have enough detail to assess the claims being made."

The company maintains that it does not engage in facial recognition, a claim supported by the forensic analysis of the software, which showed no active or enabled facial recognition features. However, the presence of the capability within the base Android operating system—even if dormant—leaves critics uneasy about how easily such features could be toggled via a remote software update.

Broader Implications for Municipal Surveillance

The incident raises fundamental questions about the balance between public safety and the right to privacy in the digital age. Noel Pichardo, a former police officer and a vocal critic of the expansion of surveillance technology, argues that while the frustration of activists is understandable, the act of sabotage may prove counterproductive. "I think that type of vigilantism will only crystallize the police and the state at large in their belief that this tool is necessary," Pichardo noted. He suggests that the ongoing reliance on high-tech surveillance by local governments reflects a failure of civic dialogue, where the "groanings of constituents" are ignored in favor of technological quick-fixes for crime.

From a policy perspective, the breach highlights the risk of "data over-collection." By gathering millions of images that include pedestrians, cyclists, and non-target graphics, Flock is essentially creating a searchable database of the physical world. If the security of this data can be undermined by physical access to a single camera, the entire infrastructure becomes a liability rather than an asset.

As municipalities continue to weigh the costs and benefits of deploying these systems, the stegan0gram incident provides a stark reminder that the hardware installed on our street corners is not just a passive sensor—it is a sophisticated, data-rich computer that, once compromised, can reveal the patterns of a community’s daily life. The industry now faces increased pressure to prove that its commitment to security is more than just a marketing slogan, and that the data it collects is truly protected from the very people—and potential malicious actors—who live and move beneath these lenses every day.

By