“Why just destroy them when we can reverse engineer them and find the secrets of those spying on us?” one hacker told 404 Media.
The hacker belongs to a collective called stegan0gram. The group pulled a Flock Safety camera down from above a roadway and copied almost all of its data. It shared the files with 404 Media and the nonprofit Distributed Denial of Secrets. That group passed them to WIRED. The two outlets analysed the data together and published their findings on 16 September. The hackers say they are also publishing details of how they got the software, so that others can copy them.
On the same day, two members of Congress announced a bill. It would push states to restrict Flock cameras and other licence plate readers.
An encryption key stored on the device
Flock has described its cameras as protected by on-device encryption. The hackers told 404 Media they got into the camera’s Android system. They found several unencrypted partitions, including ones called “vendor” and “media”.
The “media” partition held an encryption key. That key unlocked another section containing much of the video and still images the camera had taken. Much of the device’s most sensitive storage stayed encrypted, according to the joint analysis.
In 2025, security researcher Jon Gaines reverse engineered a Flock reader and documented flaws that could give root access. Flock acknowledged those findings at the time. It said they required physical access, and that images stayed on a device only briefly after upload.
What the camera records
The camera’s processor is similar to those in midrange smartphones, the outlets found. It runs about 20 apps built by Flock. The apps handle motion detection, photography, object classification, uploads and remote updates.
When something moves into view, the camera takes a rapid burst of photos. A typical passing vehicle produced about 28 images, and some produced more than 100. The camera does not appear to read the plate or identify the make, model and colour of a vehicle. That work appears to happen on Flock’s servers.
The recovered logs covered about 21 days of activity. In that time, the camera photographed roughly 50,200 vehicles and generated about 1.6 million images. Its busiest day logged 4,454 vehicles.
The software also detects people, as well as vehicles, licence plates and bicycles. When it spots a person, it records their position in the frame and a confidence score. WIRED ran the extracted models across 27,321 short clips from the camera. It found people in 11 clips, all on motorcycles.
The plate detector sometimes cropped bumper stickers and dealership frames as if they were plates. In one clip, it cropped an American flag patch on a motorcyclist’s saddlebag.
The outlets found no sign of face recognition beyond default Android features. Those features did not appear to be in use. Flock says its cameras do not perform face recognition.
The logs also showed more than 27,000 “no space left on device” errors. About every two minutes, a check that the camera was still running logged the message “Who’s a good boy?!”
Flock’s response
“The unauthorized removal and tampering of a Flock camera is illegal,” a Flock spokesperson told 404 Media. The company said it had received no report through its public vulnerability disclosure policy. It added that it lacked the detail to assess the claims. It asked the hackers to submit their findings through that process.
Flock sells access to a national network, in which other police departments can search a city’s cameras. In Alpharetta, Georgia, WIRED previously found more than 2,000 agencies with access to the city’s camera records. In August, Flock launched an AI search tool for police. The same month, it cut its data retention to seven days.
The No FLOCK Act
Representatives Raja Krishnamoorthi, an Illinois Democrat, and Michael Cloud, a Texas Republican, told WIRED they planned to introduce the bill on 16 September. The No FLOCK Act stands for Federal License-Plate Observation and Camera Keeping.
It directs the US transportation secretary to withhold 10% of a state’s annual federal funding for highways, roads and bridges if the state does not restrict the cameras. The bill text allows only five uses.
Those are toll enforcement, finding stolen vehicles and finding missing or endangered people. The other two cover vehicles registered to people with a felony warrant and vehicles involved in a felony.
If the bill passes this year, states that do not comply would start losing funding in October 2028. The bill does not ban the cameras, and it does not stop agencies from sharing plate data, WIRED reported.
Krishnamoorthi said in a statement that an investigation into Flock had exposed “serious gaps in oversight”. “Flock cameras are enabling mass surveillance of Americans, infringing on the Fourth Amendment,” Cloud said in a statement.
President Donald Trump said on 13 September that the cameras help law enforcement, according to WIRED. Flock did not immediately respond to WIRED’s request for comment on the bill.
The bill follows state action. Florida and Texas moved against Flock cameras in the same week earlier this month. Flock’s network had spread across the US this year.
Its products now also include police response drones, which Stockton, California, approved in June.
Get the TNW newsletter
Get the most important tech news in your inbox each week.