Hackers tore down a Flock camera to see what was inside — they found 1.6 million images

A group of hackers who ripped down a Flock camera to study it and figure out how it works is now warning of its potential dangers.

The hackers, known as the stegan0gram collective, handed the Flock camera they’d stolen to 404 Media and Wired magazine, both of which conducted a joint analysis. Their findings have since gone viral.

Their most shocking finding was the sheer number of images generated by the camera. During a 21-day period that was logged by the camera, it recorded over 50,200 vehicles and a whopping 1.6 million images.

“A typical passing vehicle generated about 28 images, though some produced more than 100,” according to 404 Media and Wired.

The camera used bursts of photographs with different exposures to ensure that both the license plate and the surrounding scene were captured in full.

The investigation also found that the camera’s software wasn’t limited to recognizing license plates or cars. Its computer-vision software contained models for detecting people, vehicles, license plates, and bicycles.

ADVERTISEMENT

Whenever the camera detected a person, its software recorded their location and marked down the chances that the image contained a person.

By looking at the generated photos, 404 Media and Wired analysts were themselves able to identify some of the people by name who’d been captured by the camera. However, 404 Media and Wired analysts found zero evidence that the camera itself contained any facial recognition technology.

The analysts also found that the camera’s object-recognition capabilities can be surprisingly broad or imperfect. The camera sometimes interpreted bumper stickers, dealership frames, and other graphics as license plates.

They also found out that the camera itself functions almost entirely as just a sophisticated image-collection device. It takes pictures, selects relevant frames, and transmits them over cellular networking to Flock’s servers.

ADVERTISEMENT

Once the images reach Flock’s servers, then the real fun begins, including sophisticated analysis determining a car’s make, model, color, and license plate information. The data is then made available to relevant agencies.

“Flock then makes these time-stamped records searchable by whichever local agency owns or has access to the cameras,” Wired reported, adding that “in many cases, Flock’s system also allows other police departments from all over the country to search those cameras too.”

For example, the analysts found that records from the Flock cameras in the Georgia town of Alpharetta “were accessible to more than 2,000 agencies, including police departments, colleges, airports, and, inexplicably, the Office of Inspector General for the federal General Services Administration.”

This is particularly important because of previous reporting that found that local police were using Flock’s network to conduct searches for federal immigration authorities, even in so-called sanctuary jurisdictions.

ADVERTISEMENT

Meanwhile, the work by the stegan0gram collective exposed a potentially important security weakness: They were able to copy parts of the camera’s storage and recover an encryption key that was itself stored on the device. Using the key, the hackers were then able to unlock some of the otherwise protected sensitive video and image data on the camera.

This is especially notable because of security researcher Jon “GainSec” Gaines’ former work.

“In early 2025 … Gaines reverse engineered a Flock license-plate reader and documented flaws that could be used to gain root-level access,” according to 404 Media and Wired. “After Gaines disclosed his findings, the company acknowledged the findings but downplayed their severity.”

In defending their cameras, Flock alleged that taking advantage of the flaws required physical access to the cameras. They also claimed that even someone who gained physical access to a Flock camera “would still not be able to gain access to footage” because the photos stayed on the device only briefly before being transmitted to the servers.

However, the new findings seem to contradict what Flock said in 2025.

ADVERTISEMENT

Flock isn’t happy about this investigation.

“The unauthorized removal and tampering of a Flock camera is illegal,” a spokesperson told The Hill. “Flock takes security seriously and maintains a public Vulnerability Disclosure Policy for security researchers to report potential vulnerabilities directly to us.”

“We received no report through that process, and based on the limited information provided, we do not have enough detail to assess the claims being made,” the spokesperson added.

Vivek Saxena

Comment

We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the ∨ icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.

Latest Articles