Flock Camera Torn Off a Pole Shows 1.6 Million Images of 50,000 Cars in 21 Days

Ethical Hacking Complete Course Zero to Expert
Hack like black hat hackers. Penetration testing, Kali Linux, WiFi and web hacking, and the hacker mindset behind it.
→ Take the full courseYou drove past a camera on a pole and it took 28 photos of your car. It did that to 50,000 cars in 21 days. 1.6 million images, and the key to the encrypted ones was lying on the same disk.
A hacker collective that calls itself stegan0gram took a Flock Safety camera out of the field. They copied almost everything stored inside it. The files went to 404 Media, Wired and the leak archive Distributed Denial of Secrets. Their own description of the work: “We liberated hardware in the field, disarmed them, and proceeded with reverse engineering of the cameras and associated solar equipment.” They say they are publishing how they did it, so other people can copy them.
The camera runs Android 8.1.0, released in 2017, with support ended in 2021. The security patch level on the device reads 5 June 2018. Underneath that sits Linux kernel 3.18.71-perf. That series ran until May 2019 and ended at 3.18.140. This camera is 69 releases short of the last one in its own branch. The build itself dates from 5 June 2025. So a camera assembled last year went up a pole running software that was already seven years old. Holes published since then are still open in it. One is a Qualcomm graphics driver bug fixed in May 2021. Another is a kernel socket bug fixed in December 2018.
The storage sits in partitions, and several of them carried no encryption at all. Two of those hold the vendor files and the system. A third is called persist. That one survives a factory reset, and the login credentials for this camera sit in it in plain text. The video and the images live on a partition called media. Flock encrypts those. The key that opens them sat on the unencrypted part of that same partition, in a file named:
| |
Copy the disk, read that key, open the footage. The encryption held for exactly as long as it took to read the key lying next to it.
The firmware holds 20 Flock apps. Nineteen of them ship the same library, and inside that library sits a single fixed API key. That key calls a Flock server and asks for the login credentials of that specific camera. The name it hands over is the camera’s MAC address, the fixed number burned into its network chip. Micah Lee went through the dump. His reading: with that one key you can presumably pull credentials for any Flock camera, given that number. He published the actual values. I am leaving them out here. A device standing unattended at the roadside carries a working key into the company’s own systems, in the clear.
The logs cover 21 days. In that time the camera photographed about 50,200 vehicles and produced roughly 1.6 million images. That comes out at around 28 photos per passing car. Some cars produced more than 100. On an average day it logged about 3,300 vehicles, with a peak of 4,454. It also recorded more than 27,000 no space left on device errors while saving full-resolution images. Alongside those came tens of thousands of related errors, crashes and reboots. The camera wrote status checks to the log two minutes apart, more than 12,000 times in three weeks. The text: Who's a good boy?!. On restart it writes A reboot was requested! ¡Adios Amigos!
The software does more than read plates. The code detects vehicles, license plates, bicycles and people. For people it records where they show up in the frame and how sure it is that it saw one. Out of 27,321 video clips the researchers tested, 11 carried a person detection, and all eleven were motorcyclists. The camera hangs high above the road, so people on foot rarely enter the frame.
It also isolates bumper stickers and graphics on the back of a vehicle. In one case it picked out a flag patch on a motorcyclist’s saddlebag and handled it as a plate. The reporters who got the files went looking for face recognition. They found nothing beyond what the operating system ships by default, and that did not appear to be switched on.
The dump also identifies the camera itself. A serial number, a MAC address, and GPS coordinates that place it in Wauwatosa, Wisconsin. The logs hold 2,264 calls to the company’s own API and 155 recorded positions. Those coordinates lead straight to it on Street View. A solar panel on a light post next to a No Parking sign on N Mayfair Rd, photographed by a passing Google car.
That is one camera on one street. The network behind it runs in more than 6,000 communities across 49 US states. It holds more than 120,000 cameras and performs over 20 billion vehicle scans a month. It covers more than 80 percent of the American market for automated plate readers. What that means shows up once the scans land in one searchable database. Deputies in Johnson County, Texas queried roughly 83,000 cameras nationwide during an investigation into a woman’s self-managed abortion.
The Institute for Justice keeps a running list of officers who used these systems on people they were romantically interested in. Current partners, exes, and in one case a woman a deputy first saw while working security on a TV set. On 3 September that list stood at 66 incidents, most of them since 2024. In March an officer tracked his own partner and one of that partner’s exes nearly 180 times in two months. The victims found out by looking up their own plates on a site that collects Flock audit data from local governments.
This week the Electronic Frontier Foundation published its analysis of Flock’s search logs. Officers have to type a reason before they search, and what they type includes LOL, Hehe, blah, idk and plain keyboard mash. A deputy at the Lake County Sheriff’s Department in Indiana ran a plate across more than 19,000 cameras in 1,558 cities and towns. The reason he gave was LMAO. The same group counted 1.6 billion plate scans by 80 California agencies in 2022. The share with no link to any public safety case: 99.9 percent.
This has been building for ten years. That same organisation built on earlier University of Arizona work back in 2015. They tested more than 100 plate cameras and found them sitting open on the internet in three states. Those cameras came from PIPS Technology, by then owned by 3M. Some agencies closed the hole after being told about it and others left it alone. Four years later TechCrunch found the same cameras still exposed. In 2019 a contractor working for Customs and Border Protection leaked 105,000 plate images and 184,000 traveler photos.
In June 2024 the Michigan State Police reported seven vulnerabilities in Motorola’s Vigilant readers. One was a fixed password for a hidden wireless network, identical across the cameras, scored 8.6. Another was unencrypted customer data on the disk. In January 2025 Matt Brown of Brown Fine Security found around 170 plate reader streams broadcasting on the open internet. Colour video, infrared video, plate text, vehicle make, model and colour, with timestamps and locations. Will Freeman, who runs a site that maps plate readers, wrote a script that turned those streams into spreadsheets of vehicle movements.
Early in 2025 Jon Gaines got root on a Flock device and reported it, and the company played it down. That November he published a formal paper with 51 findings, 22 assigned CVE numbers and 8 more pending. The worst of them scores 9.8 and comes down to a hardcoded password in a keystore.
That same November Senator Ron Wyden and Representative Raja Krishnamoorthi asked the FTC to investigate. They called the company’s cybersecurity negligent and pointed at 35 stolen Flock logins sitting on a criminal forum. In December researchers found at least 60 Flock cameras answering the open internet, with live video and 30 days of archive behind them. Some also handed over the admin controls. And this week a camera came off a pole.
Your own phone carries the same kind of security patch level, and it takes ten seconds to find: Settings, About phone. It tells you how far the published fixes on that device run. A patch level of June 2018 on a device built in 2025 means the holes published after that date are still sitting there. Those holes have numbers and public write-ups, and most of them come with working attack code that is free to download.
A key that opens encrypted storage has to sit somewhere the attacker cannot reach. On this camera it sat on the same disk, on a part with no protection at all. That is the same mistake as a hard coded password in firmware. It keeps showing up in devices that stand within reach of the people they watch.
Flock sells only inside the United States. Plate readers also hang over motorways and junctions in a lot of other countries. They record where a car was and when. That record lands in a database searched by people the driver will never meet.
Those 60 cameras from December were found with Shodan, a search engine that indexes devices instead of web pages. Those cameras answered without asking for a login. The same kind of search runs on your own address. Looking up one single address goes through the host page there, because the ip: filter needs a paid account. For searching wider I wrote a tool years ago called Shodan Eye. You give it a keyword and it returns what is sitting open under it.
- → Look your own public IP up on that host page and read what comes back
- → Run Shodan Eye from my GitHub to search wider than one address
- → Read the security patch level on your own phone and tablet
- → Test whether your camera or recorder answers from outside your network
- → Treat any device standing outdoors as something that can be taken and read
Your own router, camera or storage box could be answering the internet right now, and finding out takes minutes with these same tools.
My Ethical Hacking Complete Course Zero to Expert takes you there step by step: reconnaissance, scanning, exploitation and traffic analysis, hands-on, from your first day with no Linux or hacking background.
→ Join my complete ethical hacking course
Hacking is not a hobby but a way of life.
Sources:
Stay updated
Get the latest posts in your inbox every week. Ethical hacking, security news, tutorials, and everything that catches my attention. If that sounds useful, drop your email below.