A newly uncovered Flock camera security flaw has allowed a hacker collective to pull 1.6 million images and more than 27,000 video clips from a single automatic licence plate recognition unit, directly contradicting the company’s repeated claims that this kind of data exposure should be impossible.

The breach was reported by 404 Media, which said a group calling itself stegan0gram managed to physically access a Flock camera and create what it described as a “near-complete copy” of everything stored on it. The group shared its findings with 404 Media and the nonprofit Distributed Denial of Secrets, which passed the material on to Wired for further verification.

What the hackers actually found

According to the reporting, the extracted data included roughly 50,200 identifiable vehicles captured across a 21-day window. Older footage appeared to have been overwritten or was otherwise inaccessible, suggesting the camera only retains a rolling window of recent activity rather than a permanent archive.

More troubling for privacy advocates is confirmation that Flock’s cameras capture people, not just number plates and vehicles. There is no evidence facial recognition was active on the device in question, but the sheer volume of pedestrian and vehicle imagery sitting on a single unit raises obvious questions about how carefully that data is being handled once it leaves the camera.

A claim that doesn’t match reality

The core of this Flock camera security flaw lies in what the hackers discovered when they dug into the device’s Android operating system. They found two partitions, one of which, labelled “media,” contained a decryption key that unlocked a storage area holding weeks of images and video.

Flock camera security flaw shown on a roadside automatic licence plate recognition unit

That directly contradicts Flock’s public position. The company has previously stated that footage is only held briefly on the camera before being uploaded to its servers, and that decryption keys are never stored on the hardware itself. The presence of both long-retained footage and an on-device key suggests either an oversight in how the cameras are configured or a gap between Flock’s stated policy and its actual engineering.

Flock’s public claimWhat the hackers reportedly found
Footage stored briefly, then deletedUp to 21 days of images and video retained on-device
No decryption keys stored on camerasA decryption key found inside the device’s media partition
No facial recognition in usePeople detected, but no confirmed facial recognition activity

For context, this is a fundamentally different security model to what shows up in consumer-grade hardware. Home security systems, including devices like consumer surveillance cameras like Reolink’s Duo 3V, are built around clearer expectations of local storage and encryption, since buyers are choosing to install them on their own property. Flock’s cameras, by contrast, are deployed widely across public roads by police departments and local governments, often without the same level of scrutiny from the people being recorded.

A company already under siege

This isn’t an isolated headache for Flock. The company has faced a steady stream of negative coverage in recent months over how its automatic licence plate recognition network is used, who can access the data it collects, and how transparent that access actually is. Vandalism targeting its cameras has become common enough that it was raised directly by employees speaking to Wired.

That pressure appears to be showing up inside the company as well. Flock has opened a voluntary separation scheme offering what it calls a generous severance package to staff who want to leave, with applications open until 2 October and decisions due on 9 October. People familiar with the program, speaking to Wired anonymously, suggested a significant share of Flock’s roughly 1,500 employees may take the offer.

Flock camera security flaw shown on a roadside automatic licence plate recognition unit

Flock’s own chief executive acknowledged the strain in August, telling the All-In podcast that internal morale had become the biggest casualty of the growing backlash against the company’s cameras. One employee put it more bluntly to Wired, saying that seeing the level of vandalism aimed at Flock’s hardware made clear “the writing is on the wall.”

What it means for privacy and the industry

The bigger issue here goes beyond one misconfigured camera. Flock has built its business on convincing police departments, city councils, and neighbourhood groups that its network is secure enough to justify blanket surveillance of public roads. A Flock camera security flaw of this scale, verified independently by two respected outlets, undermines that pitch at the exact moment the company can least afford it.

It also fits a wider pattern where hacking collectives extract far more sensitive material than companies expect, echoing incidents like a hacking collective’s leak of cut GTA 5 and GTA 6 files, where internal assumptions about what was truly secure turned out to be wrong. For residents living near a Flock installation, the practical takeaway is simple: the company’s assurances about how briefly footage is kept and how tightly it’s locked down may not hold up to real-world scrutiny. Local governments weighing new contracts with Flock Safety now have fresh, concrete evidence to factor into that decision, rather than relying solely on the company’s own claims about how its hardware behaves in the field.