Thursday, September 24, 2026·Focal News

The Austin Focal

Austin's independent voice

Local

Flock camera breach reveals scale of automated vehicle surveillance

A hacking group that removed a Flock license-plate camera says its examination showed the system can create dozens of images from a single vehicle encounter. Investigators found one camera photographed about 50,200 vehicles and produced roughly 1.6 million images in 21 days, intensifying scrutiny of surveillance programs used by law enforcement agencies.

Flock camera breach reveals scale of automated vehicle surveillance
A group calling itself stegan0gram removed a Flock surveillance camera, extracted data from the device and reverse-engineered its software, revealing new details about how the system tracks vehicles and surrounding features. The group shared its findings with Wired and 404 Media, which reported that a single camera photographed approximately 50,200 vehicles and generated about 1.6 million images over a 21-day period. The system typically produced about 28 images during one vehicle encounter, though some encounters generated more than 100 images. Flock sells a network of automated license-plate readers, cameras and audio-detection devices that feed an artificial-intelligence database. The database can record a vehicle’s plate number along with characteristics such as its make, model, color and bumper stickers. Participating jurisdictions can share information with other law enforcement agencies, creating a broad network of vehicle-location data. The examination found that cameras send photographs and related information to Flock over a cellular connection. The devices themselves capture the images, while plate-reading and vehicle-identification functions appear to occur on Flock’s servers. One camera, investigators reported, detected an American flag patch on a motorcyclist’s saddlebag. The camera operated roughly 20 Flock-built applications, including software for detecting motion and uploading data. The hackers said they removed the equipment and its solar hardware to study how it worked rather than simply destroying it. “Why just destroy them when we can reverse engineer them and find the secrets of those spying on us?” one member of the group said. Flock said unauthorized removal and tampering with one of its cameras is illegal. A company spokesperson also said Flock maintains a public vulnerability-disclosure process for security researchers, but that the company had not received a report through that channel and did not have enough information to evaluate the claims. The revelations arrive as automated license-plate readers face growing political opposition. Florida Gov. Ron DeSantis has warned that widespread deployment could turn the state into a “digital AI surveillance state,” while U.S. Rep. Thomas Massie, a Kentucky Republican, introduced the Flock-Off Act to restrict the use of federal money for automated license-plate readers and biometric surveillance cameras. President Donald Trump has expressed support for the technology while acknowledging that critics view it as an intrusion on privacy. For communities that use or are considering Flock cameras, the findings raise questions about how much imagery is collected, how long it is retained, which agencies can access it and whether residents have meaningful ways to challenge its use. The breach also underscores the security risks of placing networked surveillance equipment in public spaces without transparent, independently verified safeguards.

More from The Austin Focal