Flock Cameras: How They Work and What the Recent Hack Revealed

Flock cameras are automated license plate reader systems used by thousands of communities, law enforcement agencies, and other organizations across the United States. They are designed to capture vehicles passing a camera, identify characteristics such as license plates and vehicle type, and make that information searchable for authorized users.
But a recent investigation by WIRED and 404 Media has provided an unusually detailed look inside one Flock camera after hackers removed a device and extracted much of its stored data and software. The analysis found that the camera generated far more imagery than a simple license-plate snapshot might suggest, including software capable of detecting people as well as vehicles.
The findings do not establish that Flock’s cloud platform was hacked or that the entire Flock network was breached. Instead, they concern physical access to an individual camera and the information stored on that device. Flock says its cloud infrastructure has not been compromised and maintains that unauthorized tampering with its cameras is illegal.
What are Flock cameras?
Flock cameras are automated license plate reader, or ALPR, cameras made by Flock Safety.
Unlike conventional security cameras that continuously record a scene, Flock’s ALPR cameras are designed primarily around vehicle detection. The company says its cameras capture still images of vehicles and associated characteristics such as license plates, vehicle type, color, and distinguishing features.
The technology can be installed in locations such as:
- Public roads
- Neighborhood entrances
- Parking areas
- Commercial properties
- School areas
- Other locations where vehicles regularly pass
Flock says its systems are intended to help with investigations involving stolen vehicles, missing people, crime investigations, and other public-safety purposes.
The important distinction is that Flock cameras are not simply standalone cameras. They are part of a larger software and data network that allows authorized users to search information collected by cameras.
How do Flock cameras work?
At a basic level, the process looks like this:
Vehicle passes → camera captures images → relevant information is extracted → data is transmitted to Flock’s servers → authorized users can search the records
Flock’s system can associate images with information including a license plate, time, location, and vehicle characteristics. The company’s current FAQ says its cameras capture multiple images of a vehicle during a detection session.
The recent investigation adds another layer to that picture.
WIRED and 404 Media examined data and software recovered from a Flock camera and found that the device rapidly captured multiple photographs when a vehicle entered its field of view. A typical vehicle generated about 28 images in the recovered system, while some generated more than 100.
The camera appears to perform some initial processing locally, while more sophisticated vehicle classification and identification functions are performed on Flock’s servers.
That architecture matters because it means the camera is more than a simple sensor taking one photograph of a license plate.
What did the recent Flock camera hack reveal?
In September 2026, hackers associated with the collective known as stegan0gram removed a Flock camera and copied much of the information stored on the device.
The recovered material was provided to 404 Media and the nonprofit Distributed Denial of Secrets, with WIRED and 404 Media subsequently analyzing the data.
The investigation found that the camera’s software contained multiple Flock-developed applications responsible for functions including motion detection, image capture, object classification, data transmission, and software updates.
Researchers also recovered an encryption key stored on the device that allowed them to access some of the locally stored media. Much of the camera’s more sensitive storage remained encrypted and inaccessible.
The scale of the recovered imagery was significant
The recovered logs covered roughly 21 days of activity across several periods.
During those periods, the camera photographed approximately 50,200 vehicles and generated about 1.6 million images. The investigators noted that the camera was almost certainly operating outside the recovered periods as well, but older logs had been overwritten or could no longer be recovered.
That does not mean every Flock camera generates 1.6 million images.
Traffic volume, camera positioning, configuration, and other factors can substantially affect how much imagery a particular device produces. The number comes from the specific camera examined by the journalists.
Flock cameras can detect people, not just vehicles
One of the more notable findings concerned person detection.
The recovered software explicitly contained functionality for detecting people within images. WIRED tested the relevant models and found that they could identify people in test imagery. The investigators also ran the models against thousands of short video clips recovered from the camera and detected people in a small number of them.
This needs some important context.
The investigation did not find evidence that Flock’s ALPR camera was using facial recognition to identify individuals. WIRED reported finding no evidence that facial-recognition capabilities were being actively used by the camera.
Flock itself says its ALPR system does not use facial recognition and does not identify drivers or passengers based on their faces.
So there is a difference between:
- Detecting that a person appears in an image
- Recognizing a particular person’s face
- Identifying someone through vehicle and movement information
Those are technically different capabilities, and they should not be treated as interchangeable.
Flock’s broader system can search more than license plates
The camera itself is only one part of the story.
In August 2026, WIRED reported on Flock’s newer law-enforcement search technology after obtaining and reconstructing portions of the software. The system can use camera records to search for vehicles based on characteristics and patterns of movement, rather than relying exclusively on a known license plate.
A later WIRED investigation into the system found that its AI-powered tools could allow officers to search across multiple cameras using written descriptions.
This is one reason the debate surrounding Flock cameras extends beyond the question of whether a camera can read a license plate.
The larger issue is what happens when thousands of individual vehicle detections become searchable as part of a connected network.
How large is the Flock network?
The scale of that network has become a major part of the controversy.
WIRED reported in August that Flock records from an Atlanta-area suburb were accessible to more than 2,000 organizations, including police departments, colleges, airports, and government agencies.
Flock has described data sharing as something controlled by customers rather than an automatic feature of every installation. Its current privacy materials say customers determine how their systems are used and who can access the data.
However, reporting and public-record investigations have raised questions about how access and sharing work in practice.
That distinction is important: the privacy implications of Flock cameras depend not only on what an individual camera captures, but also on who can search the resulting database, what jurisdictions can access it, how long information remains available, and what rules govern those searches.
What does Flock say about privacy and security?
Flock says its ALPR technology is not designed for mass surveillance or tracking individuals. Its current privacy materials state that the system captures vehicle-related information rather than biometric or facial-recognition data.
The company also says its data is encrypted throughout its lifecycle and that customer access is controlled through permissions and audit systems.
Flock has introduced several security and accountability changes in 2026, including mandatory multifactor authentication, a coordinated vulnerability disclosure program, and additional auditing and misuse-detection measures. The company also announced a seven-day recommended default retention period for ALPR data for law-enforcement customers, with mechanisms for preserving specific evidence when necessary.
Flock separately maintains that its cloud platform has not been hacked and that customer data has not been exfiltrated through a compromise of its cloud infrastructure.
The recent camera incident therefore represents a different security question: what information can be recovered if someone obtains physical access to the hardware itself?
Does the Flock camera incident mean the entire Flock network was hacked?
No.
This distinction is critical.
The September 2026 investigation involved physical removal of a camera and examination of its local storage and software. It does not establish that hackers broke into Flock’s central cloud infrastructure or gained unrestricted access to the company’s entire camera network.
The investigators were able to recover significant information from the particular device they obtained, but some encrypted data remained inaccessible.
Flock’s own public security statement says there has been no compromise of its cloud platform or customer data through a cloud breach.
Calling the incident a nationwide Flock data breach would therefore overstate what has been established.
Why the findings matter
The technical findings are significant because they make the surveillance system easier to understand.
Before the investigation, much of the public discussion focused on the basic idea of an automated license plate reader: a camera sees a car, reads its plate, and stores the result.
The recovered software suggests a more complicated process involving:
- Multiple images captured during a vehicle detection
- Local computer vision
- Detection of people and objects within imagery
- Vehicle classification
- Cloud-based analysis
- Searchable records
- Networked access across participating organizations
- Software that can analyze vehicle movement patterns
That does not automatically establish that every possible function is used in every deployment. But it provides a more detailed technical picture of what the hardware and software are capable of doing.
The privacy debate is bigger than the cameras themselves
The central policy question is not simply whether Flock cameras can help police solve crimes.
They can provide investigators with vehicle evidence, and Flock and local agencies point to uses involving stolen vehicles, missing people, and criminal investigations.
The harder questions concern safeguards.
Communities considering or already using Flock systems may want clear answers to questions such as:
- Where are the cameras installed?
- What information is collected?
- How long is it retained?
- Which agencies can access it?
- Can agencies in other states search the records?
- What reasons are required before a search is conducted?
- Are searches audited?
- Can residents review policies or search logs?
- What happens when data is requested by another government agency?
- What protections exist against unauthorized use?
These questions are increasingly important as ALPR systems become interconnected rather than operating as isolated local databases.
What should people know if there are Flock cameras in their community?
If you have noticed Flock cameras near your home, workplace, or regular travel routes, the most useful step is to find out how your local agency has configured and governed the system.
Local policies can differ substantially.
Some agencies publish camera locations, retention policies, access rules, and audit information. Others provide less detail. For example, Norwalk, Connecticut launched a transparency portal in September 2026 containing information about its Flock system, including usage and data-sharing information.
Residents can look for:
- City council or police department contracts
- ALPR policies
- Data-retention policies
- Camera-location maps
- Data-sharing agreements
- Search-audit information
- Public meeting records
- Rules governing requests from outside agencies
The presence of a Flock camera does not by itself tell you who can access its records or how long those records remain available. Those details are determined by the particular deployment and applicable policies.
The bottom line on Flock cameras
Flock cameras are sophisticated ALPR systems built to turn passing vehicles into searchable records containing images, timestamps, locations, license plates, and vehicle characteristics.
The September 2026 investigation by WIRED and 404 Media revealed new details about the technology after hackers physically obtained a camera and examined its software and stored data. The analysis showed that a single device could generate a very large volume of imagery and that its software could detect people as well as vehicles. It did not, however, establish a compromise of Flock’s cloud infrastructure or prove that the entire Flock network had been breached.
The larger issue is how these systems are governed as their networks expand. The technology can provide useful investigative evidence, but questions about access, retention, sharing, auditing, and security remain central to the public debate.
For communities using or considering Flock cameras, understanding those rules may be just as important as understanding what the cameras can technically capture.
