Quick Answer: In the Flock camera hack, a hacker group called stegan0gram physically removed a Flock Safety license plate camera from above a roadway and copied its storage. Inside, they found an encryption key that unlocked the camera’s media files. The device held 27,321 short video clips, and its logs showed about 1.6 million images of roughly 50,200 vehicles taken over 21 days. Flock’s cloud network was not breached, and the attack needed physical access. But the findings challenge Flock’s claim that footage on its cameras is encrypted and only stored briefly.
The Flock camera hack has become one of the most talked-about privacy stories in the US this month. Flock Safety runs one of the largest license plate reader networks in the country, with cameras on poles above roads, at shopping centers, and at neighborhood entrances. Now a group of hackers has shown what one of those cameras actually keeps inside, and it is far more than the company had suggested.
If you drive in the United States, there is a good chance a Flock camera has photographed your car. This guide explains what happened, what data was found, what Flock says, and what it all means for your privacy.
What Happened in the Flock Camera Hack?
A hacker collective calling itself stegan0gram took down a Flock Safety camera that had been mounted above a roadway. The group then made what it called a near-complete copy of the camera’s stored data.
The hackers shared the data with the independent news outlet 404 Media and the transparency group Distributed Denial of Secrets. Those organizations then worked with WIRED on a joint analysis. The story went public in mid-September 2026 and has since been picked up by Tom’s Hardware, TechRadar, TechRepublic, Fox Business, and many others.
Here is the short version of what the analysis found:
- The operating system: The camera runs on Android and has several storage partitions.
- The weak spot: Two partitions, labeled “vendor” and “media,” were not encrypted.
- The key: The “media” partition contained an encryption key.
- The unlock: That key opened a separate encrypted partition holding the camera’s videos and still images.
In simple terms, the camera had a locked box, but the key to that box was sitting right next to it inside the same device.
It is worth stressing how the attack worked, because it shapes how serious the risk is. The hackers did not break in over the internet. They needed the physical camera in their hands. Once they had it, though, getting to the stored footage was far easier than Flock’s public statements suggested. That gap between the company’s promises and the device’s reality is the heart of this story.
What Data Was Found on the Flock Camera?
The numbers are what made this story go viral. According to the joint investigation, the logs covered roughly 21 days of activity from a single camera.
| Data Found | Amount |
|---|---|
| Images generated (per logs) | About 1.6 million |
| Vehicles photographed | About 50,200 |
| Short video clips stored | 27,321 |
| People detected | 11 (per reporting by 404 Media) |
| Time period covered | About 21 days |
| Average images per passing vehicle | About 28 (some cars triggered 100+) |
The video clips were short MP4 files, each lasting about one or two seconds, at 1024 x 768 resolution.
That is a huge amount of data from one device. And Flock operates thousands of these cameras across the country.

Why the Flock Camera Hack Matters
At first glance, this might sound like a small story. The hackers stole one camera. They did not break into Flock’s servers. So why is everyone talking about it?
The answer is trust. For years, Flock has told cities, police departments, and the public that its cameras are safe. Specifically, the company said two things:
- Images on the camera are protected by on-device encryption.
- Images stay on the camera only briefly before being sent to the cloud.
Flock also said that even someone with physical access to a camera would not be able to see the footage. The hack appears to contradict all three claims. The key was recoverable from the device itself, and the stored media went back weeks, not minutes.
When a company’s public security promises turn out to be weaker than advertised, people start asking what else might not be true. That is why this story has spread so fast.
What Flock Cameras Actually Do
To understand the risk, it helps to know what these cameras are designed for.
What Is Flock Safety?
Flock Safety is an Atlanta-based company that makes automated license plate reader cameras, often called ALPRs. The cameras photograph passing vehicles and help police search for specific cars, such as stolen vehicles or cars linked to crimes.
Flock’s customers include police departments, cities, homeowners associations, and private businesses. Reporting says Flock camera records can be reached by more than 2,000 agencies, which lets police search data across city and county lines.
What Happens on the Camera vs. in the Cloud
The hack gave a rare look at how the system is split:
- On the camera (edge AI): The device detects people, vehicles, bicycles, and plate-like shapes. It crops those regions and sends them to Flock’s servers along with the original images.
- In the cloud: Flock’s servers read the actual license plate numbers and describe details like a vehicle’s color, make, and model.
This means the camera does more than snap plates. It also detects people. That detail worries privacy advocates, because Flock has long marketed its product as vehicle-focused rather than people-focused.
What Flock and Experts Say
Flock’s response has focused on two points. First, the company says removing and tampering with its cameras is illegal. Second, it stresses that the cloud network was never touched.
Some security experts agree the scope was limited. Jason Brown, a former Secret Service cybercrime expert, told Fox Business that access to one stolen camera did not give the hackers a way to log into Flock’s cloud. He also said Flock reports that about 97 percent of law enforcement agencies using its system now have multifactor authentication turned on.
Here is a fair summary of what the hack does and does not show:
| The Hack Shows | The Hack Does Not Show |
|---|---|
| A stolen camera can expose weeks of stored images and video | That hackers can remotely pull images from Flock cameras |
| The encryption key was stored on the device itself | That Flock’s cloud servers were breached |
| Cameras keep far more data locally than Flock suggested | That police accounts were compromised |
| Edge AI on the camera detects people, not just cars | That Flock’s full national database was exposed |
Both things can be true at once. The attack needed physical access, which limits how widely it could be used. But thousands of these cameras sit in public places, often on easy-to-reach poles. A design that relies on nobody ever taking one down is a weak design.
This Is Not the First Flock Security Warning
The stegan0gram hack did not come out of nowhere. Earlier in 2025, security researcher Jon “GainSec” Gaines documented root-level access vulnerabilities in a Flock camera. Flock’s response at the time was that physical access was still required and that images were only briefly retained.
The new hack goes further. It shows that physical access is enough to reach the stored footage, and that the footage is kept for weeks.
Flock has also faced controversy beyond security flaws:
- Several police officers have been arrested for using Flock data to stalk romantic partners, according to Tom’s Hardware.
- A mistyped license plate reportedly led to an unnecessary police “ambush” of a car reviewer.
- TechRadar reports that morale inside the company is low, with many employees said to be looking to leave.
Each incident adds to a growing debate over how much surveillance power private companies and police should have, and who is watching the watchers.

The Case For and Against License Plate Readers
To be fair, license plate readers are popular with many police departments and residents for a reason. The debate is not simply “good” versus “bad.”
What Supporters Say
- Solving crimes faster: Police say plate readers help them find stolen cars, locate suspects in hit-and-run cases, and track vehicles tied to kidnappings or Amber Alerts.
- Cheaper than more officers: A network of cameras can cover more roads than a patrol car, at a fraction of the cost.
- Neighborhood peace of mind: Many HOAs buy Flock cameras after a string of break-ins or package thefts, and residents say they feel safer.
What Critics Say
- Mass tracking of innocent people: The vast majority of cars photographed belong to people who have done nothing wrong.
- Misuse by insiders: Cases of officers abusing the system to stalk partners show that access controls do not always work.
- Errors with real consequences: A single misread or mistyped plate can lead to a dangerous police stop.
- Weak security: As the Flock camera hack shows, the devices themselves may not protect the data as well as promised.
Where you land on this debate often depends on how much you trust the people and companies holding the data. That trust is exactly what this hack has shaken.
Could Your Car Be in Flock’s Data?
If you drive regularly in the US, the honest answer is probably yes. Flock cameras are common in suburbs, on major roads, at retail parking lots, and at the entrances of gated or HOA communities.
That does not mean your data was part of this hack. The hackers took one camera, and its location has not been widely published. The real concern is broader: every Flock camera near you may hold weeks of images locally, and that data could be exposed if a camera is stolen or tampered with.
What Kind of Information Can a License Plate Photo Reveal?
One photo of your plate seems harmless. But thousands of photos over time can build a detailed map of your life:
- Where you live and work
- When you leave home and when you return
- Which stores, clinics, churches, or events you visit
- Who you visit, and how often
This is why privacy groups often describe license plate readers as location-tracking tools, not just crime-fighting tools. It is the same reason big data leaks, like the recent Pentagon data breach, worry experts so much: small pieces of data become dangerous when combined.
What You Can Do About License Plate Surveillance
You cannot opt out of being photographed on public roads. But you are not powerless. Here are legal, practical steps you can take.
1. Find Out Where Cameras Are in Your Area
Many cities and police departments that use Flock publish a transparency portal. These pages often list how many cameras they run, how long data is kept, and how many searches officers make. Search your city or police department name along with “Flock transparency portal.”
2. Ask About Data Retention Rules
Flock has long said its standard cloud retention period is 30 days, but local contracts and state laws can change that. Ask your city how long images are kept, who can search them, and whether data is shared with other agencies. The hack suggests you should also ask what is stored on the cameras themselves.
3. Use Public Records Requests
In most states, you can file a public records request to see your city’s contract with Flock, its usage policies, and audit logs. Local journalists and privacy advocates have used these requests to uncover misuse.
4. Speak Up at City Council Meetings
Many Flock contracts are approved by city councils or county boards. Public comment periods give residents a chance to ask for stronger rules, audits, or shorter retention times. Some cities have paused or canceled Flock contracts after residents raised concerns.
5. Check Your HOA’s Policies
If your neighborhood association uses Flock cameras, ask who has access to the footage, whether it is shared with police automatically, and how long it is stored. HOA boards often approve these contracts with little discussion.
6. Know Your State’s Privacy Laws
Some states limit how long license plate data can be stored or who can access it. Others have almost no rules. Our guide to US state privacy laws in 2026 explains how protection varies depending on where you live.
One important note: Do not tamper with or remove surveillance cameras yourself. Flock says doing so is illegal, and you could face criminal charges. The right path is through public records, local government, and the courts.
What About Your Own Home Security Cameras?
The Flock story is also a useful reminder about the cameras you own. Video doorbells and home security cameras collect similar data about your street, your visitors, and your neighbors.
Ask yourself a few questions about your own setup:
- Is local storage encrypted? If someone steals your camera or its SD card, can they view the footage?
- Is two-factor authentication on? Your camera account should have it turned on.
- Do you share footage with police automatically? Some doorbell brands offer opt-in programs. Check your settings.
- How long is footage kept? Shorter retention means less data at risk.
If you are shopping for a new camera, our comparison of the best video doorbells in 2026 covers privacy features like end-to-end encryption and local storage options.
The Bigger Picture: Surveillance Tech Under Pressure
The Flock camera hack lands during a busy year for surveillance and privacy news. Government agencies have suffered major breaches, including the ATF data breach by the Qilin ransomware gang. Consumer camera tech is spreading into everyday wearables too, as we saw with the new smart glasses at Meta Connect 2026.
The common thread is simple. More devices are collecting more data about people in public spaces, and security often lags behind. Every camera on a pole, every doorbell, and every pair of smart glasses is a potential target.
For Flock, the stakes are high. The company depends on trust from city governments and police departments. If residents lose faith that the data is secure, more cities may push back on new contracts or demand stricter oversight.
What Happens Next?
Several questions remain open:
- Will Flock change its camera design? Storing encryption keys on the same device as encrypted data is a known weakness. Security experts will watch for a hardware or firmware fix.
- Will Flock update its public claims? The company’s statements about brief on-device storage are now in question.
- Will cities react? Expect the hack to come up at city council meetings where Flock contracts are up for renewal.
- Will lawmakers step in? State legislators who already track license plate reader rules may use this story to push for stronger limits.
- Will there be legal action? Flock has said tampering is illegal, so the hackers could face investigation.
Key Takeaways
- The Flock camera hack was carried out by a group called stegan0gram, who physically removed a camera from above a roadway.
- They found an encryption key on the device that unlocked stored videos and images.
- The camera held 27,321 video clips, and its logs showed about 1.6 million images of 50,200 vehicles over 21 days.
- Flock’s cloud servers were not breached, and the attack required physical access.
- The findings contradict Flock’s claims that on-device footage is encrypted and only stored briefly.
- You cannot opt out of public road cameras, but you can use transparency portals, public records requests, and city council meetings to push for stronger rules.
Frequently Asked Questions
What is the Flock camera hack?
It is a September 2026 incident in which a hacker group physically removed a Flock Safety license plate reader camera and copied its storage. They found an encryption key on the device that unlocked weeks of stored images and video clips.
How many images were found on the Flock camera?
The camera’s logs showed about 1.6 million images of roughly 50,200 vehicles over about 21 days. The device also stored 27,321 short video clips.
Was Flock’s cloud network hacked?
No. The hackers only accessed the physical camera they removed. A former Secret Service cybercrime expert told Fox Business that nothing in Flock’s cloud was accessed.
Who hacked the Flock camera?
A hacker collective called stegan0gram. It shared the data with 404 Media and Distributed Denial of Secrets, which worked with WIRED on the analysis.
Is my data at risk from the Flock camera hack?
Only the data from the one stolen camera was exposed. However, the hack shows that any Flock camera may store weeks of images locally, so data from other cameras could be exposed if they are stolen or tampered with.
Do Flock cameras record people?
The cameras are designed to read license plates, but the hack revealed that their on-device software can also detect people, bicycles, and other vehicles. The analyzed camera logged 11 people during the period studied.
How long does Flock keep license plate data?
Flock has said its standard cloud retention period is 30 days, though local contracts and state laws may differ. The hack showed that the camera itself held weeks of media, which Flock had described as only briefly stored.
Is it legal to remove a Flock camera?
No. Flock says removing or tampering with its cameras is illegal. If you have concerns, the legal route is public records requests, city council meetings, and contacting your state lawmakers.
Final Word
The Flock camera hack did not bring down Flock’s network, but it did something that may matter more in the long run. It showed that the public was given an overly rosy picture of how these cameras protect data. One stolen device held weeks of footage, and the key to unlock it sat right beside it.
License plate readers are not going away. But this story gives residents, journalists, and lawmakers a strong reason to ask tougher questions about how much data these cameras collect, how long they keep it, and who can see it. For a deeper technical breakdown, Tom’s Hardware’s report on the Flock camera is worth a read.



