Flock Exposed - Cybersecurity Vulnerabilities
Flock pitches itself as protecting your town. But the cameras, servers, and login systems that make up its nationwide network are themselves a target - and documented cases show they have been left exposed to the open internet, broken into by outside researchers in under a minute, and accessed using stolen police passwords. A surveillance system is only as trustworthy as the security protecting it, and Flock's own record raises serious questions.
Researchers found dozens of Flock cameras livestreaming to the open internet with no password
In December 2025, YouTuber and technologist Benn Jordan discovered that at least 60 of Flock's AI-enabled "Condor" cameras around the country were exposed to the open internet, where anyone could watch the live feed, download 30 days of video archive, and change device settings. Working with security researcher Jon "GainSec" Gaines, Jordan documented the findings in a video titled "We Hacked Flock Safety Cameras in under 30 Seconds," showing that pressing a button on the back of a physical camera in a specific sequence could create a wireless access point into the device. Flock's own response confirmed the vulnerabilities required physical device access, and the company said it traced the exposure to Verizon supplying the wrong SIM cards with public IP addresses on 60 to 70 devices, rather than a flaw of its own design.
Source: 404 Media, "Researcher Turns Insecure License Plate Cameras Into Open Source Surveillance Tool"; PetaPixel, "Big Brother Left the Door Open: Flock's AI Surveillance Cameras Exposed to the Internet"; Flock Safety, "Response to Compiled Security Research on Flock Safety Devices"; Slashdot, "What Happened After Security Researchers Found 60 Flock Cameras Livestreaming to the Internet"
Hackers stole a Flock camera off the street and tore it apart - here's what they found inside
Beyond remote exposure, researchers demonstrated that physically stealing a single Flock camera is enough to compromise it. After obtaining a device, hackers found it runs on a standard Android operating system, and that its internal hard drive contained unencrypted sections, including one labeled "media" that held the encryption key needed to unlock the camera's stored videos and images. In other words, the one component meant to keep captured footage secure was sitting in plain, unencrypted view right next to the footage itself, once someone had the physical device in hand.
Source: SAN, "Hackers stole a Flock camera. Here's what they found inside"
Two US senators and a congressman asked the FTC to investigate
Senator Ron Wyden and Congressman Raja Krishnamoorthi sent a formal letter to the Federal Trade Commission asking it to investigate Flock Safety, stating the company has "unnecessarily exposed Americans' sensitive personal data to theft by hackers and foreign spies" by failing to implement basic industry-standard cybersecurity protections. The letter cited a case in which a Texas sheriff accessed license plate data from Mount Prospect, Illinois while searching for a woman who had received reproductive care - illustrating how a single town's camera data can be reached from anywhere in the country once it is on Flock's shared network. The letter also noted that Flock does not require its law enforcement customers to use multi-factor authentication, leaving accounts open to being taken over with nothing more than a stolen password.
Source: Senator Ron Wyden, letter to FTC Chair Andrew Ferguson, November 3, 2025; Congressman Raja Krishnamoorthi press release, "Congressman Krishnamoorthi, Senator Wyden Urge FTC to Investigate Surveillance Tech Companies to Protect Americans' Personal Data"; The Record, "Lawmakers ask FTC to probe Flock Safety's cybersecurity practices"
At least 35 police login credentials for Flock's system have already been stolen by hackers
A search of a public database maintained by the cybersecurity firm Hudson Rock, which tracks accounts compromised by "infostealer" malware, found that passwords for at least 35 Flock customer accounts have been stolen. Congressional staff also found evidence that Flock login credentials had been offered for sale on a Russian-language cybercrime forum. Because Flock does not require multi-factor authentication for its law enforcement customers, a single stolen password is enough to grant an intruder direct access to a department's camera feeds and search history, without needing to break into the cameras themselves at all.
Source: Senator Ron Wyden, letter to FTC Chair Andrew Ferguson, November 3, 2025 (citing Hudson Rock data); TechCrunch, "Lawmakers say stolen police logins are exposing Flock surveillance cameras to hackers"; TechNadu, "Flock Safety Security Flaws Exposed by Stolen Police Logins"
Independent university researchers found the same kinds of flaws in ALPR cameras nationwide
This is not limited to one company. In a case cited by the Electronic Frontier Foundation, a team of computer scientists at the University of Arizona found vulnerable automated license plate reader cameras deployed in Washington, California, Texas, Oklahoma, Louisiana, Mississippi, Alabama, Florida, Virginia, Ohio, and Pennsylvania. EFF has argued that courts weighing how long ALPR data should be retained cannot ignore the possibility of a hacking incident, since a data breach is not the only way this kind of location data can be leaked or abused - it noted that in 2022, an officer in the Kechi, Kansas Police Department misused ALPR data shared with his department by the Wichita Police Department to stalk his own wife.
Source: EFF, "New ALPR Vulnerabilities Prove Mass Surveillance Is a Public Safety Threat," 2024
Boston's own pilot program leaked data nationwide within three days, despite the contract saying sharing was off
Boston Police ran a 156-day, no-cost Flock pilot from April 1 to September 4, 2025, with the contract explicitly stating that outside data sharing would be disabled, and BPD confirmed with Flock in writing that the sharing setting was off. According to the city's own 2025 Surveillance Technology Report, within three days of the pilot starting, BPD discovered other law enforcement agencies were nonetheless able to access its license plate and vehicle data - a failure the report attributed to a vendor-side "error" by Flock, not a setting BPD had ever agreed to. The access was disabled once discovered, but the episode became part of the record that led Boston Mayor Michelle Wu to announce the city has abandoned Flock altogether, citing exactly this kind of gap between a policy on paper and what the platform's settings actually enforced.
Source: WBUR, "Flock Safety failed to secure Boston vehicle data during 2025 pilot, report finds," 2026; GovTech, "Boston Drops Flock After Outside Agencies Access Data," 2026
A federal border contractor's license plate database was hacked, and the images ended up on the dark web
License plate surveillance data does not need a headline-grabbing hack of Flock itself to end up exposed - contractors in the same industry have already been breached. In 2019, a subcontractor for the U.S. Customs and Border Protection agency, later reported to be Perceptics, was hacked after an employee copied license plate and traveler photo data onto a company server in violation of its own contract, which had specifically forbidden retaining that data. The breach exposed more than 105,000 license plate images and over 184,000 traveler facial images; the hacker demanded a ransom, and when the company did not pay, uploaded more than 9,000 files to the dark web. CBP initially said none of the image data had been identified on the dark web, but CNN's own analysis found at least 50,000 unique license plate numbers there.
Source: DHS Office of Inspector General, "Review of CBP's Major Cybersecurity Incident during a 2019 Biometric Pilot"; CNN, "At least 50,000 license plates leaked in hack of border contractor not authorized to retain them," 2019; Wikipedia summary of Perceptics reporting (The Register, Vice)
The bottom line: a camera network is a database, and databases get breached. Flock has disputed that it has ever been "hacked" in the sense of an intruder breaking into its own core cloud platform - but livestreaming cameras with no password, a physically stolen camera yielding its own encryption key, stolen police logins sold on hacking forums, a pilot program that leaked data within three days despite the sharing setting being off, and a related industry's own breach exposing tens of thousands of plates onto the dark web are not hypothetical risks. They are documented events. A town considering this technology is not just deciding whether to trust Flock's intentions - it is deciding whether to trust its security.
This page will be updated as more factual sources become available.