One Stolen Flock Camera Exposed 50,200 Vehicles and 1.6 Million Images
A hacker collective physically stole a roadside Flock Safety license-plate camera and extracted 1.6 million images of about 50,200 vehicles from 21 days.

TL;DR
- —Physical theft of surveillance hardware is almost unheard of — most attackers prefer silent remote breaches.
- —But on the morning of September 18, 2026, the collective stegan0gram did exactly that: they climbed up to a roadside Flock Safety camera, tore it down, and walked away with it.
- —When they pried the device open, they found two storage partitions — one labeled "vendor," one labeled "media" — that were not encrypted.
The Theft Physical theft of surveillance hardware is almost unheard of — most attackers prefer silent remote breaches. But on the morning of September 18, 2026, the collective stegan0gram did exactly that: they climbed up to a roadside Flock Safety camera, tore it down, and walked away with it. When they pried the device open, they found two storage partitions — one labeled "vendor," one labeled "media" — that were not encrypted. The "media" partition contained the encryption key that unlocked a third, encrypted partition holding the sensitive footage. Flock has long marketed end-to-end encryption; the incident indicates the algorithm protecting at-rest data could be bypassed locally once physical access was obtained. What One Camera Held The math is what gives regulators pause. In 21 days, that single camera generated: ~1.6 million images, capturing roughly 50,200 vehicles
27,321 short MP4 video clips at 1024×768 resolution
Footage that included, per 404 Media and WIRED (working with Distributed Denial of Secrets), computer-vision identifications of people, bicycles, and even bumper stickers — not just plates
Details of the device's roughly 20 Flock-built applications, spanning motion detection and automated uploading For context on the network's scale: Flock's system spans more than 6,000 U.S. communities, interlinking license-plate data across 2,000+ organizations. A single stolen device connected to that network becomes a potential entry point, and its OS Investigate tool can merge camera records with police and civilian databases. The Flaws That Made It Possible The theft didn't happen in a vacuum. Security researcher Jon Gaines ("GainSec") had documented root-level access vulnerabilities in Flock cameras back in November 2025. And in July 2026, researchers found unsecured Flock AI cameras with default credentials that granted root access in under 30 seconds, enabling real-time remote viewing of vehicle movements. Flock confirmed the encryption exists but stressed the exploit required physical access, not a network intrusion — and that it did not breach Flock's central servers, with some sensitive storage tiers staying encrypted and images retained only briefly on-device. Declassified Today separately reported Flock is investigating unauthorized access to "one of its cameras or its associated data." The company's core marketing claim — that no decryption keys reside on individual devices — is now directly contradicted by what the attackers found. The Policy Aftermath The incident landed in a year already thick with surveillance backlash, and it's become a legislative trigger. On September 16, 2026, two members of Congress introduced the No FLOCK Act, proposing to withhold 10% of federal highway funding (roughly $10M–$100M per state annually, beginning October 2028) from states that fail to restrict Flock camera deployments. The momentum was already there: police officers have reportedly used Flock to stalk romantic partners, at least 53 U.S. cities have rejected the network, towns have terminated contracts or wrapped cameras in makeshift covers, and recently Boston abandoned Flock Safety after this breach exposed the privacy flaws. This connects directly to the broader pattern we've documented with flock and automatic license-plate readers and the accountability timeline of surveillance failures. What This Means The Flock breach collapses two separate anxieties into one incident: Surveillance overreach: a private company running a de facto national plate-tracking network, used for everything from routine enforcement to stalking.
Security failure: that same network's most sensitive data, guarded by a decryption key stored on the very device it was meant to protect. "end-to-end encrypted" and "physically safe" are not the same promise. For the estimated 50,200 vehicle owners captured in that one 21-day window, the footage now sits in the hands of strangers. The strongest argument for tightening surveillance-device security begins with a single stolen camera — and for the people who never consented to be tracked in the first place, the breach proves what critics have said all along: they didn't ask, and nobody asked them. What to Do Assume plate data is collected. If you drive through any city using Flock (most major metro areas do), assume your plates are photographed daily, by default.
Support warrant requirements and retention limits. The No FLOCK Act and state ALPR bills create the accountability that "voluntary" company policy has failed to provide.
Question the encryption claims. "Encrypted" doesn't mean "safe" when the key rides on the same device. Demand that vendors keep keys separate from the media they unlock.
Know who queries the data. Ask your local police department how it uses ALPR data, how long it retains it, and whether it shares it out of jurisdiction.