Physically Removed Flock Safety Camera Revealed Local Vehicle Data

Media outlets 404 Media and WIRED analyzed data from a physically removed Flock Safety camera. The device contained local records, logs and a key for decrypting them.

Flock Safety camera that a group of hackers physically removed from the roadside reportedly allowed 404 Media and WIRED to analyze its locally stored data. The files were said to contain videos, operational logs and an encryption key directly on the device. According to the findings, this key may have enabled the decryption of vehicle-detection records.

The confirmed incident concerns one physically obtained device and its local storage. It is not evidence of remote access to Flock’s cloud platform or the compromise of data belonging to the company’s other customers.

What the analyzed Flock Safety camera showed

According to the media outlets’ joint analysis, the camera produced approximately 1.6 million images of about 50,200 vehicles over 21 days. The recovered logs and data also showed that, in addition to vehicles and license plates, the device’s software can detect people and bicycles.

The volume of records indicates how much data may be stored directly on a field device. In this case, some local data could be recovered after the camera was physically removed and a key—reportedly found in its storage—was used.

404 Media and WIRED said they were provided with files from the camera, which they subsequently analyzed. The analysis does not demonstrate an attack on the company’s central infrastructure.

Physical security and protection of local keys

Flock operates an extensive network of automated cameras for public- and private-sector customers. The finding from one camera raises questions about protecting encryption keys in devices installed along roads and about the volume of data these devices store locally.

Flock called the unauthorized removal and tampering with the camera illegal. The company also referred to its vulnerability-reporting program. Its earlier statement says that the company’s cloud was not compromised; the analyzed case, by itself, neither confirms nor disproves that claim.

It would therefore be misleading to describe the event as a data breach affecting Flock’s entire network. The available information confirms the compromise of local data from one physically removed device, not the mass acquisition of data from the cloud platform.

What has not been confirmed so far

  • It has not been independently verified whether the device’s technical information enables access to Flock’s backend, data falsification or the compromise of additional cameras.
  • It is not known whether Flock changed its device configuration, rotated the affected keys or issued a security update after publication.
  • Details about the incident’s location, the number of potentially affected devices or any investigation have not been confirmed.

Further information may come from an official security notice, a firmware update or a company statement on key rotation and other measures. Independent technical verification of claims about possible additional vulnerabilities will also be important.

Sources

  • WIRED – The joint investigation describes the physical removal of one camera, analysis of its storage, the key that was found and the scope of the local records.
  • 404 Media – Independently corroborates that files from the camera were provided to the newsrooms and that the goal was to obtain the device’s software and data.
  • Flock Safety – Documents the company’s earlier statement that its cloud was not compromised and its security claims; the current incident, by itself, neither confirms nor disproves that cloud-related claim.

Verified and updated: 09/17/2026 09:11

Sharing