Flock Camera Hacked: 1.6 Million Images and 2026's Edge Security Lesson
Hello HaWkers, a Flock Safety camera removed from a public road revealed far more than license plates. On September 16, 2026, a joint investigation by WIRED and 404 Media reported that the stegan0gram collective copied nearly all of the device's storage and recovered videos, images, applications, and logs. In just 21 days, the device had produced 1.6 million images of approximately 50,000 vehicles.
But this was not a remote cloud breach: the hardware was physically accessed. So what does it really prove about encryption, privacy, and edge system security? In this article, we will separate the facts from hasty conclusions and turn the investigation into a useful practice for any team that installs cameras, sensors, kiosks, or other devices outside its own office.
What Happened to the Flock Camera
According to the WIRED investigation, members of stegan0gram removed an automatic license plate reader camera, disassembled the unit, and reverse-engineered its storage and software. The material was shared with 404 Media and the transparency organization Distributed Denial of Secrets before journalists analyzed it.
The researchers found an Android system divided into partitions. Some areas remained encrypted and inaccessible, including part of the most sensitive content. However, a partition called media contained a key that allowed them to open another area and view thousands of videos and images. That nuance is essential: there was no proof that the entire Flock platform had been opened, but the claim that physical access would not provide access to images no longer seemed sufficient.
The camera ran around 20 applications built by Flock. They handled motion, capture, object classification, data transmission, and remote updates. The files also showed that the software detected people, vehicles, license plates, and bicycles. The analysis found no active facial recognition, and Flock continues to state that its license plate reader system does not use that technology.
The incident requires another point of precision. Removing or tampering with equipment installed on a public road may be a crime, and the company stated that it did not receive the material through its vulnerability disclosure program. Studying the journalistic findings is legitimate; replicating the removal of a camera is neither a technical nor an ethical recommendation.
How One Camera Produced 1.6 Million Images
A Flock Camera does not need to stream continuous high-resolution video all day. It can detect motion locally, record short clips, take bursts of photos when a vehicle passes, classify the content, and send only relevant events. This design reduces bandwidth use, but it concentrates responsibility in the equipment installed on the street.
Across the 21 recovered days, the logs indicated around 50,200 vehicles and 1.6 million images. The simple average is close to 32 images per vehicle and 76,000 images per day. That does not mean every vehicle always generates exactly 32 files: position, speed, lighting, repetition, errors, and deletion policies change the result. The calculation serves to reveal the scale.
const periodo = {
dias: 21,
veiculos: 50_200,
imagens: 1_600_000,
}
const imagensPorVeiculo = periodo.imagens / periodo.veiculos
const imagensPorDia = periodo.imagens / periodo.dias
// The averages describe the dataset; they are not a fixed rule for the camera.
console.log(`Imagens por veículo: ${imagensPorVeiculo.toFixed(1)}`)
console.log(`Imagens por dia: ${Math.round(imagensPorDia).toLocaleString('pt-BR')}`)The journalists also ran the recovered models on 27,321 MP4 clips, each one to two seconds long and with a resolution of 1,024 by 768 pixels. People appeared in 11 clips, all of them riding motorcycles. The camera's position, pointed toward the road, helps explain the small number. Even so, the code had an explicit class for people and recorded the position and confidence of each detection.
The license plate detector also produced false positives. In some cases, it cropped stickers, frames, and even an American flag on a motorcycle bag as though they were plates. This shows why probabilistic output should be treated as a lead, not as truth. Flock itself says that alerts require human confirmation.
Encryption Does Not Solve the Problem When the Key Travels With It
Encrypting the disk is essential, but writing “data protected at rest” in a presentation is not enough. An autonomous device must boot without an operator entering a password. At some point, it receives or derives a key. If the storage, key, and unlocking process are all on the same equipment and can be extracted, encryption becomes a delaying barrier rather than an absolute boundary.
The problem is like keeping the key to a safe in a drawer attached to that safe. The lock is still real, but the threat model ignored the attacker who takes the entire piece of furniture. For edge devices, the team must assume that someone may touch, open, disconnect, or transport the hardware.
A simple review can turn this assumption into verifiable requirements:
const controles = [
{ nome: 'boot verificado', presente: true, peso: 3 },
{ nome: 'chave em secure element', presente: false, peso: 5 },
{ nome: 'apagamento após violação física', presente: false, peso: 4 },
{ nome: 'rotação remota de credenciais', presente: true, peso: 3 },
{ nome: 'dados locais com vida curta', presente: true, peso: 5 },
]
const riscoResidual = controles
.filter((controle) => !controle.presente)
.reduce((total, controle) => total + controle.peso, 0)
// Internal score: use it to prioritize work, not as public certification.
console.log({ riscoResidual, ausentes: controles.filter((c) => !c.presente) })In practice, a robust design combines verified boot, a key bound to a secure component, a unique identity for each device, credential rotation, rapid revocation, and minimal local retention. Ephemeral data reduces the reward available to anyone who obtains the hardware. And no device key should unlock data from other units or from the cloud.
This is a physical version of the supply chain problem discussed in the article about the V8 zero-day in Chrome and Electron: the trust boundary must include the runtime, updates, credentials, and the place where the software actually runs.
The Logs Revealed Operational Failures Beyond Privacy
The storage did not only contain data; it showed the health of the product. The investigation found more than 27,000 “no space left on device” messages while the camera tried to save full-resolution images, as well as tens of thousands of related errors, crashes, and restarts. A process checked activity approximately every two minutes and recorded more than 12,000 health messages.
Logs like these are useful during development, but they consume space, create noise, and may reveal internal details. On a remote device, the system needs to limit files, export aggregated metrics, and respond before reaching critical capacity. Restarting after the disk fills up may restore service briefly without fixing the cause.
This small analyzer illustrates how a team could summarize events without indefinitely retaining every raw line:
function resumirEventos(linhas) {
const resumo = { discoCheio: 0, reinicios: 0, saudavel: 0 }
for (const linha of linhas) {
if (linha.includes('no space left on device')) resumo.discoCheio++
if (linha.includes('reboot was requested')) resumo.reinicios++
if (linha.includes("who's a good boy")) resumo.saudavel++
}
// In production, send counters and retain only the sample needed for diagnosis.
return resumo
}
console.log(resumirEventos([
'no space left on device',
"who's a good boy",
'a reboot was requested',
]))The important alert is not just diskFull > 0. It is the combination of queue growth, remaining space, failure rate, and restarts. A policy can temporarily reduce resolution, stop new nonessential captures, confirm transmission before deletion, and open an incident. The behavior must be defined before the unit runs out of space in the field.
The Conflict Between Public Messaging and What the Software Detects
In its Trust Center, Flock states that its license plate reader product captures images of license plates, vehicle characteristics, time, and location, and that it does not collect driver information or facial recognition data. The recovered analysis showed no facial recognition. It did, however, show a computational person category and the ability to record where a person appeared in an image.
Detecting a person is not the same as identifying them. That technical distinction matters, but it does not end the privacy discussion. A system can track clothing, routes, associations between vehicles, and movement patterns without knowing someone's name. WIRED had previously reconstructed Flock search tools that allow users to search for people by description in some video products, although the company says that this search does not work by personal attributes in license plate cameras.
Public documents should therefore describe capabilities, not just purposes. “We do not use it to monitor people” is a policy; “the model has a person class” is a property of the software. Good practices connect the two through controls: who can search, for what reason, in which product, for how long, and with what auditing.
In August 2026, Flock announced changes: recommended and default retention reduced from 30 to 7 days for new configurations, case codes, misuse detection, multifactor authentication, and an independent Bishop Fox review. Existing customers may retain locally defined periods. The Associated Press reported that thousands of agencies in 49 states use or share data from the network, making configuration and governance as important as the algorithm.
How to Test an Edge Device Without Touching Someone Else's Hardware
You do not need to disassemble someone else's equipment to apply the lesson. Start in an authorized lab with a test unit, synthetic data, and a physical loss plan. The goal is to answer what happens when the device disappears, not to prove hacking skill.
A minimal matrix should cover unexpected shutdown, storage removal, bit-for-bit copying, restoration of old firmware, network loss, and revoked credentials. Each scenario needs an expected result, evidence, and an owner. “We could not read the volume” is better than “we use AES-256” because it tests the effect, not the label.
const cenarios = [
{ evento: 'armazenamento removido', esperado: 'dados ilegíveis', passou: true },
{ evento: 'dispositivo roubado', esperado: 'credencial revogada em 15 min', passou: false },
{ evento: 'firmware antigo', esperado: 'boot bloqueado', passou: true },
{ evento: 'rede ausente', esperado: 'retenção local limitada a 24 h', passou: true },
]
const falhas = cenarios.filter((cenario) => !cenario.passou)
if (falhas.length) {
process.exitCode = 1
console.error('Gate de segurança reprovado:', falhas)
} else {
console.log('Todos os cenários físicos passaram')
}The test should also confirm that one compromised unit cannot impersonate another. Unique certificates, narrow scope, and individual revocation prevent a local incident from becoming systemic access. Updates need signing, downgrade protection, and a version inventory. Telemetry should warn about enclosure opening, orientation changes, unusual restarts, and prolonged silence.
Finally, simulate the response time. Who receives the alert? Who can revoke the identity? How do you preserve evidence without retaining unnecessary personal data? How long does it take to notify the customer? Operational security appears in these answers, not just in a list of algorithms.
Checklist for Buying Connected Cameras, Sensors, and Kiosks
Public- and private-sector teams should request evidence before installing thousands of units. First, what is the physical threat model? The answer needs to explain key protection, boot, debugging, exposed ports, and the destination of data when connectivity fails. “The enclosure is mounted high” is not a cryptographic control.
Second, what is the actual retention period at each layer? The cloud, local cache, logs, backups, preserved evidence, and support environments may have different timelines. Flock's announced 7-day policy is a measurable step, but existing customers may retain a different configuration, and active cases may preserve records. The contract should state who authorizes exceptions and who can audit them.
Third, demand transparency about vision models. Which classes are detected? Which attributes can be searched? Which false positives were measured? A model trained for plates may crop stickers; a model that detects people may have future uses beyond the current workflow. Updates that expand categories should trigger a new privacy assessment.
Fourth, verify the vulnerability process: a public channel, response timeline, protection for good-faith research, signed updates, and a correction history. Coordinated disclosure does not eliminate conflict, but it creates a responsible alternative to surprise publication.
Finally, treat sharing as a product, not as a checked box. Access across thousands of agencies increases both investigative value and the impact of abuse. Least privilege, MFA, case codes, justification, anomalous behavior alerts, and human review need to be enabled by default.
Outlook: Security Begins When the Device Leaves the Building
The Flock Camera case does not prove that anyone on the internet can watch every camera. Nor can it be reduced to “someone stole the equipment, so it does not count.” Devices installed on poles and public roads live in a hostile environment by definition. Physical access is part of the threat model.
The most useful finding is the gap between declared encryption and proven resistance. Some sensitive material remained inaccessible, showing that controls worked. At the same time, a local key opened thousands of records, the logs revealed storage failures, and the software showed capabilities broader than the public image of a simple license plate reader.
For developers, the answer is not to abandon edge processing. It is to design as though the box could disappear tomorrow: reduce data, separate keys, limit credentials, record only what is needed, test physical loss, and give the operator fast revocation tools. Privacy does not depend on one heroic control, but on layers that remain useful when one of them fails.
In 2026, the mature question is not “is the disk encrypted?” It is: “what data remains exposed when the attacker possesses the device, how long does it live, and how far can a compromised identity reach?” If your team can answer with a repeatable test, it has already learned the main lesson from this camera.
Let's go! 🦅
📚 Want to Keep Up With What Is Coming?
This article covered the physical breach of a Flock Camera and edge device security, but the ecosystem changes every week, and not everything becomes an article here.
On X, I share what I am testing, behind-the-scenes details from my projects, and news before it becomes a post.
Follow Me There
💡 Daily content about development, careers, and the tools I actually use

