Direct answer: In September 2026, a group calling itself stegan0gram physically removed a Flock Safety camera from its mount, copied its stored data and software, and shared the material with WIRED, 404 Media, and Distributed Denial of Secrets. The camera had logged roughly 21 days of activity: about 50,200 vehicles and 1.6 million images, an average of 28 images per vehicle passage. Researchers also found the device running nine-year-old, unpatched Android and Linux software, with encryption keys and API credentials recoverable directly from the hardware. This was physical access to one camera, not a remote breach of Flock’s cloud systems.
Key Takeaways
- The camera was physically removed and dismantled, not remotely hacked. Flock’s cloud infrastructure was not reported as breached.
- Over 21 recovered days, the camera logged about 50,200 vehicles and 1.6 million images — a typical vehicle generated about 28 images, and some generated more than 100.
- The recovered software captured video clips of people in some cases, not only still images of plates, and its computer-vision system sometimes flagged bumper stickers and other graphics alongside actual plates.
- Separately from the image-volume finding, researchers reported the device ran outdated, unpatched Android and Linux software and stored encryption keys and API credentials that Flock had described as protected.
- Flock’s public response addressed the legality of removing the camera, not the technical findings once it was opened.
- None of this determines whether a specific HOA’s Flock deployment is at similar risk — a community-specific camera model, firmware version and configuration would need to be verified separately.
What Happened
According to reporting from WIRED, corroborated by 404 Media, Cybernews, Hackaday and other outlets, a group physically detached a Flock Safety automated license plate reader (ALPR) camera from its pole, opened the housing, and extracted its stored filesystem and software. The recovered material was published through Distributed Denial of Secrets and analyzed by journalists and independent security researchers. This is an important distinction: the incident is a physical teardown of a single field device, not evidence that Flock’s servers, national network, or other customers’ cameras were remotely compromised.
What the Recovered Data Showed
The device held roughly 21 days of activity logs. In that window, it recorded approximately 50,200 vehicles — averaging around 3,300 per day — and generated about 1.6 million images. Reporting describes the camera firing a rapid burst of exposures at varying settings each time a vehicle passed, to improve the odds of a readable plate; a typical passage produced about 28 images, with some vehicles triggering well over 100. That volume reflects one camera’s local storage window, not a claim about how long Flock retains data across its network or in a given customer’s account — retention policy is a separate, contractual question covered in our Flock guardrails contract checklist for HOA boards.
Does the Camera Detect People, Too?
Yes, in a narrower sense than some summaries of the story suggest. Researchers reported that the recovered software’s detection classes include people, bicycles and vehicles alongside license plates, and that some detections were captured as short video clips rather than the still images used for plate reads. That is a real finding worth a board’s attention, but the reporting we reviewed identified it in a limited number of clips — it is not evidence that the system logs a video profile of every pedestrian who walks near a camera.
The Bumper-Sticker Finding
WIRED’s reporting states that the camera’s computer-vision software “sometimes isolated bumper stickers and other graphics” — in one example, an American flag patch on a motorcyclist’s saddlebag — alongside genuine plate detections. The available reporting describes objects being flagged as regions of interest, not that the system reliably records bumper-sticker text as though it were a plate number. It is a real limitation of the detection model worth asking a vendor about, but it should be stated at that level of precision rather than as a broader claim about what the system is designed to read.
The Bigger Problem: Old Software and Exposed Keys
The volume of images is the part that made headlines, but the security research underneath it may matter more for a board doing diligence. Reporting indicates the dismantled camera was running Android 8.1 on a Linux kernel more than nine years out of date, with at least two previously identified critical vulnerabilities left unpatched at the hardware level. Researchers also recovered encryption keys and API credentials stored on the device itself — despite Flock’s public materials describing on-device encryption — along with location data stored in plaintext. Coverage also notes a security researcher privately flagged related issues to Flock in 2025, and that the company reportedly did not treat the findings as urgent at the time.
None of this proves every deployed Flock camera runs the same firmware version or has the same exposure; hardware generations and patch levels vary by deployment and camera model. It is a legitimate, sourced reason for a board to ask a specific, verifiable question rather than an assumption to repeat as fact: what firmware version is on our cameras, when was it last updated, and how are credentials and encryption keys protected on the device itself.
What Flock Has Said
Flock’s public response to this specific incident has focused on the camera’s removal, stating that unauthorized removal and tampering with one of its devices is illegal. That is a statement about the act of taking the camera, not a rebuttal of the technical findings reported once it was opened. Separately, and on a different timeline, Flock announced a broader set of privacy and security safeguards on August 13, 2026 — including a recommended default retention period, a case-code requirement for law-enforcement searches, mandatory multi-factor authentication, audit-assistance tooling and proactive lockouts. Those safeguards are worth understanding on their own terms; we cover them in detail, including what a board should verify rather than assume, in the Flock guardrails contract checklist.
What This Means If Your HOA Is Evaluating LPR Options
This incident does not answer the question of whether Flock, or any other vendor, is the right fit for a specific community — and it should not be used to make a blanket claim about a competitor that the available reporting does not support. What it does illustrate is a governance point worth applying to any LPR vendor, PLACA included: ask who can access recorded images, how long they are retained, whether encryption keys and credentials live on the hardware or behind a server-side boundary you don’t control, and what happens to those protections if a camera is ever physically compromised. Those are the same questions our Flock Safety alternatives for HOA communities guide walks through when comparing operating models rather than camera specs.
Frequently Asked Questions
Did hackers break into Flock Safety’s servers?
No. Reporting describes a group physically removing one field camera and extracting data stored on that device. There is no report of Flock’s cloud infrastructure or other customers’ cameras being remotely breached as part of this incident.
How many images did the camera really capture per vehicle?
Recovered logs showed a typical vehicle passage generating about 28 images, with some vehicles triggering more than 100, across roughly 21 days and 50,200 logged vehicles.
Does this mean Flock cameras record video of pedestrians?
The recovered software’s detection classes included people alongside vehicles and plates, and some detections were captured as short clips. Reporting identified this in a limited number of cases rather than describing it as continuous pedestrian video recording.
Is every Flock camera running the same outdated software found in this one?
That isn’t established by the available reporting. Firmware version and patch level can vary by camera model and deployment date. It’s a fair, specific question to put to any vendor rather than an assumption to apply to every installed unit.
Should this change how my HOA evaluates a Flock renewal or an alternative?
It’s a reasonable prompt to ask sharper questions — about firmware patching, on-device credential storage, retention and audit access — of any LPR vendor a board is considering, rather than a reason to treat one incident as a full verdict on a category of technology.
Sources Reviewed
- WIRED: Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works
- Cybernews: Hackers rip Flock spy camera off pole and crack open its secrets
- Benzinga: Hackers Take Apart Flock Camera and Expose Vehicle Surveillance Data Collection
- Hackaday: This Week In Security — Flock Cameras Are Old
- Flock Safety: Updates to Privacy, Accountability, Security and Transparency Safeguards