TL;DR: A group of hackers pulled a Flock Safety automatic license-plate-reader camera off a roadway, copied its data and software, and shared the files with 404 Media and WIRED. The September 16 joint investigation found roughly 21 days of camera data on the device, covering around 50,000 vehicles and 1.6 million images, plus the camera software itself, which documents the tracking mechanics in detail. The hackers say they will publish how they did it so others can copy them. Read alongside 404 Media's Flock City PD demo account and the EFF audit-log stories on cops typing "LMAO" and "asdfg" as search reasons, the picture is the same network exposed in three different lights in two weeks.
The Rip
404 Media reporters Joseph Cox and Dhruv Mehrotra published the investigation jointly with WIRED on September 16. The lede is direct: "Hackers ripped down a Flock camera above a roadway, made a near-complete copy of the data stored inside it, and shared the files with 404 Media and WIRED, revealing in new detail how exactly Flock Safety's cameras track the movements of both vehicles and people." The article frames the act this way: "While people around the U.S. are tearing down Flock cameras, one group of hackers went a step further: extracting the camera's software too." [1][2]
WIRED's own preview of the joint piece confirms the data scale: thousands of videos, logs, around 1.6 million images, and roughly 50,000 vehicles recorded across about 21 days on the single camera. The hacker's stated goal is distribution, not secrecy: "The hackers say they are also publishing details on how they managed to obtain the software, in the hopes that other people may copy them." [2][1]
Flock Safety's response, as the article summarizes it, is that unauthorized removal and tampering is illegal and that the reporters should have filed through the company's vulnerability disclosure policy rather than publishing the findings. The article notes the response argued the reporting "lacked enough detail through its vulnerability disclosure policy" and pointed researchers toward that channel [1]. That framing matters: the camera, by Flock's own security posture, is a production system that the company argues should only be probed through a controlled channel. The hackers did not probe. They took the box.
What's in the Data
A single Flock ALPR camera sitting over a roadway, over a 21-day window, captured roughly 50,000 vehicles and generated about 1.6 million images. Those are the counts WIRED surfaced from the joint investigation [2]. The volume is what makes the camera different from a passive dash-cam-style recording. The system is built to capture every plate that passes, upload every capture to Flock's cloud for plate-read and make/model/color identification, and log every search an authorized user runs against the national network.
That last layer, the national network, is the part that turns a roadside box into a trans-jurisdictional surveillance tool. Prior 404 Media reporting already tied Flock's network to ICE and to an out-of-state abortion search [1]. The new piece's value is not in re-establishing that the network is searchable across jurisdictions; that has been established. The value is in showing what the camera is doing on the road shoulder before the cloud step: which cameras are tracking, how often, how much data each one is generating, and how the on-device software is structured to feed it all upward.
Flock's marketing pitch to cities is that the cameras capture "plates only." The on-device software analyzed in the piece, by contrast, includes detection code for vehicles, plates, bicycles, and people. The investigation reports no evidence of face recognition beyond unused Android defaults, but people-detection code is in the build. The "plates only" framing is the marketing. The on-device code is the product. Those are not the same thing, and the gap between them is the privacy case.
Why This Matters
Three Flock stories have landed in two weeks. On September 14, EFF and 404 Media each documented Flock ALPR audit logs where officers typed "LMAO," "IDK," "asdfg," and other junk strings as the stated reason for thousands of searches across hundreds of agencies [3][4]. On September 17, 404 Media reported that Flock operated accounts named "Flock City PD - Law Enforcement Demo" and ran real ALPR and camera queries against Dunwoody, Georgia and Bryan, Texas residents, on criteria including "Star of David" and "coexist bumper sticker" [5]. On September 16, this piece, the camera itself was the source.
Each story exposes a different layer of the same system. The audit logs are the search layer. The City PD account is the moderation layer. The stolen camera is the device layer. The warrant-requirement bills in Colorado (SB 26-070) and the camera-destruction wave this site tracked in July both assume Flock is a passive data pipe [6]. The stolen camera shows Flock is a data pipe whose contents include the camera-side software that decides what gets uploaded, who gets searched, and which criteria get flagged or allowed. The product is the camera. The product is the network. The product is the moderation. They are not separable.
The investigator's stated goal is replication: "The hackers say they are also publishing details on how they managed to obtain the software, in the hopes that other people may copy them" [1]. The risk for Flock is not the data on the box that was ripped down. It is the playbook that lets any researcher, journalist, or curious passerby pull the next box and find out what the camera on their street corner is sending home.
What to Watch
The published playbook. Watch for the hackers' own documentation of how the camera was extracted and what they found inside. The investigation says the methods will be published. That publication is the moment the threat model for every Flock camera changes from "your data might leak" to "anyone with a ladder and a laptop can pull this and see."
Flock's response, on the record. Watch whether Flock publishes a written technical response addressing what the cameras capture on-device, what is shipped to the cloud, and what controls exist on the network-search layer. The "vulnerability disclosure" framing the company used on this story is forward-looking. The cameras already deployed are not subject to that process. The cities that bought them deserve the same level of detail the reporters got.
State bills that assumed "plates only." Watch whether warrant bills and contract-renewal fights in Colorado, California, Texas, Washington, Oregon, and elsewhere use this week's three Flock stories together to argue that "plates only" is not a meaningful limit. The cameras track people in code, the demo account searches for people by criteria, and the audit logs justify searches with junk. The "plates only" frame was never the technical reality.
Sources
- 404 Media, Joseph Cox and Dhruv Mehrotra: Hackers Stole Flock's Camera Software, Revealing How the Company Tracks Cars and People (September 16, 2026)
- WIRED: Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works (September 16, 2026)
- 404 Media, Jason Koebler: Cops Search Thousands of Flock Cameras for Reasons of "LMAO," "IDK," "Hehe," and "asdfg" (September 14, 2026)
- Electronic Frontier Foundation: High Crime LMAO: How Cops Are Treating Mass Surveillance as a Joke (September 14, 2026)
- 404 Media, Jason Koebler: Flock City PD: The Fake, Flock-Owned Police Department That Searched Real Cameras for Real People (September 17, 2026)
- State of Surveillance: Flock Cameras Destroyed Nationwide in ICE Backlash (July 2026)