Hackers Stole a Flock Camera. What They Found Is More Interesting Than the Viral Video

By  
Gigabit Systems
October 5, 2026
•
20 min read
Share this post

Hackers Stole a Flock Camera. What They Found Is More Interesting Than the Viral Video

One roadside camera captured 1.6 million images in 21 days.

A viral video making the rounds this week shows what appears to be a stolen Flock license-plate camera being subjected to an absurd experiment: thousands of license plates flashing past it at extreme speed.

The joke accompanying the video is that an American man “kidnapped” the surveillance camera and forced it to process 23,040 license plates per second.

There’s just one problem.

That number doesn’t appear to be real.

I couldn’t find credible technical evidence that the camera processed 23,040 license plates per second. Reporting tracing the viral claim says the number originated in social-media framing and is inconsistent with how Flock’s system actually operates.

But here’s the strange part:

The real story is arguably more interesting.

Security researchers actually did physically remove a Flock camera from above a roadway, copy its internal storage and reverse-engineer its software.

And what they discovered gives us one of the clearest looks yet inside America’s rapidly expanding license-plate surveillance infrastructure.

They Really Did Take Apart a Flock Camera

In September, the hacker collective stegan0gram physically removed a Flock Safety camera and made a near-complete copy of its internal storage.

The data was provided to journalists at WIRED and 404 Media, who analyzed the files along with the transparency organization Distributed Denial of Secrets.

This wasn’t a remote compromise of Flock’s cloud.

The researchers had physical possession of the hardware.

Inside they found an Android-based computer running roughly 20 Flock applications responsible for functions including detecting movement, capturing images, classifying objects, uploading information and receiving updates.

Essentially:

There’s a small computer sitting on that pole watching traffic all day.

And the amount of information it generates is remarkable.

1.6 Million Images From One Camera

Recovered logs covered roughly 21 days of operation.

During those periods, that single camera encountered approximately:

50,200 vehicles.

And generated approximately:

1.6 million images.

A typical vehicle generated around 28 images, while some vehicles triggered more than 100.

That works out to roughly 76,000 generated images per day during the recovered period.

Not 23,040 license plates every second.

But still an enormous amount of visual information from one camera.

The camera wasn’t simply snapping one picture of every license plate.

It rapidly captured multiple exposures as vehicles passed, allowing the system to find useful images of both the plate and the surrounding vehicle.

It then selected and cropped useful frames and transmitted information back to Flock over a cellular connection.

That’s an important distinction.

The Camera Doesn’t Appear to Actually Read Your Plate

This is one of the most surprising technical details.

The roadside camera apparently performs some computer-vision work locally.

It detects objects.

Finds potential plates.

Captures images.

Crops useful regions.

But according to WIRED’s analysis, the actual license-plate recognition and identification of attributes such as vehicle make, model and color appear to happen on Flock’s servers, rather than entirely inside the roadside camera.

So think of the roadside unit as the eyes.

The cloud provides much of the brain.

That architecture matters.

Because once thousands of cameras feed observations into a centralized searchable system, the capability becomes much larger than any individual camera.

The surveillance power isn’t the camera. It’s the database behind it.

They Also Found 27,321 Video Clips

Flock cameras are generally discussed as license-plate readers capturing still images.

But investigators recovered 27,321 MP4 video clips from the device.

They were short—roughly one to two seconds each—and recorded at 1024×768 without audio.

They were separate from the higher-resolution bursts of still images generated as vehicles passed.

That does not mean a Flock ALPR is secretly recording continuous 24/7 surveillance video.

There is no evidence from this investigation establishing that.

But it demonstrates that the hardware can create and temporarily retain considerably more visual information than someone might imagine from the phrase:

License-plate reader.

Then Researchers Discovered It Could Detect People

This may be the most interesting discovery.

The software recovered from the camera explicitly contained models capable of detecting:

Vehicles.

License plates.

Bicycles.

And people.

When the software identifies a person, it can record where that person appears within the image and the confidence of the detection.

WIRED extracted the computer-vision models and tested them independently.

They successfully detected people—including a reporter in a test selfie.

Researchers then ran the model across the 27,321 recovered video clips.

People were detected in 11.

All were riding motorcycles.

That low number isn’t especially surprising considering the camera had been mounted above a roadway and pointed primarily at vehicle traffic.

Importantly, investigators found no evidence that the device was performing facial recognition.

Detecting:

There is a person here

is technically very different from determining:

That person is John Smith.

But the distinction is worth understanding.

The Camera Sometimes Thought Other Things Were License Plates

Computer vision isn’t perfect.

Researchers found examples where the system isolated objects that weren’t actually license plates.

Bumper stickers could confuse it.

Other graphics could confuse it.

In one particularly interesting example, the system identified an American flag patch on a motorcyclist’s saddlebag as though it might be a license plate.

That’s not merely funny.

It’s an important reminder about automated surveillance.

Humans tend to treat computer-generated classifications as objective.

But computer vision is making probabilistic judgments.

Sometimes it gets them wrong.

And those errors matter when the resulting information enters a law-enforcement system.

There have already been documented cases where erroneous license-plate-reader matches contributed to innocent drivers being detained.

Automation can make a mistake faster than a human ever could.

Then They Found the Encryption Key

This is where the story becomes a cybersecurity story.

Flock has described its system as using encryption to protect captured information.

That’s exactly what you would expect.

These cameras sit unattended on poles in publicly accessible locations.

You have to assume that eventually somebody will physically obtain one.

The researchers discovered an encryption key stored on an unencrypted portion of the device’s storage.

That key allowed them to decrypt some of the camera’s recorded media.

Much of the camera’s most sensitive storage remained encrypted and inaccessible, so this wasn’t a complete defeat of every security mechanism.

But the architecture creates an obvious cybersecurity lesson.

Strong encryption is extraordinarily difficult to break.

But attackers often don’t attack the encryption.

They look for the key.

It’s the equivalent of installing an extremely expensive safe and then leaving information needed to open part of it nearby.

The cryptography can work perfectly.

The key management can still fail.

Physical Access Changes Everything

Cybersecurity professionals have an old rule:

If an attacker gains unrestricted physical access to a device, your security problem becomes substantially harder.

Roadside infrastructure makes that particularly challenging.

These devices aren’t sitting inside locked data centers.

They’re deployed outdoors.

Thousands of them.

Often unattended.

Twenty-four hours a day.

That means manufacturers have to design them assuming someone eventually:

Steals one.

Opens one.

Copies the storage.

Analyzes the firmware.

Extracts the software.

Examines credentials.

Studies communications.

And tries to discover weaknesses.

The physical enclosure is only one layer.

You should design every device as though your attacker eventually owns one.

But Flock Cameras Have Genuine Public-Safety Uses

The privacy debate becomes difficult because this technology can also be extremely useful.

Flock cameras have helped police locate stolen vehicles, identify suspects and recover missing or kidnapped children.

For example, Kalamazoo public-safety officials say Flock data helped officers locate a kidnapped infant and stop the suspect within approximately 25 minutes.

In another case last year, a Flock camera in Arizona spotted a vehicle connected to the kidnapping of a one-year-old child in California, helping authorities locate the child safely after the vehicle crossed state lines.

That’s the strongest argument for these systems.

If police know the plate of a vehicle carrying an abducted child, a distributed camera network can potentially find that vehicle considerably faster than officers manually searching roads.

That’s enormously valuable.

The privacy question isn’t whether that capability can do good.

Clearly it can.

The question is:

What else can that same capability do?

Because the Network Is Enormous

A single camera doesn’t know where you’ve been.

A network can.

That’s the fundamental difference.

According to a Washington Post investigation published in August, Flock’s system was operating across more than 6,000 communities and recording roughly 20 billion license plates per month.

Those observations can become searchable.

And once observations from many locations are connected, investigators can potentially reconstruct movement.

Where a vehicle appeared.

When it appeared.

Where it appeared next.

Repeated patterns.

Connections between locations.

That’s why describing Flock simply as a camera can miss the point.

One camera records a car. A network can record a life.

And That Power Has Already Been Misused

This isn’t merely hypothetical.

The Washington Post documented allegations involving law-enforcement personnel using Flock systems for unauthorized surveillance.

In one case, a police chief allegedly searched Flock records involving his former girlfriend and her teenage daughter’s vehicles roughly 600 times, according to records compiled by Have I Been Flocked.

That doesn’t mean most police officers misuse the system.

It demonstrates something more basic:

A powerful legitimate tool can also be abused by an authorized user.

Cybersecurity has a name for that problem:

Insider threat.

You don’t solve insider threat by saying employees aren’t supposed to misuse the system.

You build controls.

Strong authentication.

Least privilege.

Search justification.

Immutable audit logs.

Automated abuse detection.

Independent review.

Retention limits.

Alerts for unusual queries.

And consequences for misuse.

The same principles protecting a hospital database or corporate network should apply to surveillance infrastructure.

The Viral Number Distracts From the Real Story

The internet loves 23,040 plates per second because the number sounds insane.

But there is no good evidence that the stolen Flock camera actually demonstrated that processing capability.

And we don’t need an exaggerated number to make this story interesting.

The verified findings are extraordinary enough:

One roadside camera.

About 21 days of recoverable logs.

Roughly 50,200 vehicles.

Approximately 1.6 million images.

27,321 short video clips.

Software capable of detecting people.

An encryption key recovered from the device.

And a cloud-connected infrastructure capable of turning individual roadside observations into searchable vehicle intelligence.

That’s the real story.

The Camera Isn’t What Should Get Your Attention

We’re entering a world filled with inexpensive sensors.

Cameras.

Doorbells.

Cars.

Phones.

Drones.

Access-control systems.

Retail cameras.

Traffic infrastructure.

The individual sensor isn’t necessarily remarkable.

What’s remarkable is what happens when AI can continuously convert billions of observations into structured, searchable information.

A human could never watch millions of photographs every day.

Software can.

That’s what AI changes.

It turns surveillance from:

Someone might see you

into:

Someone can search for you later.

And that’s why debates about systems like Flock shouldn’t focus exclusively on whether cameras exist.

The important questions are:

Who can search the data?

What can they search for?

How long is it retained?

Who can share it?

Who audits those searches?

What happens when someone abuses access?

And what happens when somebody physically steals the hardware collecting it?

Because the most powerful part of modern surveillance isn’t the camera watching the road.

It’s the computer that remembers what the camera saw.

70% of all cyber attacks target small businesses, I can help protect yours.

#Cybersecurity #Privacy #FlockSafety #Surveillance #DataProtection

Someone really did steal a Flock surveillance camera and tear it apart. The viral “23,040 license plates per second” claim appears bogus—but what researchers ACTUALLY found is crazier: 1.6 MILLION images from about 21 days, 27,321 video clips, software that detects people, and an encryption key stored on the device.

Share this post
See some more of our most recent posts...