Hacker collective stegan0gram dismantles a Flock camera, recovering an encryption key and showing it runs ~20 apps on a midrange smartphone-grade processor
While people around the U.S. are tearing down Flock cameras, one group of hackers went a step further: extracting the camera's software too.
404 Media
Context & Ripple Effects
Flock’s camera network had already been deployed through more than 500 police departments by 2021, making the hardware endpoint consequential beyond any one installation. In August 2026, reconstructed login-page code pointed to OS Investigate’s integration of plate scans with arrest records and case files, extending the importance of how collection devices and back-end systems are secured.
The teardown turns a largely opaque capture device into an inspectable software stack. It follows a broader record of surveillance-camera exposure, including the claimed Verkada breach affecting camera feeds and archives, but is distinct in showing what can be recovered directly from a device.
First-order effects
Flock must assess whether the recovered encryption key and roughly 20-application device stack require credential rotation, software changes, or other remediation.
Police departments and other Flock customers gain concrete evidence to evaluate the security implications of physical access to deployed cameras.
Second-order effects
Agencies using Flock’s network face added pressure to treat camera hardware as a security boundary, rather than relying only on protections around central search and analytics systems.
Vendors selling networked surveillance equipment will face closer scrutiny of whether encryption secrets, application inventories, and device software can be extracted from field hardware.
Third-order effects
As capture devices feed broader investigative systems, endpoint security becomes part of the governance case for surveillance networks, not merely an engineering detail.
If such teardowns become routine, procurement standards may shift toward independently reviewable hardware security and clearer accountability for compromise of field devices.
The trend: Networked surveillance is evolving from standalone camera deployment toward integrated data systems whose trust depends on the security of the devices that collect the data.
Flock is not a license plate recorder, despite what defenders claim. It is a midrange Android taking millions of pictures & sending a lot of them to Flock. Makes you wonder: what else is Flock doing with those photos?
Still coming to terms with the fact that Flock is a badly secured Android on a pole chanting “Who's a good boy?!” to itself while spying on the world..
@dmehro The best part of this story is that the files were encrypted, and the key to unencrypt them was also found inside the camera. This is like having a bank vault door with the key duct taped to the front of it. COMPLETE INEPTITUDE
NEW: Hackers cut down a Flock camera, dumped its internal storage, and shared the files. It includes thousands of videos and logs showing how the device took images of 50,000 vehicles in days It reveals in new detail how Flock tracks vehicles and people. https://www.wired.com/...
Nothing says we don't take security seriously like leaving encryption keys unprotected at rest. Finding these keys sadly is not an uncommon occurrence …
I've got a lot of work to do today but I'm getting absolutely nerdsniped by the new Flock dataset. You can download it here. It's all of the Android partitions extracted from a Flock device ddosecrets.org/article/floc... [embedded post]
Analysis of the data “shows that software running on the device explicitly detects people as well as vehicles, license plates, and bicycles. The camera can produce dozens of images of a single passing vehicle and, according to several weeks of recovered logs, generated more than…
“Hackers ripped down a Flock camera above a roadway, made a near-complete copy of the data stored inside it, and shared the files with 404 Media and WIRED, revealing in new detail how exactly Flock Safety's cameras track the movements of both vehicles and people.”
NEW: When @dmehro.bsky.social at @wired.com and @josephcox.bsky.social at @404media.co both got handed the full contents of a Flock camera, we worked together to figure out what it revealed. (WIRED's below, 404's version here: www.404media.co/hackers-stol...)
Did we expect Flock to care any more about security than it does privacy? Hackers dismantled and reverse-engineered a camera. It's missing eight years of Android security updates, and its kernel is nine years and 69 releases (!) out-of-date. …