Hackers leak police raid plans, confidential reports, AWS private keys, and other sensitive data from the servers of ODIN, which makes apps for the US police
Leaked files reveal tactical plans for police raids, surveillance, and facial recognition — Detailed tactical plans …
Context & Ripple Effects
This is the second ODIN exposure in under two weeks: on January 11 its SweepWizard app was found leaking officer locations and names for 5,770 suspects through a simple misconfiguration, and now attackers have gone deeper, dumping tactical raid plans, surveillance and facial-recognition documents, confidential reports, and AWS private keys straight off the company's servers.
The playbook has precedent — the 2015 Hacking Team breach showed how a single vendor selling tools to governments becomes a mass-exposure event when its own defenses fail, and DDoSecrets' 270 GB dump of police department data in 2020 established that activist leakers actively target US policing infrastructure.
First-order effects
- Police departments relying on ODIN apps must assume their operational plans — including raid tactics and surveillance targets — are in hostile hands, forcing immediate operational review of any raids or investigations documented in the leaked files.
- The exposed AWS private keys mean whatever cloud infrastructure ODIN runs is now directly attackable, putting every department's data on those servers at risk beyond what was already published.
Second-order effects
- Municipal buyers of police software face pressure to treat vendor security as a procurement criterion rather than a checkbox, after two ODIN failures in one month made 'trusted police vendor' a contradiction in terms.
- Cloud providers and security auditors serving government-adjacent SaaS firms gain leverage: a leaked key tied to AWS infrastructure gives Amazon and competitors a concrete sales argument for hardened key-management offerings to this customer base.
Third-order effects
- If the pattern holds — Hacking Team in 2015, DDoSecrets' police dump in 2020, the DC Police ransomware breach in 2021, and now ODIN twice in two weeks — law-enforcement technology consolidates around vendors who can survive being breached, because the alternative is operational secrets published by activists or criminals.
- Policing's dependence on small commercial app vendors turns departmental secrecy into a supply-chain problem: the weakest vendor, not the department, sets the security floor for raid planning and surveillance data.
The trend: US police software vendors are becoming recurring breach targets, converting law-enforcement operational secrecy into a supply-chain security problem that activists and criminals alike can exploit.