Hackers accessed and extracted stored data and decryption keys from Flock Safety roadside camera systems, releasing evidence of how the cameras detect and track people and vehicles
Incident ● Confirmed 72% confidence first seen
Hackers removed a Flock roadside camera and copied stored data from the device, including recovering an encryption key used to unlock videos tied to thousands of detections. The released files indicated the system can detect people as well as cars and that local records were searchable, prompting heightened scrutiny and some jurisdictions to halt use. In related reporting, leaked demo/login activity also described a Flock-branded “police” account used to run searches against live automated license plate reader camera systems.
Decision brief
- What changed
- Hackers physically removed a Flock Safety roadside camera, copied data stored on the device, and recovered an encryption key that unlocked videos tied to thousands of detections. Reporting on the released files said the camera software detected people as well as vehicles, exposed searchable local records within a broader network, and added scrutiny alongside separate leaked audit activity involving a Flock-run demo “police” account querying live systems.
- Why it matters
- This raises immediate security and governance questions for any organization operating edge AI devices: if data and keys can be extracted from a field device, physical compromise can become a data-compromise event. It also turns a product-positioning issue into a leadership issue, because the reporting suggests broader detection capabilities and live-system demo practices that may differ from stakeholder assumptions, increasing regulatory, contractual, and public-trust risk. Some jurisdictions reportedly paused use, so leaders should treat this as an operational and procurement review trigger rather than only a technical incident.
- Evidence
- The core facts are supported across two separate outlets’ reporting on the extracted camera files: 404 Media and Ars Technica both reported that hackers copied onboard storage, recovered an encryption key from the device, and exposed evidence the software detects people as well as vehicles. A separate 404 Media report cited audit records for a Flock-created “Flock City PD” demo account running searches on live ALPR systems, adding consistency to concerns about governance and system use.
- What remains uncertain
- The coverage does not establish how widespread this device-level weakness is across Flock’s installed base, whether the extracted keying approach was unique to the compromised unit, or what compensating controls existed centrally. It also remains unclear how representative the leaked demo-account activity was of normal operating practice and which reported safeguards were active, bypassed, or misconfigured at the time.
- Monitor next
- Watch for Flock’s documented remediation details—especially any confirmed changes to on-device key storage, physical tamper protections, search controls, and customer/jurisdiction suspension or restart decisions.
Analytical support, not advice — assumptions and open questions stated above.