How a Stolen Flock Camera Exposed a Surveillance System Built on Paper-Thin Security
Hackers pulled a Flock surveillance camera off a pole and found the encryption key sitting on the device itself. The breach reveals how AI-powered camera systems marketed as impenetrable are actually built on dangerously thin security assumptions.
The key was in the lock
A group calling itself stegan0gram didn’t need sophisticated remote hacking tools to compromise Flock’s surveillance network. They needed a ladder, a pair of pliers, and about fifteen minutes.
Last year, members of the group removed a Flock camera from above a roadway, disarmed the hardware including its solar equipment, and opened it up. What they found inside would make any security engineer uncomfortable: an encryption key sitting openly on the device, plus unencrypted storage partitions containing thousands of video clips and over a million vehicle images. The investigation, conducted jointly by 404 Media and Wired, did not breach Flock’s cloud servers. It required nothing more than physical access to a camera mounted publicly on a pole.
This is the story that keeps repeating itself in the surveillance industry. Companies market AI-powered monitoring systems as fortress-grade operations. In practice, they often behave like locked filing cabinets with the combination written on a sticky note.
What was inside the camera
The findings are specific and unsettling. Inside the Android-based device, the hackers found unencrypted partitions holding 27,321 MP4 video clips at 1024 by 768 resolution. Each clip lasted roughly one to two seconds, contained no audio, and was separate from higher-resolution still images. Much of the more sensitive storage remained encrypted and inaccessible, which means Flock does have encryption layered somewhere. But the key that unlocked the accessible portion was stored on the device itself.
Over approximately twenty-one days across multiple observation periods, the camera had generated roughly 1.6 million images of about 50,200 vehicles. That works out to roughly twenty-eight images per vehicle on average, with some triggering more than a hundred captures. The camera selected and cropped useful frames before uploading them over a cellular connection. Plate reading and vehicle characteristic identification appeared to happen on Flock’s servers, not on the camera itself.
The software also detected people in eleven of the recovered videos, all involving motorcyclists. And the system was imperfect: the plate detector mistook bumper stickers and other graphics for license plates, including an American flag patch on a motorcyclist’s saddlebag. There was no evidence of active facial recognition in this particular deployment, but the fact that the system could detect people at all is worth noting.
More troubling than the data exposure were the error logs. The cameras threw more than 27,000 errors from failed attempts to save full-resolution images when storage was full, alongside tens of thousands of related crashes and reboots. A system that unstable is a system you should probably not trust with your city’s most sensitive surveillance infrastructure.
Flock’s response tells you everything
Flock’s response to the breach was characteristically thin. The company warned that unauthorized removal and tampering with its cameras were illegal and claimed it had received no report through its vulnerability disclosure process, saying it lacked sufficient detail to assess the claims. This is the same playbook used by companies that would rather prosecute the messenger than fix the mess.
More importantly, Flock had previously stated that physical access would not expose captured footage because images remained on cameras only briefly after upload. The investigation appears to contradict that claim directly. Data was clearly available on the device in substantial quantities.
The company has been on the defensive for some time now. Multiple cities have dropped Flock license plate readers following revelations about police officers using the system to stalk former partners and entering nonsense into database search fields to justify queries. In one California city, Flock even reinstalled cameras after the police department canceled its contract and physically took the units down.
The pattern, not the exception
This breach matters beyond Flock or beyond the United States. Any city or country deploying AI-powered surveillance cameras operates on essentially the same architecture: edge devices collecting data, cellular or satellite uplinks transmitting to central servers, and encryption meant to protect that data in transit and at rest. The assumption everywhere is that the data is safe unless someone breaks into the cloud infrastructure. Physical compromise is treated as a separate, unlikely problem.
It is not. As the stegan0gram investigation showed, physical access to these devices routinely grants access to significant amounts of data, often protected only by keys stored on the device itself. This is not a Flock-specific problem. It is a category problem.
The surveillance industry sells these systems as invisible, intelligent, and secure. The reality is messier. Cameras crash. Storage fills up. Encryption keys sit where anyone with a screwdriver can find them. Bumper stickers get read as license plates. The gap between the marketing and the engineering is where the public gets harmed.
Who wins and who loses
The companies selling these systems win by default. Their contracts are signed by municipal governments that lack the technical expertise to evaluate the security claims being made. When breaches like this surface, the companies retreat behind legal threats and procedural complaints rather than substantive answers. The data they collected remains collected. The contracts they hold remain active, even as cities quietly walk away.
The public loses twice. First, their images, their vehicles, their movements are recorded without meaningful consent. Second, when that data proves vulnerable, the recourse is limited. Cities may cancel contracts. Hackers may publish findings. But the footage exists whether anyone likes it or not.
What happens next
Several cities are already removing Flock cameras. That trend will likely accelerate as more technical details about these systems come to light. But removing Flock cameras does not solve the underlying problem. Other vendors sell similar systems with similar architectural assumptions. Until those assumptions change, the next breach is a matter of when, not if.
The more useful response would be regulatory. Requirements for how surveillance devices store encryption keys, how long data remains on edge devices, and what data is accessible through physical compromise should be codified into law, not left to vendor promises. Right now, they are not.
Flock’s latest headline is another stain on a company that already has too many. But the real story is simpler and more systemic: the AI surveillance industry is building the most widespread monitoring infrastructure in history on foundations that crumble under minimal physical pressure. That needs to change before the next camera comes down from the next pole.