TLDR
- A hacker collective called stegan0gram pulled a Flock Safety camera off a roadway and copied its storage.
- The camera’s “media” partition held an encryption key in the clear. That key unlocked the footage partition.
- One camera captured about 1.6 million images and 27,321 video clips in 21 days.
- Flock had claimed on-device encryption made physical access a dead end. The findings say otherwise.
What Happened in the Flock Camera Hack
The Flock camera hack didn’t start with a laptop. Someone physically pulled a Flock Safety camera off its mount above a road. Then they copied almost everything stored on the device.
The collective, calling itself stegan0gram, shared the data with 404 Media and Distributed Denial of Secrets. DDoSecrets passed a copy to WIRED. The two outlets analysed the files together and published their findings on 16 September 2026.
Here’s the thing. Flock has said its cameras use on-device encryption. Footage stayed safe, the company argued, even with the hardware in hand. This teardown put that claim to the test.
How the On-Device Encryption Key Was Found
The camera runs Android. Storage sits across several partitions, and two of them weren’t encrypted at all. One was labelled “vendor”. The other was labelled “media”.
That “media” partition is where things went wrong for Flock. Inside sat an encryption key. The hackers used that key to unlock a separate encrypted partition. That’s where the camera kept its videos and still images.
Take a moment with that. The lock was strong. The key was taped to the front door.
Not everything fell open, mind. According to the joint analysis, the most sensitive storage stayed encrypted. But the footage partition matters most to anyone worried about surveillance.
This wasn’t the first warning either. Back in 2025, researcher Jon “GainSec” Gaines documented root-level access flaws in a Flock camera. Flock played those down. The company said attackers needed physical access. And images, they said, only stayed on the device briefly after upload.
What One Camera Captured in Three Weeks
The numbers are a bit staggering for a single roadside unit. Over 21 days, the camera generated roughly 1.6 million images. Around 50,200 vehicles passed through its view.
Each passing car triggered a burst of photos. The average was about 28 images per vehicle. Some events produced more than 100. Each burst uses different exposure settings, which helps with plate legibility and the wider scene.
The device also stored 27,321 short video clips. These were MP4 files at 1024 x 768 resolution. Most lasted a second or two.
People showed up too. The software logged a person’s position in the frame along with a confidence score. Researchers found people in 11 of the recovered clips, all motorcycle riders. That’s likely down to the camera angle pointing at traffic rather than pavements.
Inside the Software: An IoT Security Lesson
The camera runs about 20 custom Flock-built Android apps. They handle motion detection, image capture, object classification, cellular upload and remote firmware updates. The processor is comparable to a mid-range smartphone.
Some jobs happen on the device. The camera spots people, vehicles, bicycles and plate-shaped objects. Those get cropped and sent to Flock’s servers alongside the original images.
The heavy lifting happens in the cloud. Actual plate reading and vehicle details like make, model and colour get worked out on Flock’s servers after upload.
What about facial recognition? Flock says its cameras don’t do that. The analysis found stock Android face detection libraries on the device. Nothing suggested they were switched on.
The plate detector isn’t exactly precise either. Tests found the detector flagging bumper stickers, dealer frames and decorative graphics as plates. One American flag patch on a motorcycle saddlebag got cropped as a plate.
The logs had a few surprises. A watchdog process wrote “Who’s a good boy?!” more than 12,000 times. That was just a check that the camera was still running. A reboot service signed off with “A reboot was requested! Adiós, Amigos!”
Flock’s Response and the Wider Picture
Flock’s reply was short. The company said removing and tampering with its cameras is illegal. Flock also said it takes security seriously. There’s a public vulnerability disclosure policy, and no report came through it. Without more detail, the company said it couldn’t assess the claims.
Flock has also stressed that its cloud infrastructure has never been compromised. That’s a fair point. This was one physical device, not a breach of the central platform.
Still, the scale of the network makes any weakness matter. Flock cameras now sit in more than 6,000 communities across the United States. In Alpharetta, Georgia, WIRED found one camera’s records were open to over 2,000 agencies.
Not everyone cheers the teardown approach. Noel Pichardo, a former Pawtucket police officer, spoke to 404 Media. He reckons this sort of vigilantism will only convince police the tool is necessary.
What the Flock Camera Hack Means for IoT Security
The Flock camera hack is a textbook case of a device trusting its own casing. Encrypt the data, then store the key on the same disk in the clear. That pattern turns up loads in embedded systems. Attackers know to look for it.
William Fieldhouse, Director of Aardwolf Security Ltd, put it this way: “Encrypting a partition means nothing if the key sits unencrypted next to it. We see this constantly in IoT security testing. Vendors treat the plastic casing as the security boundary, and it simply isn’t one.”
If you’re building or buying connected hardware, the lesson is simple. On-device encryption only counts when the key is protected. Keys belong in a hardware-backed secure element, not on a mountable partition. Test any public-facing device as though someone will open it up. Because eventually, someone will.
Picking the best penetration testing company for hardware work matters here. A proper tester opens the device up, just like stegan0gram did, only with permission. Plate reading and data sharing happen in the cloud, though. So web application penetration testing matters just as much.
Final Thoughts on the Flock Camera Hack
One camera. Three weeks. 1.6 million images and a key that shouldn’t have been there.
The Flock camera hack didn’t need a zero-day. It needed physical access and a bit of patience. Brilliant reverse engineering, whatever you make of the method, and uncomfortable news for anyone running fleets of IoT devices in public.
Does your organisation deploy connected hardware? Then find out what an attacker sees with the device in hand. Get a penetration test quote and find out before someone else does.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.