Follow
Subscribe via Email!

Enter your email address to subscribe to this platform and receive notifications of new posts by email.

Inside a Downed Flock Camera, Stored Data Reveals Tracking Reach

Hackers dismantled a roadside Flock camera and extracted internal drives, uncovering 1.6 million images, pedestrian detection models, and system errors while Boston drops the vendor.
TechRadar illustration showing an automated license plate reader device mounted above traffic.

Hackers from the stegan0gram collective climbed a roadway pole to rip down an automated Flock camera, disassembling its casing to expose the inner workings of municipal surveillance. A joint investigation by 404 Media and WIRED revealed that the seized hardware contained unencrypted storage partitions and a hardcoded cryptographic key unlocking thousands of recorded files. The recovered database demonstrates how widespread Flock cameras have become across municipal roadways. Analysis of the camera logs proved that the device generated 1.6 million images while actively tracking pedestrians and cyclists. [2]

Flock Camera Hardware Reverse Engineered

Activists took physical possession of the pole-mounted reader above an active roadway, disarmed its electronics, and reverse-engineered both the optical assembly and the accompanying solar power gear. One hacker from the stegan0gram collective stated in an interview that the group wanted to inspect the technology spying on the public rather than merely destroying municipal street hardware. Examining the internal hard drive revealed an Android operating system split into distinct storage volumes. Two specific disk partitions (isolated functional sections of local storage) remained completely unencrypted, labeled vendor and media. The unencrypted media volume housed a stored cryptographic key that successfully unlocked protected video and still recordings captured during roadside operations. [2]

The physical hardware was seized. Stegan0gram copied the local flash memory before publishing procedural instructions to encourage similar teardowns across the country. [2]

Security researcher Jon Gaines, known online as GainSec, reverse-engineered a Flock automated license plate reader in early 2025 to disclose security flaws enabling root-level administrative access. Flock Safety acknowledged those vulnerabilities at the time but minimized their practical severity, publicly insisting that physical tampering would never expose stored footage because vehicle captures remain on local hardware only temporarily before cloud transmission. The data recovered by 404 Media and WIRED directly refutes that corporate defense. The device operates with a processor comparable to components found in midrange smartphones and runs about 20 Flock-built apps dedicated to movement detection, image classification, data uploads, and remote software updates. Similar physical extraction techniques appear in broader reverse engineering leaked device firmware, showing how hardware access exposes internal software configurations that vendors describe as secure. [2]

Stored Logs Reveal Pedestrian Detections

Recovered operating logs documented 21 days of traffic monitoring across several observation periods. During those windows, the single roadside unit photographed roughly 50,200 vehicles and generated 1.6 million images. Older logs were overwritten. A typical operational day logged around 3,300 vehicles, reaching a high of 4,454 vehicles during peak traffic flow. Each vehicle passage prompted the camera to fire rapid bursts of photos. A standard crossing generated about 28 distinct frames, though some produced more than 100 images across varying exposure levels to capture plates and wide street scenes. [2, 3]

How do hackers get your information from roadside sensors? Embedded computer-vision models explicitly detect people and bicycles, recording spatial coordinates alongside confidence scores. WIRED extracted these models and verified that the software readily identified pedestrians and human faces. The detection models monitor far more than automobile tags. [3]

TechRadar report examining a downed Flock camera and municipal automated surveillance policies.
TechRadar examined automated license plate reader hardware and surveillance accountability following policy reversals in Boston. (Credit: TechRadar)

Reporters evaluated the vision software against 27,321 short videoclips preserved in the internal storage. Each clip was an MP4 video lasting one to two seconds, recorded at 1,024 by 768 pixels. No audio was recorded. The models detected people in 11 clips, all featuring individuals riding motorcycles. The license plate reader also misidentified bumper stickers, dealership frames, and promotional decals. In one recording, the software cropped an American flag patch on a motorcyclist’s saddlebag as an official tag. [3]

Read these too!

Storage Crashes and Internal Log Messages

System telemetry logs revealed that the roadside unit experienced severe performance degradation under continuous recording cycles. The camera logged more than 27,000 separate no space left on device errors while attempting to store full-resolution visual frames on local storage. Tens of thousands of related application crashes, buffer overruns, and unexpected hardware reboots plagued the device during active deployment. Local flash memory constantly struggled to manage rapid photograph bursts. Cellular transmitters uploaded cropped vehicle captures to corporate cloud servers, but uncompressed visual data overwhelmed local physical partitions. [2]

System storage ran out repeatedly. The camera continued attempting to write photographic frames until internal operating services collapsed. [2]

Firmware logs also preserved playful diagnostic messages embedded by Flock Safety software engineers. A background watchdog service (a diagnostic process that periodically tests system health) executed every two minutes to confirm hardware stability, recording the sentence: Who’s a good boy?! More than 12,000 iterations of that pet-inspired phrase appeared in the recovered diagnostic logs. When unexpected system failures forced an operating reset, an auxiliary recovery service printed a lighthearted exit message: A reboot was requested! ¡Adiós, Amigos! These informal internal diagnostics contrasted sharply with corporate marketing portraying the devices as hardened, enterprise-grade public safety infrastructure. [2]

Boston Cancels Contract Over Data Sharing

While physical hardware leaks revealed device capabilities, municipal governments initiated administrative pushback against Flock Safety’s surveillance infrastructure. Boston city officials and the Boston Police Department announced that the municipality will no longer use Flock cameras. The decision followed a municipal report reviewing a pilot program conducted in 2025. City investigators discovered that Flock shared local camera data with outside law enforcement agencies despite an explicit contractual agreement stipulating that external data sharing must remain disabled. Flock had previously confirmed to municipal leadership that inter-agency data distribution was shut off. [1]

Boston halted its deployment. However, privacy advocates caution that Boston’s departure from Flock does not signal the termination of automated vehicle surveillance across the city. The Boston Police Department initiated alternative trials with two competing Automatic License Plate Recognition (automated license plate reader) vendors. Boston began testing Motorola technology in February, followed by an Axon pilot initiated in June. The city dropped Flock while continuing automated license plate tracking through rival contractors. Municipal administrators sought tighter control over external data pipelines rather than eliminating roadway camera surveillance altogether. [1]

WIRED coverage investigating decrypted files recovered from a physical Flock camera.
WIRED and 404 Media analyzed extracted storage partitions and computer-vision models recovered from the roadway device. (Credit: WIRED)

Controversy surrounding Flock’s nationwide sharing network extends well beyond Boston. In Alpharetta, Georgia, records generated by local municipal Flock cameras were accessible to more than 2,000 external agencies across the country. Authorized search access included out-of-state police departments, college campus security forces, airport authorities, and the Office of Inspector General for the federal General Services Administration. Previous investigations by 404 Media revealed that municipal police officers used the nationwide network to conduct license plate searches for Immigration and Customs Enforcement (ICE), bypassing local statutory bans on cooperating with federal immigration authorities. In Texas, a police officer searched nationwide Flock records to track a woman who self-administered an abortion. [2]

Audit Loopholes and Growing Backlash

Search accountability safeguards have failed to stop unauthorized lookups. Public records obtained by the Electronic Frontier Foundation (a digital civil liberties organization) showed that officers routinely bypassed justification requirements when searching Flock databases. Officers submitted flippant explanations such as LMAO, idk lol, TBD, and Sexy, while others typed random character strings. Flock introduced preset menu options like Traffic infraction and Other, but critics argue standardized drop-down categories make searching databases without legitimate suspicion even easier. [1]

Can administrative checkboxes prevent surveillance overreach? Advocates argue that mandatory judicial warrants represent the only effective safeguard against search abuse. [1]

A Flock Safety spokesperson stated: “The unauthorized removal and tampering of a Flock camera is illegal.” The company noted that it maintains a public Vulnerability Disclosure Policy, emphasizing that no vulnerability report was received through official channels. Flock insists that researchers must submit findings through authorized reporting portals. Meanwhile, an unnamed hacker from stegan0gram acknowledged the legal hazard: “Being investigated is a legit concern and something we are trying to avoid. I’m sure our actions have attracted some attention as it is, but we are careful and try to keep a low profile.” [1, 2]

Multiple individuals face arrest across the country for damaging roadway cameras, prompting one police department to deploy a fake 3D-printed camera housing to catch saboteurs. Former Pawtucket, Rhode Island police officer Noel Pichardo warned that vigilantism could solidify official support for surveillance: “I think that type of vigilantism will only crystallize the police and the state at large in their belief that this tool is necessary. The longer the state continues to ignore the groanings of their constituents who are against this type of surveillance, the more this will happen.” Community resistance continues to escalate. [1, 2]

Sources
  1. ONLINE NEWS Hector, H. (2026, September 16). Hackers just extracted a scary amount of data from a downed flock camera, as Boston reveals it won’t use Flock anymore over data sharing concerns. TechRadar. [Article Link]
  2. ONLINE NEWS Mehrotra, D., & Cox, J. (2026, September 16). Hackers got inside a Flock camera. Its data shows how the system really works. WIRED. [Article Link]
  3. ONLINE NEWS 404 Media & WIRED. (2026, September 16). Joint investigation into decrypted Flock Safety automated license plate reader data. WIRED. [Article Link]

Leave a Comment

Related Posts
Total
0
Share