Key facts
- Hackers copied data from a Flock camera and recovered an encryption key.
- The camera's software explicitly detects people, vehicles, license plates, and bicycles.
- One hacked camera captured 1.6 million images and logged approximately 50,200 vehicles.
- Flock cameras send images and data to company servers for analysis.
- The camera's processor is similar to those used in mid-range smartphones.
- Security researcher Jon Gaines previously documented flaws in Flock cameras.
Hackers have revealed new details about Flock Safety's cameras, demonstrating that the devices are capable of detecting people in addition to vehicles. The hackers, part of a collective calling itself stegan0gram, reportedly removed a camera, copied its data, and recovered an encryption key, which allowed them to access videos and logs.
Analysis of the recovered files, shared with 404 Media and WIRED, shows that the software running on the camera explicitly identifies people, vehicles, license plates, and bicycles. While much of the camera's sensitive storage remained encrypted, the recovered data indicates that a single device captured approximately 1.6 million images and logged over 50,200 vehicles across several periods totaling about 21 days.
The camera's computer-vision software can isolate details like bumper stickers and graphics. When a person is detected, the software records their location in the image and its confidence level. In testing, the models readily detected people, including in 11 out of 27,321 short video clips analyzed, all of which involved individuals on motorcycles.
Flock cameras photograph passing vehicles and transmit images and data to the company's servers for processing, including license plate reading and vehicle identification. The cameras themselves do not appear to perform these identifications. The recovered data suggests the camera's processor is comparable to those in mid-range smartphones and runs about 20 Flock-built applications.
In early 2025, security researcher Jon Gaines had previously documented flaws in Flock cameras that could allow for root-level access. Flock acknowledged these findings at the time but downplayed their severity, stating that footage would remain inaccessible due to encryption even with physical access.
