A significant security flaw in Flock’s automatic license plate recognition cameras has allowed hackers to retrieve 1.6 million images and 27,000 video clips from a single device, contradicting the company’s claims about data storage and encryption.

  • Hackers accessed extensive stored images and videos from one Flock camera.
  • Discovered device-stored decryption keys contradict company claims on encryption.
  • Employee morale plummets amid backlash, voluntary exit program launched.

What happened

Hackers associated with the stegan0gram collective exploited a vulnerability in Flock’s automatic license plate recognition cameras to extract around 1.6 million images and 27,000 video clips stored over a 21-day period from a single device. This data included images capturing approximately 50,200 vehicles and individuals, raising significant privacy concerns given the volume and nature of the material.

The hackers found two partitions in the camera’s Android operating system, including one labeled 'media' that contained a decryption key to access the stored media files. This discovery directly contradicts Flock’s earlier assertions that images and videos are only temporarily stored after upload and that no decryption keys are stored on the devices themselves.

Why it matters

This breach exposes critical flaws in Flock’s security and privacy practices, as sensitive data about the public—including both vehicles and people—was accessible and decryptable on the device. The company’s failure to secure data as claimed undermines trust in its surveillance technology and raises legal and ethical questions about how personal information is handled.

The incident exacerbates ongoing reputational issues for Flock, which has faced increasing public and regulatory scrutiny recently. The internal impact has been acute, with employee morale deteriorating so significantly that a large number of staff are reportedly seeking to leave the company, compounding operational challenges.

What to watch next

Flock has introduced a voluntary separation program offering severance packages to staff, which could lead to a notable workforce reduction. Observers should watch for official company responses addressing the security vulnerabilities, privacy safeguards being implemented, and any potential regulatory investigations following the exposure of this breach.

Industry stakeholders and privacy advocates will be monitoring how Flock manages its data security going forward, especially concerning encryption protocols and data retention policies. The outcome of this incident may influence broader surveillance camera standards and vendor accountability in the security technology sector.

Source assisted: This briefing began from a discovered source item from TechRadar. Open the original source.
How SignalDesk reports: feeds and outside sources are used for discovery. Public briefings are edited to add context, buyer relevance and attribution before they are published. Read the standards

Related briefings