A recent Flock camera software hack has revealed new details about how Flock Safety’s automatic license plate reader (ALPR) cameras work. Hackers removed a Flock camera from a roadway and copied a large amount of data from the device. The recovered files gave researchers a closer look at the software used to detect vehicles, people and other objects.
The incident has also raised fresh questions about the security and privacy of camera-based surveillance systems.
What the Flock Camera Hack Revealed
According to the analysis of the recovered files, the camera does much more than simply photograph license plates. Its software can detect vehicles, people, bicycles and other objects.
When a vehicle passes the camera, the device can take a rapid series of photographs. A typical vehicle generated around 28 images, while some produced more than 100 images. The camera then selects useful frames and sends the information to Flock’s servers through a cellular connection.
The camera itself apparently does not identify the vehicle’s make, model, color or license plate. That processing appears to take place on Flock’s servers.
During about 21 days of recovered activity, the camera photographed roughly 50,200 vehicles and generated around 1.6 million images.
The Camera Can Also Detect People
One of the more notable findings was that the software running on the camera explicitly detects people.
Researchers tested the recovered software models using images and video clips. The system successfully detected people in several clips, although the number was small because the camera was positioned above a roadway and mainly focused on traffic.
The software also showed some mistakes. In certain cases, it treated bumper stickers, dealership frames and other graphics as license plates. In one example, an American flag patch on a motorcycle was incorrectly identified as a plate.
Flock has stated that its cameras do not use facial recognition. The analysis found no evidence that face recognition was actively used by the camera beyond capabilities included in the Android operating system.
Security and Privacy Questions

The breach also exposed concerns about how data is protected on the camera. Hackers reportedly found an encryption key stored on the device that allowed them to unlock some of the stored media.
The discovery is significant because Flock has described its devices as protected by on-device encryption. Earlier security research had also identified vulnerabilities that could provide deep access to the camera when someone had physical access.
The system’s wider network has become another point of debate. Flock records can be searched by local agencies and, in some cases, other agencies across the country.
| Feature | What the analysis showed |
|---|---|
| Vehicle detection | Yes |
| People detection | Yes |
| License plate detection | Yes |
| Bicycle detection | Yes |
| Facial recognition | No evidence of active use |
| Images generated | About 1.6 million in recovered periods |
What Happens Next?

The Flock camera software hack highlights how much information modern surveillance devices can collect and process. It also shows why security protections matter when cameras are installed in public spaces.
Flock said unauthorized removal and tampering with its cameras is illegal and pointed to its vulnerability disclosure process. Meanwhile, critics and activists continue to question the growing use of ALPR technology.
The incident is likely to keep the discussion around surveillance, cybersecurity and public privacy active as communities decide how these systems should be used.
