A group of hackers ripped down a Flock Safety surveillance camera from above a US roadway and copied much of its internal data. Collectively calling themselves stegan0gram, the group took down the roadside camera and accessed its Android-based operating system. The group also extracted a near-complete copy of the data stored on it before handing the material to 404 Media and WIRED for analysis.
Both WIRED and 404 Media identify the physical setting. But they do not publicly identify the exact location of the hacked camera in their reports. But based on GPS coordinates from the recovered logs, security researcher Micah Lee placed the hacked device in Wauwatosa, Wisconsin, a suburb northwest of Milwaukee.
The hackers found, inside roughly 21 days of recoverable logs, that the single camera photographed about 50,200 vehicles, generating an astonishing 1.6 million images.
A typical passing vehicle triggered around 28 photographs, while some produced over 100. The device also contained more than 27,000 short MP4 video clips.
The recovered material showed that the camera’s software is not only tracking license plates. It also detects people, vehicles, bicycles, and license plates, recording where each appears in the frame and assigning a confidence score to every detection.
In one example, the system apparently mistook an American flag patch on a motorcyclist’s saddlebag for a license plate. Sometimes, it also set aside bumper stickers, dealership frames, and other graphics as if they were plates.
Hidden in an unencrypted partition
After accessing the camera’s Android system, the group found several storage partitions, including unencrypted areas labeled “vendor” and “media.”
The media partition contained an encryption key, allowing them to unlock another partition of the device that held many of the stored photographs and videos. That finding is no small matter. Previously, Flock claimed that its cameras use on-device encryption and that images are retained only briefly before being transmitted to its servers.
The stegan0gram said they don’t want to simply tear down the device; they wanted to understand the technology behind the camera. “Why just destroy them when we can reverse engineer them and find the secrets of those spying on us?” one member of stegan0gram told reporters.
“We liberated hardware in the field, disarmed them, and proceeded with reverse engineering of the cameras and associated solar equipment.”
A smartphone-like computer hidden inside
The investigation found that the camera contains a processor comparable to those used in mid-range smartphones and runs about 20 Flock-built applications.
Those programs handle tasks including motion detection, photography, image classification, cellular uploads and remote software updates.
The camera itself does not appear to perform the most sophisticated license-plate and vehicle identification.
Instead, it captures and processes images before sending information to Flock’s servers, where the system appears to identify the plate and characteristics such as the vehicle’s make, model, and color.
The recovered software also showed that the device’s computer-vision system can detect people. WIRED and 404 Media found no evidence that the camera used facial recognition beyond the functions built into Android itself.
One camera. 1.6 million images.
The scale of the data recovered from just one roadside device revealed that in roughly three weeks of recoverable logs, it photographed 50,200 vehicles, generated 1.6 million images, and stored over 27,000 video clips. These represent only what remained on the device when it was obtained, as older records had already been overwritten or were no longer recoverable.
Flock maintains that unauthorized removal and tampering with its cameras is illegal. It also said it had not received a vulnerability report through its official channels, limiting its ability to assess the hackers’ claims.
The incident, according to Flock, did not amount to a demonstrated breach of Flock’s centralized cloud infrastructure. Instead, it involved physical access to a single deployed camera and the data stored on that device.
Flock’s expanding surveillance network
The revelations come as Flock faces increasing scrutiny over its rapidly expanding network of automated license plate readers (ALPR)..
WIRED found that records from Flock cameras in Alpharetta, Georgia, for example, could be accessed by more than 2,000 agencies, including police departments, colleges, airports and federal entities.
The system has also come under criticism after reports that police officers used the national network for searches connected to immigration enforcement and, in one Texas case, to locate a woman who had self-administered an abortion.
Rep. Thomas Massie (R-Ky.) unveiled the Flock-Off Act early this month. The bill seeks to restrict the use of federal funds for ALPRs and biometric surveillance cameras. Specifically, the measure would block any attempt to purchase, install, maintain, operate, or upgrade ALPRs and biometric surveillance cameras for municipalities and local law enforcement.
Meanwhile, communities across the United States have begun removing or rejecting Flock cameras, while other devices have been vandalized or torn down.
The stegan0gram took the device apart and opened a window into what the roadside system was actually doing rather than simply pulling a camera from a pole and walking away, resulting in a trove of images, videos, software, and logs offering an unusually detailed look at a technology designed to quietly watch America’s roads.

