Has Flock Safety been hacked?

7 min readGuide

Flock now says some of its data was taken. In a notice sent to customers in late September 2026, it said device names and locations, plus the type of each device, accurate as of December 2025, were “unlawfully accessed and exfiltrated” through an exposed map access key, and that no plate images, video or CJIS data were exposed. Researchers have separately found flaws in Flock devices, which is a different finding from confirmed data theft.

What Flock told customers in September 2026

Flock emailed customers a security incident notice in late September 2026. Researcher Joshua Michael posted the full text. On September 29, Hartford TV station WFSB reported that Connecticut police departments had received the same email and quoted its wording.

According to the notice, a website that went up on September 22 showed where customer devices were as of December 2025. The records included each device's name, location and type. Flock says the data came from a third-party map service and that no license plate images, video footage or CJIS criminal justice data were exposed.

Flock says the same person reported an exposed map access key to its security team in November 2025. According to the notice, Flock confirmed the problem, fixed it and closed the issue in December 2025, and saw no sign of unauthorized access at the time. Flock now says the person used the key in late 2025 to take and keep the data. It says it has notified law enforcement.

Flock device names can reveal more than a dot on a map. The Intercept reported that names in the dataset typically include a street address and sometimes other identifying details. Flock told WFSB the records covered decommissioned, planned and in-service cameras, as well as devices such as Raven gunshot detectors and drones.

Flock's notice as posted by Joshua Michael · WFSB I-Team report · Our brief on the map takedown request

What is confirmed and what is still unknown

Keep the distinction. A flaw demonstrated in a Flock device shows what was possible. Confirmed data theft shows what actually left the company. Flock's September notice is the first public statement we found in which the company says its data was taken.

Flock's lawyers described the incident more broadly than the customer notice did. In a September 25 cease-and-desist letter to Michael, published by the Flock-tracking site Footnote 4a, they said the information included proprietary and confidential material belonging to Flock and its customers. The letter does not list that material.

When we checked on October 4, Flock's January 6, 2026 blog post answering whether it had been hacked still said no. Its security advisories page, last updated September 15, still listed no published advisories.

Scroll horizontally to compare all columns.

Status of the main claims as of October 4, 2026
ClaimStatusBasis
Device names and locations were takenConfirmed by FlockCustomer notice
Plate images, video or CJIS data were takenFlock says no. We found no independent forensic reportCustomer notice
Information belonging to customers was takenFlock's lawyers say yes, without detailSept. 25 demand letter
When the reported key stopped workingDisputed. Flock says December 2025, while Michael wrote it was unpatched on Jan. 7, 2026Notice and Michael's write-up
Which police agency is investigatingNot disclosed. Flock did not tell WFSBWFSB
Researchers broke into Flock devicesShown on specific devices, separate from this incidentGainSec and WIRED

Footnote 4a's account and the demand letter · Flock's security advisories page

Device flaws researchers demonstrated

In May 2025, Flock posted an advisory about flaws in its plate readers and gunshot detectors, including an enabled debug interface and hardcoded credentials. Flock said exploiting them required physical access to a device.

Security researcher Jon Gaines began publishing write-ups on Flock devices in June 2025. His November 5 white paper covered 45 issues. An update a week later counted 51. Flock replied on November 6 that exploiting the flaws would require physical access and detailed hardware knowledge, and that customers did not need to act.

In December 2025, 404 Media reported that livestreams and administrator panels for at least 60 Flock Condor video cameras were open to the internet without a password. Technologist Benn Jordan found the exposure first.

Michael's January 9, 2026 write-up describes two exposed mapping credentials. One had access to 50 private map items, and he lists it as fixed in June 2025. Michael says he did not open those items, so their contents remain unverified. The other credential reached camera locations and was the flaw he reported in November 2025.

In September 2026, WIRED and 404 Media reported that a group called stegan0gram took down a Flock camera and copied its storage. According to WIRED, a key stored on the device gave access to its recorded media. WIRED's analysis of the logs found about 1.6 million images of roughly 50,200 vehicles over about 21 days. Flock told WIRED that removing or tampering with its cameras is illegal and that it had received no report through its disclosure program.

Flock's May 2025 advisory · Gaines's white paper post · WIRED on the removed camera · Our brief on the camera teardown

What the 2026 Bishop Fox test found

Flock hired security firm Bishop Fox for its 2026 penetration test, which ran from January 12 to March 27. Flock's summary, published September 22, lists 36 issues, including two rated critical and seven rated high. Flock says Bishop Fox verified fixes for every critical and high finding, and that customers can download the full report.

Flock chose to leave one medium finding open. First-generation Falcon cameras run Android 8.1, and Flock says it patches that software itself instead of replacing the hardware. The summary also says older plate readers now use Secure Boot, which addresses a reported attack on stolen devices.

The Bishop Fox summary says no customer data or systems were accessed by anyone outside Flock as a result of the testing. Three days later, Flock's lawyers wrote that the exposed key had been used in November 2025, about two months before testing began, to take confidential data. Footnote 4a has asked why the summary left that out.

Flock's Bishop Fox summary · Our brief on the audit

Timeline of reported Flock security events

Dates come from the source named in each row. Where accounts differ, both are shown.

Scroll horizontally to compare all columns.

Flock security findings and incidents, 2025 to 2026
DateEventSource
May 5, 2025Flock posts an advisory on plate reader and gunshot detector flaws it says require physical accessFlock
June 19, 2025Jon Gaines publishes his first Flock device write-upsGainSec
Nov. 5–6, 2025Gaines releases a white paper on 45 issues, and Flock respondsGainSec and Flock
Nov. 13, 2025Joshua Michael reports an exposed map access key to FlockThe Intercept
Dec. 2025Michael downloads device location data. Flock says it closed the issue that monthThe Intercept and Flock notice
Dec. 22, 2025404 Media reports at least 60 Condor camera feeds open to the internet404 Media
Jan. 6, 2026Flock posts that it has never been hackedFlock
Jan. 9, 2026Michael publishes his researchMichael
Jan. 12 – Mar. 27, 2026Bishop Fox penetration testFlock
Sept. 16, 2026WIRED and 404 Media report on data copied from a removed cameraWIRED
Sept. 22, 2026Flock publishes its Bishop Fox summaryFlock
Sept. 22 or 23, 2026Michael's device map goes online. Flock says the 22nd, The Intercept the 23rdFlock notice and The Intercept
Sept. 25, 2026Flock's lawyers send Michael a cease-and-desist letterFootnote 4a
Late Sept. 2026Flock emails customers its incident notice. The exact send date is not publicWFSB
Sept. 29, 2026WFSB reports the notice. The police chief in Ledyard, Connecticut says he is moving to end the town's Flock contractWFSB

The Intercept on the device map · Michael's January 2026 write-up

What to ask your police department after a vendor breach

If a police department or sheriff near you uses Flock, it should have the September 2026 notice. Ask for documents, and name the record you want.

The device list matters most. The notice covers device names and locations, and your local agency can tell you which of its devices were in the data. Ask for the contract's security terms too. They show what Flock promised to report and when.

Keep each answer tied to its date and scope. A reply covering plate readers says nothing about video cameras or gunshot detectors. And a missing record leaves a gap in the file. It doesn't prove that nothing happened.

Copies of any security incident notice, update or correspondence the department received from Flock Safety about unauthorized access to device location data, from September 1, 2026 to the date of this request.

Any record listing which of the department's Flock devices were in the data Flock described in that notice, including device names as they appear in Flock's system.

The security, breach notification and incident response terms in the department's current Flock agreement and order forms.

Any copy of Flock's 2026 Bishop Fox penetration test report or retest report that the department downloaded or received.

How to request Flock audit logs · Find your agency's transparency portal · Records request tools · What happens when a city cancels Flock

See the cameras near you

The live map is free and needs no account.

Open the live map

Questions people ask

Has Flock Safety had a data breach?
A notice Flock sent customers in September 2026 says device names and locations were unlawfully taken through an exposed map key in late 2025. Flock says plate images, video and CJIS data were not exposed. Its January 2026 post saying it had never been hacked came before that notice.
Were license plate images stolen in the September 2026 incident?
Flock says no plate images, video footage or CJIS data were exposed. As of October 4, 2026, we found no independent forensic report confirming or contradicting that account.
Can Flock cameras be hacked?
Researchers have demonstrated flaws in specific Flock devices, most requiring physical access. In 2026, a group also copied stored data from a camera it removed. Flock says it has fixed many of these issues. A device flaw is a separate finding from data stolen from Flock's cloud.
What was the flocksurveillance.org map?
A map Joshua Michael published in September 2026 using device data he downloaded in December 2025. The Intercept reported that it showed more than 300,000 Flock devices. A firm that said it was acting for Flock filed a trademark complaint seeking the map's removal.
Is FlockDetour connected to Flock Safety or the leaked data?
FlockDetour is independent of Flock Safety. This guide reports what Flock, researchers and news outlets have published. The sources for FlockDetour's map are listed on the sources page.

Who owns Flock Safety? · How to request your city's Flock audit logs · Why are Flock cameras controversial? · What are Flock cameras, and how do they work? · What happens when a city cancels Flock cameras? · All guides · Live camera map · Get the app

Sources

FlockDetour is independent and is not affiliated with or endorsed by Flock Safety or any surveillance vendor.