Has Flock Safety been hacked?
Flock now says some of its data was taken. In a notice sent to customers in late September 2026, it said device names and locations, plus the type of each device, accurate as of December 2025, were “unlawfully accessed and exfiltrated” through an exposed map access key, and that no plate images, video or CJIS data were exposed. Researchers have separately found flaws in Flock devices, which is a different finding from confirmed data theft.
What Flock told customers in September 2026
Flock emailed customers a security incident notice in late September 2026. Researcher Joshua Michael posted the full text. On September 29, Hartford TV station WFSB reported that Connecticut police departments had received the same email and quoted its wording.
According to the notice, a website that went up on September 22 showed where customer devices were as of December 2025. The records included each device's name, location and type. Flock says the data came from a third-party map service and that no license plate images, video footage or CJIS criminal justice data were exposed.
Flock says the same person reported an exposed map access key to its security team in November 2025. According to the notice, Flock confirmed the problem, fixed it and closed the issue in December 2025, and saw no sign of unauthorized access at the time. Flock now says the person used the key in late 2025 to take and keep the data. It says it has notified law enforcement.
Flock device names can reveal more than a dot on a map. The Intercept reported that names in the dataset typically include a street address and sometimes other identifying details. Flock told WFSB the records covered decommissioned, planned and in-service cameras, as well as devices such as Raven gunshot detectors and drones.
Flock's notice as posted by Joshua Michael · WFSB I-Team report · Our brief on the map takedown request
What is confirmed and what is still unknown
Keep the distinction. A flaw demonstrated in a Flock device shows what was possible. Confirmed data theft shows what actually left the company. Flock's September notice is the first public statement we found in which the company says its data was taken.
Flock's lawyers described the incident more broadly than the customer notice did. In a September 25 cease-and-desist letter to Michael, published by the Flock-tracking site Footnote 4a, they said the information included proprietary and confidential material belonging to Flock and its customers. The letter does not list that material.
When we checked on October 4, Flock's January 6, 2026 blog post answering whether it had been hacked still said no. Its security advisories page, last updated September 15, still listed no published advisories.
Scroll horizontally to compare all columns.
| Claim | Status | Basis |
|---|---|---|
| Device names and locations were taken | Confirmed by Flock | Customer notice |
| Plate images, video or CJIS data were taken | Flock says no. We found no independent forensic report | Customer notice |
| Information belonging to customers was taken | Flock's lawyers say yes, without detail | Sept. 25 demand letter |
| When the reported key stopped working | Disputed. Flock says December 2025, while Michael wrote it was unpatched on Jan. 7, 2026 | Notice and Michael's write-up |
| Which police agency is investigating | Not disclosed. Flock did not tell WFSB | WFSB |
| Researchers broke into Flock devices | Shown on specific devices, separate from this incident | GainSec and WIRED |
Footnote 4a's account and the demand letter · Flock's security advisories page
Device flaws researchers demonstrated
In May 2025, Flock posted an advisory about flaws in its plate readers and gunshot detectors, including an enabled debug interface and hardcoded credentials. Flock said exploiting them required physical access to a device.
Security researcher Jon Gaines began publishing write-ups on Flock devices in June 2025. His November 5 white paper covered 45 issues. An update a week later counted 51. Flock replied on November 6 that exploiting the flaws would require physical access and detailed hardware knowledge, and that customers did not need to act.
In December 2025, 404 Media reported that livestreams and administrator panels for at least 60 Flock Condor video cameras were open to the internet without a password. Technologist Benn Jordan found the exposure first.
Michael's January 9, 2026 write-up describes two exposed mapping credentials. One had access to 50 private map items, and he lists it as fixed in June 2025. Michael says he did not open those items, so their contents remain unverified. The other credential reached camera locations and was the flaw he reported in November 2025.
In September 2026, WIRED and 404 Media reported that a group called stegan0gram took down a Flock camera and copied its storage. According to WIRED, a key stored on the device gave access to its recorded media. WIRED's analysis of the logs found about 1.6 million images of roughly 50,200 vehicles over about 21 days. Flock told WIRED that removing or tampering with its cameras is illegal and that it had received no report through its disclosure program.
Flock's May 2025 advisory · Gaines's white paper post · WIRED on the removed camera · Our brief on the camera teardown
What the 2026 Bishop Fox test found
Flock hired security firm Bishop Fox for its 2026 penetration test, which ran from January 12 to March 27. Flock's summary, published September 22, lists 36 issues, including two rated critical and seven rated high. Flock says Bishop Fox verified fixes for every critical and high finding, and that customers can download the full report.
Flock chose to leave one medium finding open. First-generation Falcon cameras run Android 8.1, and Flock says it patches that software itself instead of replacing the hardware. The summary also says older plate readers now use Secure Boot, which addresses a reported attack on stolen devices.
The Bishop Fox summary says no customer data or systems were accessed by anyone outside Flock as a result of the testing. Three days later, Flock's lawyers wrote that the exposed key had been used in November 2025, about two months before testing began, to take confidential data. Footnote 4a has asked why the summary left that out.
Timeline of reported Flock security events
Dates come from the source named in each row. Where accounts differ, both are shown.
Scroll horizontally to compare all columns.
| Date | Event | Source |
|---|---|---|
| May 5, 2025 | Flock posts an advisory on plate reader and gunshot detector flaws it says require physical access | Flock |
| June 19, 2025 | Jon Gaines publishes his first Flock device write-ups | GainSec |
| Nov. 5–6, 2025 | Gaines releases a white paper on 45 issues, and Flock responds | GainSec and Flock |
| Nov. 13, 2025 | Joshua Michael reports an exposed map access key to Flock | The Intercept |
| Dec. 2025 | Michael downloads device location data. Flock says it closed the issue that month | The Intercept and Flock notice |
| Dec. 22, 2025 | 404 Media reports at least 60 Condor camera feeds open to the internet | 404 Media |
| Jan. 6, 2026 | Flock posts that it has never been hacked | Flock |
| Jan. 9, 2026 | Michael publishes his research | Michael |
| Jan. 12 – Mar. 27, 2026 | Bishop Fox penetration test | Flock |
| Sept. 16, 2026 | WIRED and 404 Media report on data copied from a removed camera | WIRED |
| Sept. 22, 2026 | Flock publishes its Bishop Fox summary | Flock |
| Sept. 22 or 23, 2026 | Michael's device map goes online. Flock says the 22nd, The Intercept the 23rd | Flock notice and The Intercept |
| Sept. 25, 2026 | Flock's lawyers send Michael a cease-and-desist letter | Footnote 4a |
| Late Sept. 2026 | Flock emails customers its incident notice. The exact send date is not public | WFSB |
| Sept. 29, 2026 | WFSB reports the notice. The police chief in Ledyard, Connecticut says he is moving to end the town's Flock contract | WFSB |
The Intercept on the device map · Michael's January 2026 write-up
What to ask your police department after a vendor breach
If a police department or sheriff near you uses Flock, it should have the September 2026 notice. Ask for documents, and name the record you want.
The device list matters most. The notice covers device names and locations, and your local agency can tell you which of its devices were in the data. Ask for the contract's security terms too. They show what Flock promised to report and when.
Keep each answer tied to its date and scope. A reply covering plate readers says nothing about video cameras or gunshot detectors. And a missing record leaves a gap in the file. It doesn't prove that nothing happened.
Copies of any security incident notice, update or correspondence the department received from Flock Safety about unauthorized access to device location data, from September 1, 2026 to the date of this request.
Any record listing which of the department's Flock devices were in the data Flock described in that notice, including device names as they appear in Flock's system.
The security, breach notification and incident response terms in the department's current Flock agreement and order forms.
Any copy of Flock's 2026 Bishop Fox penetration test report or retest report that the department downloaded or received.
How to request Flock audit logs · Find your agency's transparency portal · Records request tools · What happens when a city cancels Flock
Questions people ask
Has Flock Safety had a data breach?
Were license plate images stolen in the September 2026 incident?
Can Flock cameras be hacked?
What was the flocksurveillance.org map?
Is FlockDetour connected to Flock Safety or the leaked data?
Related guides
Who owns Flock Safety? · How to request your city's Flock audit logs · Why are Flock cameras controversial? · What are Flock cameras, and how do they work? · What happens when a city cancels Flock cameras? · All guides · Live camera map · Get the app
Sources
- Flock security incident notice, posted by Joshua Michael: full notice text; undated; wording matches what WFSB quoted; checked October 4, 2026
- WFSB I-Team: Flock warns CT police about a security breach: September 29, 2026, updated October 2; Flock statements and Ledyard chief; checked October 4, 2026
- The Intercept: Flock wants the most detailed map of its cameras taken offline: September 24, 2026; disclosure dates, map contents and trademark complaint; checked October 4, 2026
- Footnote 4a: Flock now says it got hacked: October 3, 2026; advocacy site; used for the demand letter and its timeline questions; checked October 4, 2026
- Flock cease-and-desist letter, September 25, 2026: letter from Nelson Mullins on behalf of Flock Group Inc., as published by Footnote 4a; checked October 4, 2026
- Flock: Has Flock Been Hacked?: vendor post dated January 6, 2026; still live on October 4, 2026
- Flock: Bishop Fox penetration test summary: vendor summary dated September 22, 2026; finding counts and test window; checked October 4, 2026
- Flock security advisories: last updated September 15, 2026; no advisories listed; checked October 4, 2026
- Flock: Gunshot Detection and License Plate Reader Security Alert: vendor advisory dated May 5, 2025; checked October 4, 2026
- Flock: Response to compiled security research: vendor response dated November 6, 2025; checked October 4, 2026
- GainSec: Formalizing my Flock Safety security research: Jon Gaines, November 5, 2025, with links to earlier write-ups; checked October 4, 2026
- 404 Media: Flock exposed its AI-powered cameras to the internet: December 22, 2025; opening section read, rest paywalled; checked October 4, 2026
- Joshua Michael: 53 times Flock Safety hardcoded the password: researcher write-up, January 9, 2026; used for his own claims only; checked October 4, 2026
- WIRED: Hackers got inside a Flock camera: September 16, 2026, joint investigation with 404 Media; Flock's statement; checked October 4, 2026
FlockDetour is independent and is not affiliated with or endorsed by Flock Safety or any surveillance vendor.