Flock Safety, a prominent provider of automatic license plate recognition (ALPR) cameras, released the findings of its 2026 annual penetration test. The audit, conducted by Bishop Fox, an independent security firm, uncovered vulnerabilities across Flock's hardware, software, and cloud infrastructure, as reported by Yahoo Finance.
The results highlight the ongoing security challenges in surveillance technology, which directly impacts drivers whose movements are tracked by these cameras. Understanding these vulnerabilities is key to knowing what data might be at risk and how it's being protected.
What did the security audit find?
Bishop Fox's "clear box" testing, which involved full access to Flock's source code and system architecture, identified a total of 36 security findings. The audit ran from January 12 to March 27, 2026. The findings were categorized by severity:
- Two Critical findings: All remediated and independently verified.
- Seven High findings: All remediated and independently verified.
- 16 Medium findings: 13 remediated and verified, two partially remediated, and one under documented risk management.
- Three Low findings: All remediated and independently verified.
- Nine Informational findings: Addressed through routine hardening processes.
Flock Safety stated that none of these identified issues resulted in unauthorized access to customer data or systems during the testing period. Drivers can review our map of ALPRs to see where these cameras are deployed in their communities.
What does this mean for drivers and data security?
One significant remediation involved adding Secure Boot, using Android Verified Boot, to older ALPR cameras. This feature aims to prevent unauthorized software from running on a device, which could protect the limited number of images stored locally if a camera is stolen or compromised. Bishop Fox independently verified this fix.
However, one Medium-severity finding remains open. This vulnerability relates to a legacy operating system on Flock's first-generation Falcon cameras. Addressing this issue would require a substantial hardware and operating system upgrade. While Flock's engineers maintain the Android-based platform and can deploy security updates, the company is still evaluating the long-term migration path for these older devices.
For drivers, this means that while many vulnerabilities have been addressed, older models of Flock cameras may still pose a potential, albeit managed, risk. It emphasizes the need for continuous vigilance and updates in surveillance technology. For more background on how ALPRs work and their implications, drivers can visit our learn page.
Flock Safety conducts annual penetration tests and other ongoing security measures. Chris Castaldo, Flock's Chief Information Security Officer (CISO), noted that "Security is never done, it is a continuous practice." The company also maintains a Vulnerability Disclosure Program for external researchers.
Drivers should remain aware that no system is entirely impervious to vulnerabilities, and the security of ALPR cameras is an evolving challenge for all manufacturers. Flock Safety has published further details on its blog.
Correction, October 5, 2026: An earlier version of this article said six findings were rated high, following the coverage it summarized. Flock's own summary of the Bishop Fox test lists seven. For the wider record, see has Flock Safety been hacked?