Inside the Dumped Flock Camera: 1.6M Images, Person Detection

An analysis of files from the stolen Flock camera shows it photographed 50,200 vehicles in 21 days and explicitly detects people, not just plates.

Read as article

Inside the Dumped Flock Camera: 1.6M Images, Person Detection

By @sharedot · · 8 pages

An analysis of files from the stolen Flock camera shows it photographed 50,200 vehicles in 21 days and explicitly detects people, not just plates.

What the Journalists Found Inside the Stolen Camera

The story moves beyond the theft itself: WIRED and 404 Media have now analyzed the files, and the findings show a device that photographs passing vehicles in rapid bursts, sending everything to Flock over a cellular network. According to the recovered logs covering roughly 21 days, the camera photographed about 50,200 vehicles and generated around 1.6 million images. A typical passing vehicle produced about 28 images, and some encounters generated more than 100, with the camera using different exposures to capture both the license plate and the wider scene.

The Encryption Key Was On the Device

The breach cracked open a system Flock has long described as protected by on-device encryption. The hackers from the collective calling itself stegan0gram found two unencrypted partitions on the camera's internal storage — one holding vendor files, the other media — and the media partition contained an encryption key that unlocked most of the recorded footage. That detail directly undercuts Flock's earlier public position: after security researcher Jon 'GainSec' Gaines disclosed flaws in early 2025, the company argued that even someone with physical access to a camera 'would still not be able to gain access to footage.'

Person Detection Is Explicitly in the Software

Perhaps the most consequential finding is that the software running on the camera explicitly detects people as well as vehicles, license plates, and bicycles — a capability largely absent from public discussion of the devices. When it spots a person, the camera records where they appear in the image and its confidence in the detection. WIRED extracted the machine-learning models from the device and ran them against 27,321 short video clips stored on the camera, detecting people in 11 of them, all riding motorcycles. WIRED and 404 Media report they found no evidence of active facial-recognition capability, and Flock maintains its cameras do not perform face recognition.

Where the Analysis Actually Happens

The teardown revealed a device closer to a midrange smartphone than a dumb sensor. It runs around 20 Flock-built Android applications handling motion detection, image classification, uploading, and remote updates. Notably, the camera itself does not read license plates or identify a vehicle's make, model, and color — that processing happens later on Flock's servers, after the images are transmitted. The recovered software also showed a plate detector with a loose trigger: it mistook bumper stickers and dealership frames for plates, and in one video cropped an American flag patch on a motorcyclist's saddlebag as if it were a license plate.

The National Network Is the Real Stakes

The individual camera is only the front end of a searchable national database. According to WIRED, records from a single city's cameras can be accessed by thousands of outside agencies — in Alpharetta, Georgia, more than 2,000 agencies including police departments, colleges, airports, and the federal GSA's Office of Inspector General could reach the city's Flock data. 404 Media has previously reported the network was used by local police to run lookups on behalf of ICE, and in one case to search for a woman who self-administered an abortion, fueling the backlash that prompted this breach in the first place.

Flock Responds and the Backlash Grows

A Flock spokesperson called the removal and tampering 'illegal' and said the company received no report through its public Vulnerability Disclosure Process, adding that without more technical detail it cannot assess the claims — but it encouraged the hackers to submit findings for review. The backlash shows no sign of slowing: multiple people have been arrested for tampering with cameras, some towns have dropped Flock entirely, one police department deployed a fake 3D-printed camera case as bait, and Mashable reports cities across the country are canceling contracts. Former officer-turned-critic Noel Pichardo, quoted by WIRED, worries that such vigilantism 'will only crystallize' police belief that the tool is necessary.

Sources

  1. wired.com › Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works
  2. mashable.com › Hackers dismantle Flock camera to see what makes it tick
  3. newsone.com › Report: Hackers Breach And Expose Flock Camera Software, As Resistance Continues

More on Gadgets