Hackers who physically removed a Flock Safety license plate camera were able to recover an encryption key stored on the device and use it to unlock a large collection of locally stored media. A joint investigation by 404 Media and WIRED found 27,321 short video clips on the camera, while recovered logs showed it generated roughly 1.6 million images of about 50,200 vehicles across approximately 21 days of recorded activity. The findings provide one of the clearest public looks yet at how Flock’s roadside surveillance hardware operates internally.
The camera was obtained by a hacker collective calling itself stegan0gram, which said it removed the hardware from above a roadway and reverse engineered both the camera and associated equipment. The group shared material from the device with 404 Media and Distributed Denial of Secrets, with WIRED subsequently receiving a copy for analysis. The incident was not a remote compromise of Flock’s cloud infrastructure; it depended on physical access to an individual camera.
Once inside the Android-based system, the hackers found several storage partitions, including areas labeled “vendor” and “media.” According to the investigation, the media partition contained an encryption key that could unlock another partition holding videos and still images captured by the camera. More sensitive areas of the device remained encrypted and inaccessible, so the recovered material did not amount to a complete extraction of everything stored on the hardware.

The accessible media included 27,321 MP4 clips recorded at 1024 x 768 resolution, generally lasting one or two seconds and containing no audio. Separate logs showed that a typical passing vehicle caused the camera to generate around 28 images, while some vehicles triggered more than 100 frames. Across the periods represented in the recovered logs, the camera recorded roughly 50,200 vehicles and produced about 1.6 million images.
Those findings are significant because Flock has previously said physical access to its hardware would not be enough to obtain footage. In an earlier security advisory, the company acknowledged vulnerabilities requiring physical access but said an attacker would still be unable to access footage because data remained on the device only briefly after being sent to the cloud. Flock’s current evidence policy similarly states that data stored on a camera is temporary and automatically removed after upload.
The recovered camera appears to have retained considerably more media than those descriptions might suggest. The investigation does not establish that every Flock camera stores the same amount of historical material, and the volume available on the examined unit may depend on factors such as upload behavior, storage management or device configuration. It does, however, demonstrate that meaningful quantities of locally stored footage could be recovered from at least one physically compromised camera.
Analysis of the software also showed that the hardware performs more than simple license-plate capture at the edge. The on-device computer-vision system could identify vehicles, people, bicycles and plate-like objects before sending selected images and associated information to Flock’s servers. The journalists found no evidence that active facial-recognition functionality was being used, despite generic facial-detection components being present as part of the underlying Android software.
The camera also occasionally misclassified unrelated objects as license plates. Investigators found examples involving bumper stickers, dealership frames and an American flag patch on a motorcycle saddlebag being isolated by the plate detector. More advanced functions such as reading plates and determining vehicle characteristics including make, model and color appear to be handled primarily on Flock’s servers rather than directly by the roadside unit.
Flock responded to the investigation by emphasizing that unauthorized removal and tampering with its cameras is illegal. When questioned about the recovered encryption key, the company pointed to its vulnerability disclosure program and said security researchers can report potential flaws directly. Flock has previously said its cloud platform has not been hacked and that it has not suffered a customer-data breach through compromise of its central infrastructure.
That distinction remains important in this case. The hackers did not penetrate Flock’s cloud systems or remotely access customer accounts; instead, they physically acquired a field device and extracted data directly from its storage. Even so, the ability to recover locally stored footage after physical compromise raises questions about device-level encryption, key management and the amount of data retained on roadside hardware before deletion.
The discovery adds another security and privacy issue to ongoing scrutiny of automated license plate reader networks. Flock cameras are widely used by law enforcement agencies and private organizations, with captured records capable of being searched across interconnected systems depending on local sharing settings. The recovered device now provides unusually detailed evidence of what happens before those records reach the cloud, including how aggressively a single camera can capture and temporarily retain images of passing traffic.

