Hackers Confirm Flock License Plate Readers Log People, Not Just Cars

The roadside cameras know when you enter the frame.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

Flock Safety describes its roadside cameras as license plate readers built to capture vehicle information. Software recovered from one of those cameras shows the system can also detect and identify people in the frame.

Hackers from the collective stegan0gram removed a Flock camera, dismantled it, and extracted its software and stored data, according to a joint investigation by 404 Media and WIRED.[1][2]

The recovered files contained no evidence that the device was running facial recognition. However, the camera’s object-detection software could recognize a human being, log the detection, and connect it to footage captured at a particular place and time.

In this article
Hackers found people hidden among the traffic data
Flock says it does not use facial recognition
The camera’s encryption did not keep the files hidden
Can you stop a Flock camera from recording you?

Hackers found people hidden among the traffic data

The camera had recorded approximately 21 days of activity across several periods. During that time, it photographed roughly 50,200 vehicles and generated about 1.6 million images.

Its software identified people in 11 clips, all involving motorcyclists. The small number makes sense for a camera installed beside a highway with little pedestrian traffic.

The location may have limited how many people appeared. The underlying detection technology was already installed and operating.

The camera used multiple exposures to capture license plates and wider views of passing traffic. It then scanned the images, selected useful frames, and transmitted them to Flock through a cellular connection.

More detailed analysis appeared to occur on Flock’s servers, including identifying a vehicle’s make, model, and color. The device could generate as many as 100 images as a vehicle passed, although it would transmit only selected images and associated data.

AAC has previously detailed how Flock’s cameras collect license plates, vehicle features, timestamps, and location data. The recovered files provide a rare look at how much processing happens before that information reaches Flock’s servers.

Flock says it does not use facial recognition

Flock says its license plate readers record vehicle sightings and help investigators search for relevant evidence. Its website also states that the cameras do not use facial recognition or identify a vehicle's occupants.

The files from this camera do not contradict that specific claim. Person detection recognizes the presence of a human figure, while facial recognition analyzes someone’s face and attempts to establish their identity.

However, detecting a person creates another category of surveillance data. The software can isolate someone from the background, preserve the image, and link the sighting to a camera and timestamp.

Those records could reveal more when combined with footage from other cameras or separate databases. Flock is already developing tools that can identify vehicles from their behavior and movements, allowing police to begin searches without entering a name or license plate.

The presence of person detection also raises questions about future expansion; a capability installed inside existing hardware could potentially be activated or expanded through a software update without replacing the cameras lining public roads.

Flock says its cameras “do not continuously track people or vehicles” and delete images after seven days by default.

Customers can choose another retention period or preserve records for an authorized investigation.

The camera’s encryption did not keep the files hidden

The hackers reportedly recovered an encryption key from the device and used it to access footage, logs, and other internal files. Storing encrypted information alongside the means to unlock it can leave the data exposed when someone gains physical access to the hardware.

A Flock spokesperson told WIRED, “The unauthorized removal and tampering of a Flock camera is illegal.” The company also said it had received no vulnerability report from the hackers and encouraged them to submit their findings through its public reporting process.

The findings concern one physically compromised camera and do not demonstrate remote access to Flock’s entire network. However, they still show what a roadside unit can collect and hold on to before its data reaches the company’s cloud platform.

Security is only one concern surrounding access to Flock data. In one recent case, an officer allegedly searched for vehicles connected to his former partner more than 2,000 times before Flock’s AI auditing system flagged the activity.

Can you stop a Flock camera from recording you?

No browser setting or privacy app can block a roadside camera from photographing you in public. Avoiding the cameras may also be impossible when they are installed along the roads you use every day.

Covering or altering a license plate may violate state law and invite a traffic stop. Residents can instead investigate how Flock technology is used in their communities and push local officials for stronger limits.

Ask your police department or municipal government:

  • Where Flock cameras are installed
  • Whether person detections are retained or searchable
  • How long images and metadata remain stored
  • Which outside departments or federal agencies can access the records
  • Whether new detection features require public approval

Flock transparency portals and public-records requests can reveal how these cameras are used, who can access their data, and how long it survives.

Author Details
Thomas Kent is a multi-disciplined reporter with over a decade of experience covering online platforms, digital trends, and consumer-facing tech. Tom focuses on digital privacy, data tracking, and user behavior, with a particular interest in how cookies, online surveillance, and platform design shape the modern internet experience. His reporting takes a research-driven, news-focused approach, translating complex technical topics into clear, accessible insights.

Citations

[1] Hackers Stole Flock’s Camera Software, Revealing How the Company Tracks Cars and People

[2] Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works