Hackers Reverse-Engineer Flock Cameras, Revealing How AI Surveillance Tracks Vehicles
Flock Safety cameras have become a common tool for law enforcement agencies trying to identify vehicles connected to crimes.
But a new investigation is raising questions about just how much information these cameras collect — and what could happen if the hardware itself falls into the wrong hands.
A hacker group known as stegan0gram reportedly removed a Flock camera from the field, accessed its data and reverse-engineered the device to better understand how the surveillance system works. The findings were later shared with Wired and 404 Media.
What they reportedly discovered shows that modern license-plate-reader systems may collect far more visual information than many people realize.
What Did the Hackers Discover?
According to the investigation, one Flock camera recorded approximately 50,200 vehicles during a 21-day period.
But the surprising part was the number of images produced.
Those vehicle encounters reportedly generated around 1.6 million individual images.
That works out to many images for each vehicle passing the camera.
The investigation found that a typical vehicle encounter could produce roughly 28 images, while some encounters generated more than 100 images.
Instead of simply snapping one photograph of a license plate, the system can capture a sequence of images that provides additional information about the vehicle.
What Information Can Flock Cameras Collect?
Flock operates a network that includes license-plate readers, cameras and other sensors connected to an AI-powered database.
The system can log information such as:
- License plate numbers
- Vehicle make
- Vehicle model
- Vehicle color
- Distinctive vehicle characteristics
- Bumper stickers and other visible markings
Data collected by participating jurisdictions can also be shared with other law-enforcement agencies, expanding the usefulness of the network for investigations.
The reverse-engineered camera reportedly sent images and other information over a cellular network to Flock’s infrastructure, where additional analysis appears to take place.
In one example described in the investigation, the system captured enough visual detail to detect an American flag patch on a motorcyclist’s saddlebag.
That detail helps illustrate how advanced roadside surveillance technology has become.
The Camera Is Only One Part of the System
Another important discovery involves where the actual analysis happens.
According to the reporting, the roadside camera itself appears to collect and transmit images rather than performing all vehicle identification locally.
Much of the analysis appears to occur on Flock’s servers.
That means the complete surveillance system isn’t just a camera mounted beside a road.
It is effectively a connected technology stack involving:
Camera → Cellular network → Cloud infrastructure → AI analysis → Searchable database
That architecture can make surveillance systems extremely powerful.
It also creates multiple areas that organizations must protect.
Why This Is a Cybersecurity Story
At first glance, this might look primarily like a privacy debate.
But there is also an important cybersecurity lesson.
Any internet-connected device capable of collecting valuable information can become a target.
Smart cameras, traffic sensors, industrial devices, security systems and other Internet of Things equipment can potentially contain:
- Software
- Credentials
- Configuration files
- Internal applications
- Network information
- Stored data
- Hardware secrets
Once attackers gain physical possession of a device, they may attempt to extract that information or reverse-engineer how the system communicates with its backend infrastructure.
The hackers involved in this incident said they removed the hardware specifically so they could study and reverse-engineer it.
That makes physical security part of cybersecurity.
Flock Responds
Flock criticized the removal of its equipment and said unauthorized removal and tampering with a camera is illegal.
The company also said it maintains a public vulnerability-disclosure program that security researchers can use to report security issues.
According to Flock, the researchers involved in this incident did not submit their findings through that process, and the company said it did not have enough information to fully evaluate the claims being made.
That distinction matters.
Legitimate security research normally involves authorized testing or responsible vulnerability disclosure rather than physically taking deployed equipment.
The Bigger Issue: AI Surveillance Is Becoming More Powerful
The broader lesson goes beyond Flock.
Artificial intelligence is rapidly transforming traditional security cameras into sophisticated data-collection systems.
A camera that once simply recorded video can now potentially identify patterns, classify objects, recognize vehicle characteristics and make enormous amounts of information searchable.
Combine that with cloud computing, cellular connectivity and databases shared across organizations, and one roadside camera becomes part of a much larger surveillance network.
That creates powerful tools for law enforcement.
But it also creates important questions about:
Cybersecurity: How well are the devices and cloud infrastructure protected?
Privacy: How much information should be collected about ordinary vehicles?
Data retention: How long should the information be stored?
Access control: Who should be allowed to search the database?
Data sharing: How widely should collected information be shared?
Physical security: What happens if someone steals or dismantles the hardware?
These are questions governments, technology companies and communities will increasingly have to address as AI-powered surveillance expands.
Lesson for Businesses Using Smart Cameras
There is also a lesson here for companies deploying smart cameras, sensors and other connected devices.
Do not treat physical hardware as harmless simply because the most important software lives in the cloud.
Attackers may still attempt to dismantle a device and study its:
- Firmware
- Storage
- Authentication mechanisms
- Communication protocols
- APIs
- Network configuration
Organizations deploying Internet of Things devices should assume that a determined attacker could eventually obtain physical access to the hardware.
Systems should therefore be designed so that stealing one device does not expose the entire network.
Aqyreon Takeaway
The biggest takeaway from the Flock camera investigation isn’t simply that hackers removed a surveillance camera.
It’s what they reportedly learned after examining it.
A modern roadside camera can generate dozens of images from a single vehicle encounter and feed those images into a much larger AI-powered infrastructure.
That demonstrates how quickly surveillance technology is evolving.
But it also reinforces a basic cybersecurity principle:
Every connected device collecting valuable data eventually becomes part of your attack surface.
As AI moves into cameras, vehicles, factories, homes and public infrastructure, companies will need to secure not just their cloud platforms and applications — but the physical devices gathering the data in the first place.



