Skip to content
Tech News
← Back to articles

Hackers stole a Flock camera and found 27,321 video clips, 1.6 million images, and an encryption key

read original get Reolink Argus 4 Pro Security Camera → more articles
Why This Matters

This physical hacking incident exposes serious security flaws in Flock Safety's automated license plate reader systems, which are widely deployed by law enforcement across US cities. The discovery that an encryption key was stored on the device itself, and that hundreds of thousands of images and vehicle records could be extracted by anyone with physical access, raises major concerns about surveillance infrastructure security and privacy risks for the public.

Key Takeaways
Worth a Look

Reolink Argus 4 Pro Security Camera — If this story has you thinking about surveillance tech and data security, it's worth looking at consumer cameras that prioritize encrypted local storage and transparent privacy controls. The Reolink Argus 4 Pro offers solar-powered wireless operation with strong encryption options you control yourself, unlike opaque municipal systems. It's a great way to get smart monitoring without wondering who else has access to your footage.

See Reolink Argus 4 Pro Security Camera on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

WTF?! It seems that Flock just can't stop making headlines these days – none of them good, of course. The latest report illustrating why so many cities are dropping the license plate readers involves hackers who physically pulled a camera down from above a roadway, copied its storage, and found an encryption key sitting on the device itself. Convenient.

The group, calling itself stegan0gram, said it removed and disarmed the hardware before reverse engineering the camera and its associated solar equipment.

This required getting hold of an actual camera; the investigation didn't remotely breach Flock's cloud network. The recovered material became the subject of a joint investigation by 404 Media and Wired.

Inside the Android-based device, the hackers found unencrypted storage partitions. One contained a key that unlocked another area holding recorded media.

Much of the most sensitive storage remained encrypted and inaccessible, but the accessible footage included 27,321 MP4 files in a 1024 x 768 resolution, each lasting around one to two seconds. The clips contained no audio and were separate from the bursts of higher-resolution still images.

Separately, recovered logs spanning about 21 days across several periods showed the camera had generated roughly 1.6 million images of 50,200 vehicles.

A typical passing vehicle generated about 28 images, with some triggering more than 100. The camera selected and cropped useful frames before uploading them over a cellular connection. Reading plates and identifying vehicle characteristics appeared to happen on Flock's servers.

Concerningly, the software also detected people. Tests on the recovered clips identified people in 11 videos, all riding motorcycles.

Meanwhile, the plate detector occasionally mistook bumper stickers and other graphics for plates, including an American flag patch on a motorcyclist's saddlebag. The investigators found no evidence of active facial recognition.

The logs also revealed more than 27,000 errors from attempts to save full-resolution images when storage was full, alongside tens of thousands of related errors, crashes, and reboots.

... continue reading