Flock Camera Investigation Finds People Detection and a Local Key

Brendan Smith
Brendan Smith - Cybersecurity Analyst
6 Min Read
A person appears inside a camera lens above a blank license plate.
Road-camera privacy extends beyond the number plate.

A Flock license-plate camera physically removed from a roadside still held footage that could be unlocked with a key found on the device, according to a September 16 investigation by WIRED and 404 Media. The journalists also tested its computer-vision models and found that they could detect people. They did not find evidence of active facial recognition. The distinction matters: a system can notice a person in a scene without knowing who that person is. [1]

The key was beside the material it protected

The collective that removed the camera supplied copied files to journalists. According to the investigation, an unencrypted storage area contained a key that opened another area holding media. Much of the device’s sensitive storage remained inaccessible. This was a physical examination of one camera, not a demonstrated remote break-in to Flock’s nationwide cloud platform.

That result raises a more specific question than whether a product “uses encryption.” Encryption protects readable information by requiring a key; its protection also depends on how separately that key is held. An encrypted copy and an accessible unlocking key on the same seized device can leave a different exposure from an encrypted cloud database whose keys are managed elsewhere. The reported problem concerns that local boundary, not a defeat of the encryption algorithm.

Flock’s earlier security alert, published in May 2025, said that gaining physical access would not give an intruder footage because material stayed on the device only briefly after upload. The newly reported recovery challenges that assurance for the examined unit. It does not establish the condition of every installed model or software version. [2]

What the person-detection test actually showed

WIRED ran models extracted from the camera against test images and recovered video. They detected people, including motorcyclists in 11 of 27,321 short clips. Those figures describe the journalists’ test set and detections; they are not counts of identified people or proof that police performed person searches. The camera’s position over traffic also limits what that sample can show. [1]

Person detection locates a human shape; it does not establish identity.
Explanatory illustration: detecting a person in an image and establishing their identity are different tasks.

A detector answers a narrow question: where in this image is something that looks like a person? Identifying a face would require a different conclusion about who that person is. The journalists found no evidence that facial-recognition features were active in the camera software they examined.

That still leaves a meaningful privacy issue. A person can appear in a retained road image even when the system’s intended search object is a vehicle. Flock’s public explanation says its cameras focus on vehicle information and do not use facial recognition. The new findings call for more precise descriptions of what is captured, what local software can classify, and which functions customers can actually use. Those are separate questions. [3]

Local storage and cloud retention need separate answers

In its response to the investigation, Flock said it had not received a report through its vulnerability-disclosure process and lacked enough technical detail to assess the claims. The company also objected to the unauthorized removal of its equipment. That response is not a published confirmation that the reported key exposure has been fixed. [1]

Flock’s current evidence policy specifies a standard retention period of seven calendar days, subject to individual customer agreements. It also says customers own and control the data and directs noncustomer data requests to those customers. A published cloud-retention rule, however, does not itself verify when a particular camera deletes local clips, logs, or queued uploads. Nor does one recovered device establish that every customer violated a retention rule. [4]

For a neighborhood or agency reviewing its cameras, the useful follow-up is concrete: ask the operator which device and software version it uses, what remains locally after upload, how local keys are protected, what its actual retention setting is, and who can search or share the records. Request documented answers about the deployed system. The investigation shows why “encrypted” and “no facial recognition” each answer only part of the privacy question.

For cameras and other connected devices you control at home, our smart-home IoT security guide covers account protection, updates, and network separation.

References

  1. WIRED and 404 Media. “Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works.” September 16, 2026. Investigation.
  2. Flock Safety. “Gunshot Detection and License Plate Reader Security Alert.” Original publication May 5, 2025; accessed September 17, 2026. Security alert.
  3. Flock Safety. “What Do Flock Cameras Actually Capture?” Accessed September 17, 2026. Camera capabilities.
  4. Flock Safety. “Flock Evidence Policy.” Updated August 12, 2026; accessed September 17, 2026. Evidence and retention policy.
Share This Article
Cybersecurity Analyst
Follow:
Brendan Smith has spent over 15 years knee-deep in cybersecurity, chasing down malware from the gritty reverse-engineering of old-school trojans all the way to wrangling full-blown incident responses for small-to-medium businesses that couldn’t afford a full-blown breach. Over at Gridinsoft, he’s the guy piecing together those double-checked guides on nasty stuff like AsyncRAT, a remote access tool used in malware campaigns—helping readers make sense of the threat and work through cleanup without the extra headache.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?