Skip to content

Build2 publishers2 min readPublished

Flock files a trademark claim to remove a map built from its own exposed ArcGIS token

Flock Safety, through the security firm Doppel, filed a trademark complaint to take down Joshua Michael's map of 335,701 devices. The complaint leaves open how, by Michael's account, a Flock website handed an ArcGIS access token to visitors who never logged in.

The Engineer · Build desk

Photograph accompanying Flock files a trademark claim to remove a map built from its own exposed ArcGIS token
Photo: theintercept.com

What happened

  • The 335,701 figure counts devices: more than 170,000 cameras and more than 130,000 related units, including acoustic detectors and networking gear for third-party cameras, per The Intercept.
  • After Michael reported the flaw on November 13, 2025, Flock needed two more attempts to answer, said it was triaging the findings, and never followed up, he says.
  • Flock apparently closed the hole in January 2026, after Michael published his technical findings, according to his account.
  • Michael published the map on September 23, 2026, the day a Senate Judiciary subcommittee held a hearing on Flock that its CEO was invited to but did not attend.
  • Flock's security statement says its cloud platform has never experienced a data breach and that no customer data has been compromised.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • constraint Winning the trademark complaint would remove one website, while the device database Michael pulled before the January fix would stay outside Flock's control.
  • decision Police agencies relying on Flock's no-breach statement have to ask whether it covers the device-location layer, because that inventory is a separate dataset from customer license-plate records.
  • contradiction Tom's Hardware labels all 335,701 entries cameras, but cameras are just over half the list, so the figure does not rebut Flock's claim of more than 120,000 cameras.
  • precedent Flock took the same trademark route against DeFlock's crowdsourced map in January 2025, so anyone publishing a map of its hardware can expect a mark complaint whatever the data source.

By Michael's account, the weak point was a Flock web page. He says the site gave out an access token without a login [6], and he presented that token to ArcGIS, the third-party mapping service Flock uses [7]. A credential served to an anonymous browser authenticates whoever loads the page. If it worked that way, Flock's device data in ArcGIS was as private as a public web page.

In his November 13, 2025 email to Flock, Michael wrote that "all testing was strictly non-intrusive, limited to open unauthenticated endpoints, and did not involve bypassing authentication, modifying data, or invoking any billable ArcGIS or Google operations" [8]. The reporting does not say what the token was scoped to, how long it stayed valid, or whether Flock's logs recorded his queries.

The inventory holds more than coordinates. It identifies equipment by model and, in some cases, by labels that point to sensitive locations [17]. The Intercept checked six randomly selected Arizona locations and found Flock cameras at each [16]. Six hits confirm the data was real where it was sampled. They say less about the rest. The map calls its data a December 2025 snapshot [14], about nine months old when it went public [2].

According to Tom's Hardware, Michael's analysis covers 22 sensitive sites, the Pentagon and CIA Headquarters among them [24]. It gives people living within 20 miles of those sites a 57.22% to 93.94% chance of passing a Flock camera [24]. That range is his model's output. For it to hold today, the December 2025 placements have to still stand where the map puts them. The route model behind the percentages also has to match how those residents actually travel.

Michael told The Intercept that Flock issued its no-breach statement "after I pulled their database of devices" [20]. "That leaves two possibilities," he said. "Either they knew and chose not to disclose it for fear of bad press, or they didn't know I exfiltrated the data at all. The first is a transparency failure. The second is a detection failure with national security implications." [21]

Doppel, which filed the complaint, is a cybersecurity company focused on social engineering defense [4]. Its complaint says the site uses the "FLOCK SAFETY" mark without authorization and may confuse customers [3]. It arrived one day after the map went live [1]. For a firm whose business is sites that impersonate its clients, it picked an odd target: the map greets first-time visitors with a pop-up saying it is not affiliated with or endorsed by Flock [5].

What to watch

  • Whether Flock says what the exposed ArcGIS token was scoped to and whether its logs recorded Michael's queries before the January 2026 fix.
  • Whether the Flock Surveillance Map comes down under Doppel's complaint, or Michael contests it the way the EFF answered Flock's letter to DeFlock.
  • Whether the Senate Judiciary subcommittee that held the September 23 hearing presses Flock on the unauthenticated access path.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories