Security1 publisher3 min readPublished
Hackers unbolted a Flock camera and found its media key on an unencrypted partition
A collective calling itself stegan0gram copied the Android storage of a roadside Flock camera and found the key to its encrypted media sitting in the clear on the same device Flock has described as protected by on-device encryption.
The Watch · Security desk

What happened
- Hackers ripped a Flock camera down from above a roadway, made a near-complete copy of the data stored inside it, and shared the files with 404 Media and WIRED.
- The material went to 404 Media and the transparency nonprofit Distributed Denial of Secrets, which passed it to WIRED, and the two outlets analyzed the files jointly.
- Copying the storage yielded an encryption key that had been kept on the device, and that key unlocked videos of thousands of vehicle detections.
- Several weeks of logs recovered from the single camera show it generated more than a million images, and it can produce dozens of images of one passing vehicle.
- The software running on the device explicitly detects people as well as vehicles, license plates and bicycles.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Physical reach of the enclosure is the only prerequisite for a repeat, so every pole-mounted unit of this design is in range of the same extraction.
- decision Anyone specifying edge hardware now has a concrete reason to ask where the key is held, because this deployment kept it on the device it was protecting.
- capability Publishing the method turns the next teardown from a research project into a procedure someone can follow with a ladder and a wrench.
- precedent Opponents of these cameras now have a second option beyond breaking them, and it produces evidence about what the software classifies.
Part of the encryption held. Much of the reader's most sensitive storage stayed encrypted and inaccessible to the hackers [7]. The footage was another matter. The hackers said they reached the camera's Android system, found unencrypted partitions including one called "vendor" and another called "media", and took a key out of "media" that opened the partition holding the videos and stills [6]. Flock has described the system as protected by on-device encryption [3]. The published description says the hackers found two partitions and then refers to a few of them as unencrypted, so the count in the account is not consistent [6].
Divide the million by a four-week window and one unit is running above 35,000 images a day [19]. The computer-vision output also isolated bumper stickers and other graphics, including, in one case, an American flag patch on a motorcyclist's saddlebag [10].
Until now the field response to these cameras has been destruction: people have been arrested around the country for allegedly tampering with them, some towns have said they will stop using Flock, and one police department 3D-printed a fake camera case to bait vandals [11]. "Why just destroy them when we can reverse engineer them and find the secrets of those spying on us?" one of the hackers said [12]. "We liberated hardware in the field, disarmed them, and proceeded with reverse engineering of the cameras and associated solar equipment," the hacker said [13].
What comes off the camera matters because of where it goes next. The cameras send images and other data to Flock's servers, where records become timestamped and searchable by the agency that owns or has access to the cameras, and in many cases by departments elsewhere on Flock's national network [14]. WIRED found that records from Alpharetta, Georgia were accessible to more than 2,000 agencies, among them colleges, airports and the Office of Inspector General for the federal General Services Administration [15]. 404 Media has previously reported local officers running national-network lookups on behalf of ICE, including in areas that banned working with immigration authorities or moving plate data out of state [16], and a Texas officer searching Flock cameras nationwide for a woman who self-administered an abortion [17].
The hardware has been opened before. In early 2025 the security researcher Jon "GainSec" Gaines reverse engineered a Flock license-plate reader and documented flaws that could be used to gain root-level access [18]. This time the teardown produced data, and the hackers say they are publishing how they did it so that others can copy them [2]. The account describes one camera's storage; it does not report access to Flock's servers or the national network [21]. For anyone fielding unattended boxes on public poles, the question a purchase order has to answer is where the key sits once the box is in someone else's hands.
What to watch
- Whether Flock moves key material off the device, to a hardware keystore or its servers, and whether fielded units can be changed in place.
- Whether copycat extractions follow the published method, and whether agencies begin pulling cameras down themselves.
- Whether anyone opens the partitions that stayed encrypted in this teardown.