Flock Safety Claimed 120,000 Cameras: Its Database Logs 300,000 Surveillance Nodes

Flock Safety Claimed 120,000 Cameras: Its Database Logs 300,000 Surveillance Nodes

CybersecurityPrivacySurveillance

Sources:The Intercept + 研究者公开数据

On September 24, 2026, security researcher Joshua Michael launched the Flock Surveillance Map website, an interactive portal plotting raw geographic coordinates that lays bare the mechanics of the largest automated license plate recognition (ALPR) system in the United States. During press interviews this past summer, surveillance company Flock Safety cited an official metric, claiming to operate “over 120,000” cameras nationwide. Michael pulled a full snapshot via the company’s unencrypted database interface, cataloging 170,000 primary cameras alongside over 130,000 auxiliary devices—combining for roughly 300,000 surveillance nodes. The massive hardware footprint shattered the boundaries established by the company’s public relations narrative.

300,000 Surveillance Devices Mapped Across the Nation

Device locations have long been guarded as the company’s crown jewels. In prior oversight efforts, open-source initiatives like DeFlock relied on volunteers submitting crowd-sourced coordinates—an arduous process plagued by sweeping blind spots. Michael bypassed manual crowd-sourcing entirely by pulling straight from Flock’s own back-end records. Built from a database snapshot archived in December 2025, the map leaped past the coverage limitations of community spotters.

These 300,000 devices constitute an end-to-end tracking apparatus. Beyond the 170,000 primary license-plate capture cameras, 130,000 companion systems play an equally decisive role, including 27,000 acoustic detection sensors designed to pinpoint gunshots and auditory signatures, alongside network gateway hardware that links third-party CCTV feeds directly into Flock’s web. The map color-codes devices by hardware type, distinguishing “Falcon” optical sensors from “Picard” processing units. An accompanying searchable data table exposes internal device naming conventions assigned by engineers, which frequently reveal exact street addresses, building numbers, and intersections.

The location data lays bare staggering surveillance density. Outside Chicago’s O’Hare International Airport, around the Rosemont Public Safety Department, 860 devices sit tightly clustered. The network’s reach extends well behind prison walls: at the coordinates for Silverdale Detention Center in Chattanooga, Tennessee, a sensor bears the explicit internal label “C-F-23 FOXTROT MALE HOLDING 2/SHOWERS,” pinpointing a camera directly over a male holding and shower area. Even the Federal Bureau of Investigation failed to escape the net: a testing unit dubbed “FBI Pilot Camera” maps precisely to the J. Edgar Hoover Building in Washington, D.C.

To independently verify the dataset, The Intercept reporters conducted blind field audits using the map. Navigating to six randomly selected rural coordinates in Arizona, reporters located physical Flock hardware at every single target pin without exception. Blind physical testing matched the dataset without variance: 300,000 digital entries represent actively operating hardware in the physical world.

Flock camera photographed in Tucson, Arizona on September 23, 2026 Figure: A Flock camera photographed in Tucson, Arizona, on Sept. 23, 2026. Source: The Intercept

An Unauthenticated Endpoint Hands Over the Keys

Exfiltrating this trove of sensitive data required no sophisticated penetration techniques; Flock had left the front door wide open. In November 2025, Michael discovered that Flock’s public servers were actively leaking an access token that required zero authentication. Armed with this token, anyone could submit bulk spatial queries to ArcGIS, the third-party geographic information platform utilized by Flock, which returned precise coordinates and configuration attributes for all enrolled hardware.

Confronting this massive access control lapse, Michael adhered to standard white-hat disclosure practices. He emphasized that all testing was strictly non-intrusive, restricted to open unauthenticated endpoints, and did not involve bypassing authentication, modifying data, or invoking any billable ArcGIS or Google operations.

He dispatched his initial disclosure email on November 13, 2025, detailing the exact exposure pathway. The message was met with silence. Follow-up emails sent the next day and several days later finally yielded a boilerplate response: “Thank you for the findings. We are internally triaging them and will reach back out with next steps soon.” Following that routine acknowledgment, the firm controlling 300,000 surveillance nodes went completely dark.

Official Denials Clash with the Verifiable Timeline

Seeing no remediation for weeks, Michael took defensive measures. In December 2025, he downloaded a comprehensive snapshot of the device registry to preserve evidentiary proof. In January 2026, he published an in-depth technical analysis bluntly titled: “Flock Safety hardcoded credentials for US surveillance infrastructure 53 times.” The public disclosure ignited widespread scrutiny, finally forcing Flock to patch the long-exposed endpoint.

Solar-powered Flock Safety automated license plate reader camera Figure: In Saratoga Springs, Utah, a solar-powered Flock Safety automated license plate reader camera in operation. Source: Getty Images

Flock’s subsequent public statements diverged sharply from reality. In a January blog post, Flock assured the public that the company had never been hacked, insisted no sensitive records were compromised, and asserted that Flock Safety’s cloud platform had never experienced a data breach. Michael noted that from a security engineering perspective, such absolute claims admit only two realities: either Flock observed the exfiltration in its logs and withheld disclosure to evade public fallout—a conscious transparency failure; or its monitoring failed entirely, allowing hundreds of thousands of device records to be harvested unnoticed—a monumental detection failure with national security ramifications.

These 300,000 active devices weave a nationwide tracking grid capable of mapping anyone’s vehicular movements. Michael articulated the stakes: “These cameras form a nationwide surveillance network that tracks where everyone drives, so foreign nations don’t need to send spies to harm our country. They can simply watch where our soldiers, federal agents, and politicians go.” An earlier American Civil Liberties Union (ACLU) report echoed this pattern, documenting “a pattern of Flock regularly misleading or even lying about its business practices, safety record, commitment to privacy, and efforts to protect vulnerable populations.” Facing press inquiries regarding the freshly exposed database, Flock declined to comment.

Trademark Threats Cannot Re-Lock Public Records

The coordinate database quickly reverberated on Capitol Hill. On Wednesday, September 23, the U.S. Senate Subcommittee on Crime and Counterterrorism convened a hearing on Flock, citing Michael’s map as core evidentiary material. Feeling the heat, Flock responded the following day. On Thursday, September 24, a startup named Doppel—touting itself as an “AI-native social engineering defense platform”—served Michael with a formal trademark infringement takedown on Flock’s behalf.

Doppel’s takedown notice relied on a predictable legal pretext, alleging that the map used the “FLOCK SAFETY” mark without authorization in a manner that “may cause customer confusion / harm” and demanding immediate site termination. Leveraging trademark law to suppress a major security disclosure fell flat: Michael had embedded a prominent disclaimer popup on the site from day one, explicitly stating the project is “not affiliated with or endorsed by Flock”—cutting off confusion claims before they could gain legal traction.

The true operational reach of a surveillance tech vendor is defined not by marketing copy, but by the raw inventory residing in its back-end databases. In this saga, independent researchers required no zero-days or backdoors; they merely cataloged what the company exposed to the open internet. When polished compliance narratives can be cross-checked against ground coordinates, public relations claims dissolve into hypotheses waiting to be disproven.

References:

  • The Intercept Report
  • The Washington Post Report
  • ACLU Report