The company that sells the country its eyes just found out its own address book was public: 300,000 surveillance devices, each one pinned to a location, from data the company itself was leaking.
"These cameras form a nationwide surveillance network that tracks where everyone drives, so foreign nations don't need to send spies to harm our country. They can simply watch where our soldiers, federal agents, and politicians go."
— Joshua Michael, the cybersecurity researcher who mapped Flock's cameras
On Wednesday, a map appeared online showing what Flock Safety has spent a decade of contracts assembling. Built by cybersecurity researcher Joshua Michael from data leaked out of Flock's own database, it pins more than 170,000 cameras plus another 130,000 supporting gadgets, from gunshot detectors to processing units, to coordinates across the country. That is roughly 300,000 devices in all, against the 120,000 cameras the company told reporters it operates.
The Intercept visited six random locations on the map in Arizona. All six had cameras.
The map is color-coded by model. The cameras are called Falcons, the processing units Picards, a naming scheme that reads like the company was always planning on Star Trek. The dataset lists each device by its internal name, and the names are not subtle. One entry, "FBI Pilot Camera," sits at the J. Edgar Hoover Building. Another, "C-F-23 FOXTROT MALE HOLDING 2/SHOWERS," sits inside the Silverdale Detention Center in Chattanooga, Tennessee.
The data was never stolen in the Hollywood sense. In November 2025, Michael noticed that Flock's servers were handing out an access token to anyone who asked, no login required. Query ArcGIS, the third-party mapping platform Flock uses to manage its fleet, with that token and the platform hands back the company's entire device inventory: every camera, every gadget, every location.
Michael emailed Flock on November 13, polite and defensive about method: his testing was "strictly non-intrusive, limited to open unauthenticated endpoints," and he changed nothing. Flock replied once, with "Thank you for the findings. We are internally triaging them," and then went silent.
In December, Michael downloaded the inventory. In January, he published a write-up that, in its title, counted 53 ways Flock had hardcoded the password to America's surveillance infrastructure. Flock apparently patched the token after.
Flock also published a blog post in the same January. "Flock has never been hacked, and there has not been a leak of Flock information," it declared. "Flock Safety's cloud platform has never experienced a data breach."
Michael's rebuttal has exactly two options. "Either they knew and chose not to disclose it for fear of bad press, or they didn't know I exfiltrated the data at all," he told The Intercept. "The first is a transparency failure. The second is a detection failure with national security implications."
Translation: the company that sells the country its eyes could not tell that its own eyes were on public display.
The map landed on a bad week. It was cited the same day at a Senate subcommittee hearing on Flock's "nationwide AI surveillance network," in the middle of a rare bipartisan revolt: privacy advocates on the left and libertarians on the right converging on one brand of hardware bolted to a utility pole.
Texas Governor Greg Abbott has blocked state agencies from buying Flock. Senator Josh Hawley, a Republican, has opened an investigation into Flock's privacy abuses. Senator Bernie Sanders has promised a bill, and a bipartisan pair, Republican Thomas Massie and Democrat Ro Khanna, is pushing legislation to keep federal money out of Flock purchases. Jay Stanley of the ACLU, 20-plus years in, says he has never seen a grassroots uprising against surveillance technology like this one. More than 100 jurisdictions have canceled their contracts, and Washington Post polling found 46 percent of Americans now oppose license plate readers in their communities, up 13 points in a year.
The cameras conduct roughly 2 billion scans a month. Flock, founded in 2017, installed 83 percent of America's license plate readers, and its killer feature is the national network: a scan by one town's police is a query available to every agency in the system. In Alpharetta, Georgia, WIRED found the city's Flock data accessible to more than 2,000 organizations: police departments, colleges, airports, and, inexplicably, the federal General Services Administration's Office of Inspector General.
The network is why 404 Media could show a Texas cop querying Flock cameras nationwide for a woman who self-administered an abortion, and why ICE runs lookups through it, including in jurisdictions that banned cooperation with immigration authorities. A Cato Institute analyst put it plainly on a Harvard Kennedy School podcast: "They are not license plate readers anymore; they are people readers at this point."
If the map shows how many eyes there are, a second story shows what they do. In late August, a hacker collective calling itself stegan0gram pulled a Flock camera off a pole, copied its storage, and sent the files to 404 Media and the transparency nonprofit Distributed Denial of Secrets, which shared them with WIRED. The hackers' stated reasoning: "Why just destroy them when we can reverse engineer them and find the secrets of those spying on us?"
The camera is an Android box on a utility pole with a processor like a midrange phone and roughly 20 Flock-built apps. Across 21 days of recovered logs, it photographed about 50,200 vehicles and produced about 1.6 million images. A typical passing car generated about 28 photos, some more than 100. The software explicitly detects people, not just vehicles and plates; WIRED ran the models against 27,321 video clips from the device.
The camera is also, on the evidence, a bad photographer. The license-plate detector cropped an American flag patch off a motorcycle saddlebag as if it were a plate. The logs record more than 27,000 "no space left on device" errors, and every two minutes the device logs a health-check message: "Who's a good boy?!" It appears more than 12,000 times. When the camera reboots, the sign-off is: "A reboot was requested! ¡Adiós, Amigos!"
An enthusiastic, error-prone witness that takes 28 photos of a Honda Civic and cannot tell a flag from a plate. But it never stops.
Flock's response to the camera theft was a one-line press statement: "The unauthorized removal and tampering of a Flock camera is illegal." Elsewhere, one police department 3D-printed a fake Flock camera case to bait the saboteurs, and a man was charged with three felonies for breaking it.
Now the map is out, and Flock's answer is not to remove cameras. It is to remove the count.
On Thursday, a company called Doppel, which describes itself as an "AI-native social engineering defense platform," filed a trademark complaint against Michael's site, claiming to act on Flock's behalf. The complaint says the site uses the "FLOCK SAFETY" trademark without authorization and "may cause customer confusion / harm." His site, for its part, carries a pop-up disclaimer: "not affiliated with or endorsed by Flock." A trademark claim against a map that merely shows where the cameras are is the company suing its own reflection.
The shift from product to litigation is no accident. In July, the company paid a nonprofit called Neighbors for Strong Communities to text Knoxville residents, offering to draft AI-generated emails in support of the cameras. The form had a catch: residents who opposed the cameras never got a draft. Only supporters got an email to send. Commissioners received dozens of template letters; in face-to-face conversation, one found, opposition ran 99-to-1. "Don't use my people," he told The Intercept. The nonprofit was incorporated in Washington in June, its directors are political consultants, it lists no staff, and it ran the same astroturf for the Paramount merger. Its website featured a photo of a man with six fingers.
Knox County canceled the contract anyway.
The strange thing about Flock is that the company never had to hide. The cameras sit on utility poles in public view, and every town that bought them signed a contract. What Flock has been managing all along is not the cameras. It is the count. The company told the press 120,000. When a map showed 300,000, the answer was a trademark complaint.
The map did not come from a foreign intelligence agency. It came from Flock's own database, through a token handed to anyone who asked, no login required. Michael's original point is the one the company is now trying to bury with lawyers: foreign nations do not need to send spies to see where America's cars drive. The data was already public.
The question was never how many cameras Flock has. The question is who gets to decide whether the number is allowed to be known. The map answered that, and so did the cameras. One shows where the eyes are. The other shows what they do. And now there is a record of the whole thing, in the company's own handwriting.
Comments (0)
No comments yet. Be the first to speak up.
Join the Riot
Login with Google to leave a comment.
Login to Comment