The hacker collective stegan0gram said it removed a Flock Safety automated license-plate-reader camera from a roadway, disarmed it, and reverse engineered its hardware, solar equipment, and Android-based operating system. The group copied nearly all data held on the device—including thousands of videos, still images, and operational logs—and shared material with WIRED and 404 Media.
The extracted data reportedly showed one camera captured roughly 1.6 million images of 50,000 vehicles in 21 days, illustrating the scale of Flock's vehicle-tracking collection. Researchers said unencrypted vendor and media partitions were accessible; an encryption key in the media partition allegedly unlocked another partition containing much of the captured imagery. Flock cameras upload vehicle images and associated metadata to searchable Flock servers used by authorized agencies, including participants in its national network.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The copied dataset showed that one Flock camera captured approximately 1.6 million images of roughly 50,000 vehicles over 21 days. The materials included thousands of videos and logs that revealed operational details of how the system tracks vehicles and people.
Stegan0gram reported accessing the camera's Android OS and finding unencrypted storage partitions, including a media partition containing an encryption key. The group said the key unlocked another partition holding much of the camera's captured videos and still images.
The stegan0gram hacker collective said it removed a Flock Safety camera from above a roadway, disarmed it, copied nearly all data on it, and reverse engineered the camera and associated solar equipment. The group shared extracted videos and operational logs with WIRED and 404 Media.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.