
Hackers stole a Flock camera and extracted 1.6 million images and 27,000 videos, raising new privacy concerns over surveillance technology.
A stolen roadside surveillance camera has exposed just how much information a single device can collect.
Hackers who physically removed a Flock Safety license-plate camera from a roadway were able to reverse-engineer the device and recover roughly 1.6 million images and 27,000 video clips recorded over about three weeks.
The discovery has raised fresh questions about the security and privacy of automated license-plate reader systems used by law enforcement agencies across the United States.
However, cybersecurity experts say an important distinction should be made: the incident involved physical access to one camera and does not appear to have resulted in a compromise of the company’s broader cloud network.
One Stolen Camera Revealed a Massive Cache
The hackers, identified as the group stegan0gram, physically removed a camera and copied data stored on the device.
The recovered material reportedly covered approximately 21 days of activity and included information associated with about 50,200 vehicles.
The sheer volume of images was one of the most striking findings. A single vehicle could generate numerous images as it passed the camera, creating a detailed record of traffic moving through the monitored area.
Encryption Key Was Found on the Device
The investigation also uncovered an encryption key stored on the camera itself.
That discovery allowed the hackers to access portions of the locally stored footage despite security measures designed to protect the data.
The finding has drawn particular attention because the company has previously emphasized the protection provided by encryption on its camera hardware.
The Cameras Can Detect More Than License Plates
The recovered software provided another important glimpse into how the technology operates.
The camera’s computer-vision software was found to identify not only vehicles and license plates but also people and bicycles. The system can generate multiple images of vehicles and analyze visual characteristics beyond the plate itself.
That capability has implications for privacy because a system designed primarily around vehicle identification can potentially create records that reveal patterns of human movement.
Even without facial-recognition technology, repeated vehicle sightings can help establish where a particular vehicle travels over time.
Millions of Images From a Single Location
The recovered files demonstrate how quickly surveillance data can accumulate.
Over just three weeks, one camera produced more than a million images. That means a network containing thousands of cameras could potentially generate an enormous amount of information about vehicle movements.
The incident has therefore shifted part of the privacy debate away from what individual cameras are designed to do and toward the scale of information produced when those devices operate continuously across large geographic areas.
Expert Says the Cloud Network Was Not Breached
Cybersecurity expert Jason Brown, a former U.S. Secret Service cybercrime specialist, emphasized that accessing the stolen hardware is different from breaking into the company’s cloud infrastructure.
According to Brown, the hackers’ access to the physical camera did not give them the ability to log into the company’s cloud system or access its broader database.
That distinction is significant. The incident demonstrates a vulnerability involving physical access to a device, but it does not establish that attackers penetrated the company’s central cloud network.
A Physical Attack, Not a Remote Cloud Breach
The hackers did not simply connect remotely to the surveillance network and download customer information.
Instead, they obtained the actual hardware, dismantled it and examined its storage and software.
The recovered data consequently came from that individual camera rather than from a demonstrated compromise of the company’s wider cloud infrastructure.
Privacy Questions Are Growing
The discovery arrives as Flock’s surveillance technology faces broader scrutiny over how license-plate data is collected, stored and accessed.
The company’s cameras are used by law enforcement agencies to help identify vehicles connected to investigations. But the ability to search historical vehicle movements has also generated concerns about how the technology could affect people who are not suspected of wrongdoing.
Recent investigations have documented cases in which law enforcement personnel allegedly misused license-plate reader systems to monitor individuals for unauthorized purposes.
The latest incident adds another dimension to that debate: what happens when the hardware itself falls into unauthorized hands?
What the Camera Discovery Means
The stolen camera did not expose evidence of a successful breach of the broader cloud network. But it did reveal how much information can accumulate inside a single surveillance device.
More than 1.6 million images, tens of thousands of video clips and records involving roughly 50,000 vehicles were recovered from one camera operating for only a few weeks.
For privacy advocates and cybersecurity researchers, the episode highlights the importance of securing not only centralized databases but also the physical devices collecting information on public roads.
As automated surveillance networks continue to expand, the security of each individual camera may become just as important as the security of the cloud systems connecting them.
Also read: Mistress Reveals Ultimatum Before Singer’s Wife Was Killed







