Hackers stole a Flock surveillance camera and cracked it open — here's what a former Secret Service expert says it means

By 
, September 25, 2026 
Category:

Hackers who physically ripped a Flock Safety license-plate camera off a roadway pole and reverse-engineered it recovered 1.6 million images, but a former Secret Service cybercrime specialist says the company's broader network was never breached.

The incident, first detailed by WIRED, exposed roughly 21 days of surveillance logs from a single device. Those logs contained images of 50,200 vehicles and 27,000 short video clips, all pulled from a camera that had been quietly recording traffic from its perch above a public road before someone climbed up and took it.

Jason Brown, a cybersecurity expert who spent 25 years with the U.S. Secret Service investigating cybercrime, reviewed the breach and told FOX Business the damage was limited to what was stored on that one device. Brown now serves as director of customer advisory and counter-fraud lead at iCOUNTER, a threat intelligence firm.

Brown says the cloud stayed locked, the camera did not

The hackers discovered that portions of the camera's onboard storage were encrypted and portions were not. They then found an encryption key stored directly on the device itself, which let them unlock the rest. That key was the whole ballgame. It gave them access to everything the camera had logged locally, but nothing beyond it.

Brown drew a hard line between what the hackers got and what they did not get:

"This was a situation where somebody physically had access to a camera because they stole it off of a pole, took it home, and then did backward engineering on that camera."

He added that the breach stopped at the device level.

"That did not give them the capability to actually log into the cloud portion of Flock, and nothing in the cloud of Flock proper was accessed."

Brown characterized the incident as isolated. "They are one-off situations and don't show a larger problem for the Flock system that I'm aware of," he said. Flock Safety itself claims that approximately 97 percent of law enforcement agencies using its system now have multifactor authentication enabled, an extra layer of login security, though that figure is self-reported and has not been independently verified.

FOX Business reached out to Flock Safety for comment. The company did not respond.

A stolen camera is not the only security gap Flock has faced

The physical theft was not the first time Flock's hardware raised questions. Some of the company's cameras previously became remotely accessible over the internet because of weak authentication controls, meaning outsiders could potentially reach them without stealing anything at all. That vulnerability was later addressed, though the timeline and scope of the earlier problem remain unclear.

The pattern is familiar in the broader cybersecurity landscape. The Washington Examiner reported that FireEye's Mandiant team discovered 14 Cisco routers across four countries, Ukraine, the Philippines, Mexico, and India, infected with persistent malware called "SYNful Knock" for up to a year before anyone noticed. Cisco described it as "a type of persistent malware that allows an attacker to gain control of an affected device." When hardware sits unmonitored in the field, whether it is a network router or a surveillance camera, physical and digital vulnerabilities compound.

Flock cameras have also drawn scrutiny for how the data they collect gets used by the people authorized to access it. In Columbus, Ohio, police suspended their Flock camera program after an officer allegedly searched a single license plate 270 times. The problem was not hackers, it was an insider with a badge.

Brown acknowledged that the technology carries real trade-offs but argued the public should not change its behavior because of cameras on the roadside.

"Should a person conduct themselves differently because a Flock camera is there? I would argue no."

He pointed to law enforcement wins as justification for the surveillance footprint:

"We've seen good uses of the technology, where individuals, a murder is committed in one city and the individuals responsible for it were identified by Flock cameras in another city. You know that that's a positive, but we all have to understand that whenever we're out in public, we do not have a reasonable expectation of privacy. We are in public. Anybody can take a picture of us at any time. It may not be the polite thing to do, but anybody can do it at any point in time."

Communities across the country are already pushing back

Brown framed the adoption question as a local decision. "The debate of do you have Flock in your community, that's a debate for the community," he said. That debate is already well underway. Towns and cities in multiple states have canceled Flock contracts or faced public backlash over the cameras, with some residents going so far as to vandalize the devices.

The opposition is not confined to one side of the aisle. Flock surveillance cameras have drawn bipartisan resistance from voters and officials who see mass license-plate tracking as a step too far, regardless of party affiliation.

And the abuse cases keep surfacing. In Albany, New York, a sheriff's investigator was charged with using Flock cameras to stalk an ex-girlfriend nearly 3,000 times. That is not a hacker exploiting a technical flaw. That is a government employee exploiting the system exactly as designed, just for the wrong reasons.

Supply-chain risk is accelerating, and AI makes it worse

Brown widened his analysis beyond the single stolen camera. He warned that third-party technology vendors, companies like Flock that supply hardware and software to law enforcement, represent a growing supply-chain risk. Agencies that adopt these tools inherit whatever security weaknesses come with them.

"We have [to] gather intelligence on what is happening with the third parties and then work with those third parties before the incident even occurs to ensure that they are secure, so our customers are ultimately secured. And in this day of AI, the speed and the veracity of that only increases by the minute."

"The security posture of everything is changing by the minute," Brown said. That is not reassurance. It is a concession that the threat environment moves faster than the defenses built to contain it.

The identities of the hackers who stole the camera remain unknown. No motive has been publicly stated. No arrests have been reported. No law enforcement or regulatory body has announced an investigation. The camera's current whereabouts, whether it was recovered or remains in the hackers' possession, have not been disclosed.

What is known is that a single device, bolted to a pole above a public road, held 1.6 million images and the encryption key needed to read them. The hackers did not need a sophisticated network attack. They needed a ladder and some patience.

When a surveillance system stores that much data on a device anyone can reach with a pair of bolt cutters, the question is not whether the cloud is secure. The question is whether the people living under these cameras ever had a say in the first place.

About Alan Benson

STAY UPDATED

Subscribe to our newsletter and receive exclusive content directly in your inbox