Hackers who physically removed a Flock Safety roadside camera recovered software, logs and media that reveal how the device captures vehicles and detects other objects. A joint analysis by WIRED and 404 Media found records of about 1.6 million images associated with roughly 50,200 vehicles over 21 days of logged activity.
The material was supplied by a collective calling itself stegan0gram through the transparency nonprofit Distributed Denial of Secrets. The hackers accessed the camera's Android-based system and copied storage partitions. Although sensitive portions remained inaccessible, they found an encryption key on the device that unlocked a media area containing still images and short videos.
The recovered code shows that a passing vehicle can trigger a rapid sequence of photographs rather than a single frame. A typical vehicle produced about 28 images, while some generated more than 100. Different exposures capture the license plate and the broader scene; software selects and crops useful frames before sending data to Flock over a cellular connection. Analysis indicated that plate reading and classification of vehicle make, model and color occur on company servers rather than on the camera itself.
Logs from several periods covered about three weeks, during which the device recorded around 3,300 vehicles on a typical day and as many as 4,454. Those figures describe this camera's location and cannot be generalized to every installation. Older activity may also have been overwritten or otherwise unrecoverable.
The device's computer-vision software explicitly detected people, bicycles, vehicles and plates. When it identified a person, it recorded the object's location in the frame and a confidence score. WIRED extracted the models and tested them with sample imagery and recovered clips, finding that they recognized people. The software also sometimes isolated visual details such as bumper stickers or other graphics.
Flock cameras send detections to company servers, where authorized agencies can search time-stamped records. Some local camera networks are available to large numbers of outside agencies, a sharing model that has generated controversy over surveillance reach and the use of searches for immigration enforcement and other investigations.
The findings also add context to earlier claims about device security. A researcher documented flaws requiring physical access in 2025; Flock said at the time that images stayed on a device only briefly and that access would not expose footage. The newly recovered material indicates that a person with custody of a camera could obtain at least some media by locating a key stored on the unit.
This incident depended on taking the hardware, and it does not show remote access to the wider network. It does, however, provide an unusually concrete view of what one camera retained and how much visual material its capture pipeline generated.



