A group of security researchers says it recovered hardware-embedded encryption keys from a stolen Flock Safety automated license plate reader (ALPR) camera, then used those keys to extract more than 27,000 video clips and 1.6 million images the device had captured over a 21-day span. The findings, shared publicly this week, directly challenge Flock Safety’s longstanding assurances that its cameras do not store retrievable sensitive data if physically compromised.

How the Extraction Happened
According to the researchers, the stolen unit contained cryptographic keys stored on internal storage that were not sufficiently protected against physical tampering. Once removed, the keys allowed the group to decrypt locally cached footage and metadata, including timestamps, location data, and vehicle images the camera had recorded before it was taken offline.
The scale of the recovered data is notable: tens of thousands of clips and well over a million still images from just three weeks of operation, illustrating how much footage a single roadside unit accumulates and retains even without a live network connection.
Flock Safety’s Prior Denials
Flock Safety has repeatedly told customers, journalists, and privacy advocates that its cameras are engineered so that a stolen device poses minimal risk, arguing that footage is encrypted and that keys are managed in a way that prevents offline extraction. The company has used this claim to reassure law enforcement agencies and municipalities weighing the privacy tradeoffs of deploying its network.
The researchers say the successful extraction demonstrates a gap between Flock’s public security messaging and the actual protections built into deployed hardware.
Flock Safety has not yet issued a detailed technical rebuttal addressing the specific extraction method described by the group, though the company has previously stated it takes device security seriously and continuously updates its hardware protections.
Part of a Broader Pattern of Scrutiny
This is not the first time Flock’s practices have drawn criticism. Earlier this year, reporting revealed that some police officers had logged reasons as flippant as “LMAO” when running searches through Flock’s nationwide camera network, raising questions about oversight of who can query the system and why. Separately, Boston ended its Flock camera program altogether after concerns emerged about how license plate data was being shared across jurisdictions, including with agencies outside the city’s own oversight structures.
Together, these incidents paint a picture of an ALPR industry that has expanded rapidly into thousands of communities while facing recurring questions about data governance, access controls, and now, physical device security.
Why Physical Security Matters
ALPR cameras are typically mounted in public, often unguarded locations along roads and intersections, making them vulnerable to theft or tampering compared to servers housed in secured data centers. Security researchers have long warned that any internet-connected surveillance hardware deployed in the field needs to assume a stolen-device threat model, meaning that even if a unit is physically taken, the data it holds should remain inaccessible without proper authorization.
The extraction described this week suggests that assumption did not hold for at least this camera model. If encryption keys can be pulled from hardware without specialized, expensive equipment, then any of the thousands of Flock units deployed across the country could theoretically be at similar risk if stolen.
What Happens Next
Privacy advocates are likely to point to this disclosure as further evidence that ALPR networks need independent security audits before deployment, rather than relying solely on vendor assurances. Some city councils and police oversight boards that have paused or reconsidered Flock contracts may cite the finding as additional justification for tighter contractual security requirements or third-party penetration testing before renewal.
For now, Flock Safety customers, including police departments, homeowners associations, and municipalities, are left weighing whether the company’s response will include concrete hardware fixes or firmware updates addressing the vulnerability. Flock has not announced a recall or mandatory patch in connection with this incident as of publication.
The broader debate over surveillance technology’s security posture is unlikely to fade soon. As ALPR networks, similar to other connected infrastructure facing scrutiny after incidents like the recently disclosed Chinese hacking campaign against federal agencies, continue to expand into more communities, the tension between public safety utility and data protection risk remains unresolved. Researchers say they plan to publish further technical details of the extraction method to allow independent verification and to pressure vendors toward stronger physical security standards industry-wide.