FLOCK 00 security research and breaches
page 1 / 1
Flock Safety — Cybersecurity Incidents & Vulnerability Research
factual-summary . retrieved 2026-07-11
sources: GainSec white paper, SimeonOnSecurity, PetaPixel, WFLX, Flock Safety (company statements), TechTimes
archived for offline mesh reading
------------------------------------------------------------
Cybersecurity Incidents & Vulnerability Research
Documented security findings and exposures, with dates, sources, and Flock's responses.
Scale context: Flock devices photograph/track a reported **150M+ vehicles/day** across
**80,000+ deployments**, so device and platform security has systemic reach.
Independent vulnerability research (late 2024 – 2025)
- **GainSec white paper — "Examining the Security Posture of an Anti-Crime Ecosystem."**
Reported **51 findings**, with **22 CVEs assigned** (8 pending) via MITRE. Paired with
hands-on hardware testing by researcher **Ben Jordan**.
- **Physical-access takeover.** Researchers reported that a person with **physical access**
to a camera could gain **full control in under ~60 seconds** via a button-press sequence
that opened a **WiFi access point protected by a hardcoded password.**
- Additional reported issues spanned exposed services, weak/hardcoded credentials, and
device-management weaknesses (catalogued in the SimeonOnSecurity writeup, 2026).
- **Disclosure process:** researchers say they notified Flock during 2025; Flock issued a
**customer advisory** and **registered vulnerabilities as CVEs** through MITRE.
Exposed live camera feeds — January 2026
- Flock **acknowledged that some camera feeds were exposed to the open internet.** Reporting
(PetaPixel, Dec 2025 / WFLX, Jan 2026) indicated outsiders could **view live feeds, access
roughly a month of archived footage, and in some cases delete video.**
- **Flock's characterization:** an **isolated configuration issue** affecting only a
**small number of "Condor" cameras**, "not indicative of a broader or ongoing concern."
Access-control / misuse incidents (distinct from hacking)
These are **policy/authorization** failures rather than external breaches, surfaced through
public-records **audits** of search logs (see [[../Case Studies/00-documented-incidents]]):
- **Dayton, OH (audit, May 2026):** city data searched **7,100+ times for immigration
enforcement**, a use the city's own policy prohibited; officials called it "egregious."
- **Denver, CO (CORA audit):** **1,400+ searches tied to ICE** since June 2024.
- **Illinois (state audit):** Flock allowed **CBP access via an undisclosed pilot**; 47
agencies later removed; Flock said it would **pause federal pilot programs nationwide.**
Flock's overall security position
Flock's public statements ("Has Flock Been Hacked?", "Response to Compiled Security
Research") maintain that it has **found no evidence of a system-wide breach**, that it
**patches and discloses** reported issues, and that the exposed-feed event was a contained
misconfiguration. Independent researchers dispute the framing of severity, not the
existence of the findings.
Sources
- GainSec — "Examining the Security Posture of an Anti-Crime Ecosystem" (51 findings, 22 CVEs)
- SimeonOnSecurity (2026) — compiled 50+ vulnerabilities writeup
- PetaPixel (2025-12-29); WFLX (2026-01-09) — exposed camera feeds
- Flock Safety blog — "Response to Compiled Security Research," "Has Flock Been Hacked?"
- TechTimes (2026-06-29) — deployment scale; audit-driven cancellations
< prev page 1/1 next