Micron Document

FLOCK petapixel cameras exposed internet
page 2 / 3


What made the exposure more alarming was not just the live feeds but the administrative access available to anyone who found these streams. Some cameras’ control panels allowed the viewer to change camera settings, run system diagnostics, view internal log files, and download months of archived footage, all without a username or password.

How the Cameras Were Found

The exposed cameras came to light through the use of Shodan, a search engine that indexes internet-connected devices. Researchers used Shodan to locate public IP addresses associated with Flock’s Condor cameras that were misconfigured to accept traffic from the open internet. From there, the investigative team verified their findings by visiting the physical camera locations and observing themselves or colleagues live on the unsecured feeds.

This method highlights a broader cybersecurity problem: any internet-connected device without proper security controls, whether a surveillance camera, baby monitor, or industrial system, can be indexed and accessed by unauthorized users if misconfigured.

Company Response and Claims of a Misconfiguration

In response to inquiries, Flock Safety characterized the incident as a limited misconfiguration affecting a small number of devices and stated that the problem had since been corrected. The company told reporters that the exposure was not the result of a hacking incident and that its cloud infrastructure had not been compromised. Flock declined to provide deeper technical details about the flaw or the underlying causes of the exposures, and did not say how many cameras were affected in total.

Critics have questioned both the vagueness of the company’s explanation and the absence of a comprehensive public disclosure, suggesting that the incident reveals systemic weaknesses in oversight, device hardening procedures, and internal security practices.

Not an Isolated Problem: Broader Flock Safety Concerns

The camera exposure occurred amid other controversies surrounding Flock Safety. Back in August, ranking member of the House Oversight Committee Robert Garcia (D-CA) initiated an investigation into Flock Safety over reports and cases in which its ALPR system was used by law enforcement to “track women across state lines following abortion care and to conduct unauthorized immigration enforcement operations.”

“On May 9, 2025, an officer from the Johnson County Sheriff’s Office in Texas provided “had an abortion, search for female” as his reason for using Flock’s ‘National Lookup’ feature to search automatic license plate reader data captured across multiple states. This search reportedly covered 6,809 Flock networks, or more than 83,000 cameras,” Garcia’s letter sent to the FTC states.

Additionally, in Texas, the Department of Public Safety (DPS) launched an investigation into the company’s operations over claims that it had operated certain cameras without a required private security license. According to local reporting, Flock’s license had lapsed because the company failed to maintain proof of required liability insurance, and although a new license was subsequently issued, the situation raised questions about whether the company complied with state regulatory requirements for private security operations while cameras were installed and active in public spaces. DPS officials have continued their review, even as Flock described the issue as an administrative matter that has since been resolved.

Beyond licensing issues, earlier reporting by 404 Media also exposed that Flock may have relied on overseas contract workers to review and classify surveillance footage as part of its AI training processes, raising additional questions about who has access to sensitive data and how that labor is managed across borders.

Long before the recent exposure, Flock Safety had been at the center of privacy and legal debates. In Washington state, a judge ruled that images captured by Flock cameras constitute public records, potentially subjecting them to disclosure under state transparency laws, further complicating how agencies and private citizens interact with the data. Privacy advocates have also raised concerns about how Flock’s data is stored, shared, and potentially integrated with law enforcement databases.

Meanwhile, in November, Congressman Raja Krishnamoorthi (D-IL) and Senator Ron Wyden (D-OR) formally called for an FTC investigation into Flock Safety for “for failing to implement cybersecurity protections, allowing Americans’ personal data to be exposed for hackers, criminals, and spies to steal.”

The exposure of Flock cameras to the open internet has galvanized calls from civil liberties organizations, technologists, and lawmakers for stronger oversight, independent security audits, public reporting requirements, and clearer legal frameworks to govern surveillance technologies. These reforms would aim to ensure that surveillance systems are not only effective in their stated public safety roles but also secure, transparent, and respectful of individuals’ privacy rights.