Hackers rip Flock spy camera off pole and crack open its secrets
Hacktivists want others to know how they did it

- Hackers accessed an encryption key after taking physical possession of a roadside Flock camera.
- Recovered software showed the camera could detect people, vehicles, bicycles, and license plates.
- About 21 days of activity included roughly 50,200 vehicles and 1.6 million images.
- Flock said tampering with its cameras is illegal and said it lacked enough detail to assess the claims.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
A group of hackers tore down a roadside Flock camera and managed to access its encryption key, unlocking thousands of videos and software that they say has been designed to detect people as well as cars.
The hackers are part of a collective calling itself Stegan0gram, which says it obtained the Flock hardware “in the field” in order to reverse engineer the surveillance technology.
“Why just destroy them when we can reverse engineer them and find the secrets of those spying on us ?” one of the hackers told Wired.
The group dismantled the camera and made a near-complete copy of its stored data before sharing the material with 404 Media and the transparency nonprofit Distributed Denial of Secrets, which provided it to Wired for analysis.
Flock unlocked
Flock has described its cameras as using on-device encryption, yet after gaining physical access to this camera, the hackers managed to access a key stored on the device.
While some of the device’s most sensitive storage remained encrypted and inaccessible, the recovered keys showed that the physical possession of at least one camera could expose data that was supposed to be inaccessible.
What Flock watches
The investigation found that the recovered software explicitly detects people, alongside vehicles, bicycles, and license plates.
Flock Safety insists that its plate readers do not track people, despite a growing number of reports that suggest otherwise.
When the cameras detects a person, the software records their position in the images and how confident it is that it has spotted a human.
Wired extracted the camera’s computer vision models and tested them independently, successfully detecting people, including a selfie of one of its reporters.
Analysis of more than 27,000 short video clips recovered from the device found people in 11 clips, all of them on motorcycles.
The low number of humans in this instance was attributed to the fact that the camera was positioned above a roadway with limited pedestrians.
The investigation also uncovered just how much data is being generated.
Around 21 days of recovered activity showed the camera photographing roughly 50,200 vehicles and producing 1.6 million images.
A typical passing vehicle generated around 28 pictures, while some triggered more than 100. On average, the device logged about 3,300 vehicles.
The investigation found that logs show repeated storage failures.
More than 27,000 “no space left on device” errors while saving full-resolution images were documented, along with tens of thousands of related errors, crashes, and reboots.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Flock told Wired that “the unauthorized removal and tampering of a Flock camera is illegal.”
Asked about the encryption key stored on the camera, the company said it takes security seriously, has a public vulnerability disclosure policy, received no report through that process, and lacked enough detail to assess the claims
The Stegan0gram hackers, meanwhile, say they plan to publish more details about how they obtained and analyzed the software – potentially paving the way for anti-flock activists to perform a different kind of teardown.