Flock’s automated license plate reader cameras are designed to capture vehicles and identify important details such as license plates, colours, makes and models. But a recent discovery by a hacking group has raised fresh questions about how much data these cameras actually retain on the devices themselves.
Flock has previously said that images captured by its cameras are only briefly stored locally before being transferred to the company’s servers. However, hackers who obtained and analyzed a Flock camera reportedly found that the device had retained a substantial amount of visual data.

Credits: Mashable
Hackers Find Millions of Images on Flock Camera
According to 404 Media, a hacking group known as stegan0gram took down a Flock camera positioned above a roadway and examined the information stored inside the device.
The group was unable to access the most sensitive data on the camera, but researchers were reportedly able to gain access to its Android operating system. They discovered two storage partitions named “vendor” and “media.”
The media partition contained an encryption key that could be used to unlock another partition containing media files captured by the camera.
The amount of information stored on the device was significant. The particular camera reportedly contained approximately 1.6 million images collected over 21 days. During that period, the system detected around 50,200 vehicles and 11 people.
Researchers also found 27,321 video clips stored on the device. These were MP4 files with a resolution of 1024 × 768 pixels and typically lasted between one and two seconds.
The findings appear to challenge Flock’s description of how long camera images remain on the hardware before being transferred to its cloud infrastructure.
What Flock Cameras Can Do Without the Cloud
Flock’s cameras rely heavily on its servers for more advanced analysis. Reading license plates and determining characteristics such as a vehicle’s colour, make and model are handled by the company’s server-side systems.
However, the cameras themselves are not simply passive recording devices.
They have some edge AI capabilities that allow them to detect objects including people, vehicles, bicycles and plate-like shapes. The camera can then crop relevant portions of an image and send those crops to Flock’s servers along with the original image.
Researchers also reportedly discovered facial-detection functionality in the device. However, 404 Media said this appeared to be a standard capability included with the Android operating system rather than a feature actively being used by Flock’s camera software.
Flock has also said that its cameras use on-device encryption. While a security researcher previously identified weaknesses in the system, the company reportedly argued that exploiting those vulnerabilities still requires physical access to a camera.
The latest discovery is therefore particularly notable because it involves precisely that kind of physical access.
Discovery Adds to Flock’s Growing Privacy Debate
The findings arrive as Flock faces continued scrutiny over the use of its automated license plate reader network and the potential consequences of large-scale vehicle surveillance.
There have already been reports of law enforcement officers misusing the system. Several police officers have reportedly been arrested or investigated for allegedly using Flock data to monitor romantic partners. In another case, a mistaken license plate match reportedly contributed to police detaining a car reviewer after authorities incorrectly associated his vehicle with stolen tags.

Credits: KATU
These incidents have contributed to broader debates over who can access Flock’s data, how the technology is used and what safeguards are in place to prevent misuse.
Some municipalities have subsequently ended their relationships with Flock, while others have continued using the technology. Meanwhile, some individuals opposed to the cameras have attempted to physically obstruct them.
Critics of such actions, however, have argued that damaging or interfering with surveillance equipment could ultimately strengthen arguments for deploying more security technology.
The latest discovery shifts attention back to another important question: what happens to surveillance data before it reaches the cloud?
If substantial quantities of images and video can remain stored on individual cameras, the security of those devices becomes an important part of protecting the information they collect. For communities debating the use of automated license plate readers, that distinction could prove significant—not only in terms of privacy, but also in determining how securely millions of captured images are handled throughout the surveillance system.




