Flock Wants the Most Detailed Map of Its Surveillance Cameras Taken Offline

Hacker News by 6 min read 56x views
Flock Wants the Most Detailed Map of Its Surveillance Cameras Taken Offline

Share Post

Amid mounting concerns concerning its sprawling surveillance camera network, Flock Security told the media this summer that it operates more than 120,000 cameras nationwide.

But a new map published Wednesday by a cybersecurity investigator reveals Flock’s nationwide attain is equal bigger. Based on location coordinates from Flock’s own database, the map shows additional than 170,000 cameras, affirmative additional than 130,000 accompanying gadgets that perform a part in the company’s extended American surveillance network.

Joshua Michael’s Flock Surveillance Map highlights the locations of what he says are 300,000 Flock surveillance devices dispersed throughout the country. His findings — which were cited in Wednesday’s Senate Subcommittee on Crime and Counterterrorism hearing on Flock — differ from existing maps of Flock’s automated licence dish readers in range and methodology.

“These cameras form a nationwide surveillance network that tracks anywhere everyone drives.”

Unlike crowd-sourced projects specified as DeFlock, which are built on locations submitted by users, the Flock Surveillance Map relies on location data culled from a snapshot, archived by Michael in December 2025, of Flock’s own records. In supplement to cameras, it maps supplemental devices — including 27,000 acoustic finding devices, as fine as networking equipment that integrates third-party cameras — to exemplify the measure of Flock’s surveillance web.

“These cameras form a nationwide surveillance network that tracks anywhere everyone drives,” Michael told The Intercept, “so abroad nations don’t need to dispatch spies to damage our country. They can merely observe anywhere our soldiers, national agents, and politicians go.”

The Intercept visited six random Arizona locations on Michael’s map; all location had a Flock camera current at the indicated coordinates.

The Flock Surveillance Map additionally color-codes all Flock equipment according to its example — showing, for instance, whether the equipment is a Flock camera, known as a Falcon, or an accompanying handling component known as a Picard. (Flock did not immediately react to a petition for comment.)

The accompanying searchable dataset table additionally lists all camera’s idiosyncratic name, as outlined in Flock’s database, which typically includes a street location and sometimes another identifying characteristics. A camera alongside the name “FBI Pilot Camera,” for example, is shown to be located at the J. Edgar Hoover Building — the FBI agency in Washington.

The map illustrates Flock’s national spread, but additionally its clustering in certain areas. For example, 860 Flock devices appear to be concentrated fair exterior Chicago O’Hare International Airport, at the Rosemont Public Safety Department, which provides police, fire, and emergency medicinal services in the Chicago suburb.

Numerous Flock cameras appear to be installed inner detention centers. A camera titled “C-F-23 FOXTROT MALE HOLDING 2/SHOWERS” appears at the coordinates of the Silverdale Detention Center in Chattanooga, Tennessee.

In November 2025, Michael discovered a novel way to acknowledge the location of Flock’s devices. Trawling the company’s website, he realized that Flock’s servers were publically leaking data in the form of an admission token that could be acquired without needing to log in. With that token, Michael stated he could query ArcGIS, a third-party geographic data scheme phase used by Flock, to recover the locations of Flock devices.

Michael told The Intercept he promptly contacted Flock and described his findings. As Michael wrote in his first email to Flock on November 13, 2025: “all evaluation was strictly non-intrusive, constricted to open unauthenticated endpoints, and did not affect bypassing authentication, modifying data, or invoking any billable ArcGIS or Google operations.” Michael stated he didn’t obtain a reply, so he followed up alongside Flock the next day, and a third period multiple days later.

After his third attempt to communicate Flock of the discovered vulnerability, Michael received a answer from a Flock that said, “Thank you for the findings. We are internally triaging them and volition attain rear out alongside next steps soon.”

Michael stated he never heard rear concerning it from Flock.

In December 2025, Michael downloaded the Flock equipment location data, and in January wrote an in-depth specialized blog post concerning what he had found. After Michael’s post, it appears that Flock fixed the vulnerability.

Despite being alerted of Michael’s findings in November 2025, Flock published its own blog post the following January saying it hadn’t had any data breaches. “Flock has never been hacked, and there has not been a leak of Flock information,” the business claimed. “Flock Safety’s haze phase has never informed a data breach.”

The Atlanta-based startup has faced mounting criticism for its practices and deficiency of transparency in latest months. An American Civil Liberties Union report established “a form of Flock regularly misleading or equal lying concerning its endeavor practices, safety record, dedication to privacy, and efforts to defend susceptible populations.”

Michael told The Intercept that Flock’s latest claims concerning its data safety document don’t indicate reality. Flock has publically claimed multiple times that the business has never informed a data breach, “and this was following I pulled their repository of devices.”

“That leaves two possibilities,” he said. “Either they knew and chose not to disclose it for fear of bad press, or they didn’t cognize I exfiltrated the data at all. The archetypal is a transparency failure. The second is a finding nonaccomplishment alongside national safety implications.”

On Thursday, Michael was notified that Doppel, which describes itself as an “AI-native social engineering defence platfom,” submitted a trademark infringement grievance concerning his site, claiming to be operating on Flock’s behalf. Doppel says that the location is using the trademark “FLOCK SAFETY” without authorization, which “may logic client disturbance / harm.” Doppel requested the location be taken down.

When he posted the Flock Surveillance Map, Michael included a pop-up disclaimer saying that the location is “not affiliated alongside or endorsed by Flock.”

Other Article Hacker News
↑
Close Right Ads
Close Left Ads