How the Data Was Exploited Without Authentication
On September 27, 2026, Flock Safety requested the takedown of a publicly accessible map created by a security researcher that displayed the locations of over 335,000 Flock license plate recognition cameras across the United States. The map was generated using an unauthenticated vulnerability on Flock’s website that allowed access to third-party provider data without requiring login credentials. The exposure raised immediate concerns about the potential misuse of location data for surveillance or tracking purposes.
Latest news
Minisforum Unveils High‑End Ryzen AI Max+ PRO 495 Workstation
NASA Eyes Revival of SR‑71 Blackbird
My Home Wi‑Fi Was Crowded by 14 Neighbors—A Free App Helped Me Find a Clear Channel
YouTube is tightening rules for low-effort ShortsThe flaw enabled anyone with basic web knowledge to query Flock’s backend systems and retrieve precise geolocation data for cameras installed in neighborhoods, near schools, and along major roadways. Researchers warned that such information could be exploited to monitor movements of individuals, including personnel associated with military installations, government facilities, and other sensitive locations. Flock acknowledged the issue internally but has not disclosed when the vulnerability was first identified or how long it remained accessible before being secured.
Could This Information Be Used to Threaten Public Safety?
The researcher demonstrated that by manipulating parameters in Flock’s public-facing API endpoints, it was possible to bypass authentication checks and extract camera coordinates, installation dates, and associated metadata. No hacking tools or advanced techniques were required—only standard web requests using a browser or script. Flock confirmed the data originated from its integration with a third-party cloud service used for device management, which had misconfigured access controls. The company stated it has since patched the flaw and implemented additional monitoring to prevent recurrence.
While Flock maintains that the data alone does not reveal vehicle identities or real-time tracking capabilities, experts caution that combining camera locations with other public records could enable detailed pattern analysis. Law enforcement agencies use Flock systems to assist in investigations, but the widespread deployment raises privacy concerns among civil liberties groups. The incident has prompted calls for stricter oversight of how private surveillance networks handle location data, particularly when deployed at scale across public and private spaces.
What specific data was exposed through the vulnerability? The exposed data included latitude and longitude coordinates, installation timestamps, and device identifiers for Flock cameras, but not live video feeds or license plate reads.
Frequently Asked Questions
Has Flock notified users or law enforcement partners about the incident? Flock has not issued a public notice to customers or partners, stating it resolved the issue internally before any known misuse occurred.
Is the researcher’s map still available online? As of the request date, Flock has issued a takedown demand, but the map may still be accessible through archived or mirrored sources depending on hosting platforms.
Comments
Leave a comment