The Flock camera backlash, and the case for knowing your own network
ยท 10base-t interactive
Over the past year, dozens of city councils have canceled their contracts with Flock Safety, and in some towns residents have simply pulled the company's license plate readers down themselves. Flock says it runs something like 120,000 of these cameras across the US, feeding a shared database that lets police in one city search plates captured in another. The pitch was solving car break-ins and stolen vehicles. This month the backlash grew to include the cameras themselves being wide open to anyone with a browser.
Flock Safety cameras are solar-powered automated license plate readers (ALPRs) that photograph every passing vehicle, read its plate, and log the make, model, color and other visible details into a shared database that police departments across the country can search. Flock says roughly 120,000 of them are running in the US today. They've become one of the most contested pieces of everyday policing technology in the country:
- Nationwide vehicle tracking with no warrant required
- Officers documented using it to stalk partners and exes
- Federal immigration agents querying local police data
- Dozens of exposed cameras found streaming to the open internet
The exposed cameras
404 Media reported that at least 60 of Flock's Condor pan-tilt-zoom cameras, the ones built to automatically zoom in on faces as people walk through parking lots, streets, and playgrounds, were left livestreaming to the open internet with no password. A reporter stood on a street corner in Bakersfield, California and watched the feed of themselves on their own phone. Colleagues hundreds of miles away could watch the same feed, download 30 days of stored video, and reach the camera's admin panel, logs, and diagnostics. Public radio's Marketplace covered the fallout, and the exposure led Senator Ron Wyden and Rep. Raja Krishnamoorthi to formally call on the FTC to investigate Flock for failing to secure the data it collects.
No design flaw in the surveillance model caused this. It was a configuration failure, the kind that's easy to have and hard to notice, which turns out to be the theme running through Flock's whole year.
Misuse alongside exposure
The other thread is people with legitimate access using it for reasons that have nothing to do with crime-solving. CNN documented a Milwaukee police officer who used the system to look up a romantic partner's location 124 times and an ex-partner's 55 times, with no case number and no warrant, just access. In Colorado, a police chief discovered federal immigration agents were querying his town's plate data after local policy said they shouldn't be able to. Flock's response was to say it had cut off that specific access. The Washington Post reported Flock has since announced platform changes aimed at tightening who can query what, after at least 30 localities deactivated cameras or ended contracts since the start of 2025.
The exposed cameras and the misuse cases share a common thread. A networked system's access controls and exposure were more theoretical than enforced, and it took an outside party (a journalist, a police chief, a reporter with a laptop) to notice.
The part that applies beyond Flock
Set the politics aside and there's a plainer point here: a device on a network doesn't announce whether it's locked down or wide open. That's true of a municipal camera network and it's true of a lot of consumer and small-business hardware too. A doorbell camera, a "smart" driveway sensor, a cheap Wi-Fi camera an Airbnb host installed and forgot about all work the same way. The device is on the network, and unless you go looking, you don't actually know what it's doing or who else can reach it.
That's the argument for occasionally auditing your own network rather than trusting that anything already plugged in is accounted for. On a home or office Wi-Fi network, that means seeing every device currently connected, not just the ones you remember adding. IP Scanner sweeps the subnet, resolves hostnames, and matches MAC address prefixes against the vendor registry, so a camera you didn't know was there shows up labeled by manufacturer instead of as an anonymous IP address. It also flags new devices the moment they join, which is the useful trick: you don't have to remember to go check, it tells you when something new shows up. It won't tell you whether a camera's admin panel is exposed to the open internet the way Flock's were, since that's a setting on the device and its router and not something visible from a local scan, but knowing the camera is there at all is the step that has to come first.
What to actually look for
A device worth a second look usually has one of these traits: it's a manufacturer you don't recognize and didn't buy, it's been on the network longer than you can account for, or it's talking to an external address on a regular schedule when nothing you're doing should cause that. None of those are proof of anything by themselves, since plenty of ordinary smart-home gear phones home constantly by design. But they're the starting point for the same question the exposed-camera reporting and Flock's critics are asking at very different scales: who put this here, and who else can see what it collects.
Frequently asked questions
Is Flock Safety illegal?
No. Automated license plate readers are legal in most US jurisdictions and are typically installed under contract with local police or a homeowners' association. The controversy is over data retention, who can query the shared database, documented cases of access being used outside its stated purpose, and, as of August 2026, cameras left exposed to the open internet. The legality of the cameras themselves isn't in question.
Were Flock's cameras actually hacked?
No breach was required. 404 Media's investigation found the cameras' livestreams and admin panels reachable by anyone who found the address, with no password: a misconfiguration rather than an exploit. That's arguably more concerning, since it means anyone who looked would have found the same thing.
How do I find hidden cameras on my home network?
Cameras that are on your Wi-Fi network, rather than fully offline, will show up in a network scan like any other device: hostname, IP address, and a manufacturer name resolved from its MAC address. A tool like IP Scanner lists every connected device and can alert you when a new one joins. It won't find a camera that's recording locally with no network connection at all, which is rarer but does exist.
Can I check whether a camera on my own network is exposed the way Flock's were?
A local network scan will tell you a camera exists and who made it, which is the first thing to know. Whether its admin interface is reachable from the open internet is a separate question, controlled by the camera's own settings and whatever port-forwarding or UPnP rules your router has. It's worth checking directly in the camera's app or web interface, and disabling any remote access you didn't deliberately turn on. Get IP Scanner for Mac and iOS to see what's actually on your network first.