A security researcher’s discovery that dozens of Flock Safety cameras were reportedly accessible online without usernames, passwords, or encrypted footage is intensifying concerns about the rapidly expanding network of automated license-plate readers used by law enforcement. Researcher Benn Jordan says the exposed cameras allowed him to monitor locations and potentially connect license-plate information with people’s daily routines, while Flock maintains that its network has never been “hacked.” Separate security research identified 67 live camera feeds and debug interfaces allegedly exposed without authentication, while federal vulnerability records have documented security weaknesses affecting Flock license-plate-reader firmware. The revelations add a cybersecurity dimension to an already growing debate over government surveillance, privacy, police misuse, and whether municipalities are exercising sufficient oversight before installing powerful monitoring technology across American communities.
Key Takeaways
- Researchers found Flock camera feeds and administrative interfaces exposed to the public internet without authentication, demonstrating that surveillance infrastructure can create security vulnerabilities far beyond the government agencies authorized to use it.
- The controversy is broader than cybersecurity: investigations have uncovered cases in which police personnel allegedly used license-plate-reader systems for personal surveillance while departments lacked routine auditing procedures capable of detecting misuse.
- Flock’s insistence that its cloud platform has never been hacked does not eliminate the larger public-policy concern: government surveillance technology must be secured, audited, limited, and subjected to meaningful oversight before citizens are expected to trust it.
In-Depth
The security controversy surrounding Flock Safety has moved beyond an abstract debate over surveillance and into a basic question of whether government-linked camera infrastructure is protected with safeguards commensurate with its power. Researcher Benn Jordan says he found dozens of Flock cameras exposed online without usernames or passwords, with footage transmitted unencrypted. That access reportedly made it possible to observe locations and connect license-plate information with individuals’ routines.
The distinction Flock draws between a “hack” and unauthorized access may matter technically, but it does little to resolve the public-policy problem. A surveillance system capable of cataloging vehicle movements across communities creates information. If cameras or associated services can be reached without authentication, citizens have reason to question whether governments conducted adequate security reviews before deploying them.
Those concerns are compounded by problems involving authorized users. Investigations have found officers accused of using license-plate systems for personal purposes, while some departments reportedly failed to conduct routine audits. Flock has responded with additional oversight measures intended to tie searches more closely to legitimate investigations.
The conservative concern is straightforward: public safety does not require giving government or its contractors a blank check. Technology that helps police identify stolen cars or locate dangerous suspects can be valuable, but usefulness does not erase constitutional principles, privacy expectations, or government’s obligation to secure sensitive systems. Powerful surveillance tools demand strict access controls, audits, limited retention, transparent policies and consequences for abuse. Security cannot be an afterthought once a nationwide monitoring infrastructure is watching Americans travel.
Sources
- https://gainsec.com/2026/01/09/bird-hunting-season-finding-67-live-camera-feeds-and-debug-web-interfaces-accidentally-exposed-by-flock-safety/
- https://nvd.nist.gov/vuln/detail/CVE-2025-47823
- https://www.washingtonpost.com/technology/2026/08/19/we-found-cops-who-misused-flock-their-police-departments-didnt-know/

