· via Hacker News – Front Page (hnrss.org)
Researcher's map puts Flock's US surveillance network at 300,000 devices, far above its own count
A map built from Flock Safety's own database logs over 170,000 cameras and some 130,000 companion devices across the US, far above the company's stated figure, and it now faces a takedown complaint.

A cybersecurity researcher has published an interactive map of Flock Safety's surveillance infrastructure across the United States that counts roughly 300,000 devices, far more than the 120,000 cameras the company told journalists it operated this summer, according to The Intercept.
What the map shows
The Flock Surveillance Map, built by researcher Joshua Michael, plots more than 170,000 cameras alongside over 130,000 supporting devices, including some 27,000 acoustic detection units and networking equipment that folds third-party cameras into Flock's system. Unlike crowd-sourced projects such as DeFlock, which depend on user-submitted locations, the map is drawn from a snapshot of Flock's own device database that Michael archived in December 2025. Devices are color-coded by model — distinguishing Falcon cameras from Picard processing units — and a searchable table lists each device's internal name, which typically includes a street address.
The Intercept visited six randomly selected Arizona locations from the map and found a Flock camera at every one. The underlying data also surfaces details the company does not advertise: a device named "FBI Pilot Camera" sits at the J. Edgar Hoover Building, the FBI's Washington headquarters; roughly 860 devices cluster at the Rosemont Public Safety Department just outside Chicago O'Hare International Airport; and a camera named "C-F-23 FOXTROT MALE HOLDING 2/SHOWERS" appears at the coordinates of the Silverdale Detention Center in Chattanooga, Tennessee. Michael's findings were cited during Wednesday's hearing of the Senate Subcommittee on Crime and Counterterrorism, The Intercept reports.
How the data was obtained
The method behind the map is itself a story about Flock's security posture. In November 2025, Michael discovered that Flock's servers publicly exposed an access token that could be retrieved without logging in. With that token he could query ArcGIS, the third-party geographic information platform Flock uses, and pull the locations of the company's devices. He stresses that his testing was non-intrusive, limited to open unauthenticated endpoints, and did not modify data.
Michael emailed Flock on November 13, 2025 to report the flaw and followed up twice more. After the third attempt, the company replied that it was triaging the findings — and, he says, never responded again. He downloaded the device location data in December and published a detailed technical write-up in January, after which the vulnerability appears to have been fixed.
Denials and a takedown attempt
Also in January, Flock published a blog post asserting that it had never been hacked and that no Flock information had leaked — a claim issued after Michael had pulled the company's entire device database. As he framed it to The Intercept, either Flock knew about the extraction and chose not to disclose it, which he calls a transparency failure, or it never noticed, "a detection failure with national security implications."
Scrutiny of the Atlanta-based startup, best known for automated license plate readers, extends beyond this episode. An ACLU report concluded there was "a pattern of Flock regularly misleading or even lying about its business practices, safety record, commitment to privacy, and efforts to protect vulnerable populations."
Then, on Thursday, Michael was notified of a trademark infringement complaint filed by Doppel, a firm describing itself as an "AI-native social engineering defense platform" that says it is acting on Flock's behalf. The complaint argues the map site uses the trademark "FLOCK SAFETY" without authorization and may cause customer confusion, and it asks that the site be taken down — even though Michael's site displays a pop-up disclaimer stating it is not affiliated with or endorsed by Flock. Flock did not immediately respond to The Intercept's request for comment.
Why it matters
The gap between the 120,000 cameras Flock acknowledged and the roughly 300,000 devices documented from its own records is not a rounding error; it is the distance between the company's narrative and an auditable count. The map gives the public and lawmakers the first company-sourced picture of a network that, in Michael's words, "tracks where everyone drives," with device clusters near airports, detention centers and federal buildings showing exactly where monitoring concentrates. The episode also raises accountability questions that outlast the vulnerability itself: a researcher followed responsible disclosure, the company went silent, then publicly insisted it had never suffered a data leak. If one person could enumerate the entire fleet using an exposed token, Michael's warning that foreign adversaries could monitor the movements of soldiers, federal agents and politicians without ever sending a spy is not hypothetical. And responding to a factual, independently verified map with a trademark complaint, rather than by disputing its contents, is a poor look for a company already accused of misleading the public.
- #surveillance
- #privacy
- #security-research
- #flock-safety
- #license-plate-readers