Flock Cameras Exposed 335,701 Locations Through Unauthenticated Vulnerability
Security researcher Joshua Michael found an unauthenticated flaw in Flock's website that granted him an access token without any login credentials. He used that access to build a public map of 335,701 Flock surveillance camera locations across the United States. Flock has responded not by addressing the underlying security failure but by issuing a trademark infringement complaint demanding the map be taken down.
The Discovery
In November 2025, Michael queried ArcGIS, a third-party mapping and geospatial layer that Flock uses, to retrieve a database of Flock devices. He immediately reported the vulnerability to the company in an email dated Nov. 13, 2025. His message stated that all testing was strictly non-intrusive, limited to open unauthenticated endpoints, and did not involve bypassing authentication, modifying data, or invoking any billable ArcGIS or Google operations.
Flock did not reply to his first message. It took two additional attempts before a representative responded with a generic acknowledgment: "Thank you for the findings. We are internally triaging them and will reach back out with next steps soon." According to Michael, Flock has not replied since.
The Map and the Response
Flock patched the vulnerability in January 2026, but Michael had already exfiltrated the device location database. Using that data, he built the Flock Surveillance Map, which lists 335,701 cameras and was updated in December 2025.
Flock maintains that it has never been hacked, that Flock information has never been leaked, and that the Flock Safety cloud platform has never experienced a data breach. Michael rejects those claims, telling The Intercept that Flock's announcement came after he pulled their database. He sees two possibilities: either Flock knew about the exfiltration and chose not to disclose it, which would be a transparency failure, or Flock did not know the data had been taken, which would be a detection failure with national security implications.
Broader Security Failures
This incident is not isolated. Hackers have previously discovered that Flock cameras stored encryption keys directly on the device, enabling the extraction of more than 27,000 stored clips. The same research found that the system captured more than 1.6 million images in a span of 21 days. Separately, police officers were caught misusing the system to surveil romantic partners, and a car reviewer was detained for an hour in a store parking lot after a mistyped police report triggered an Flock alert.
Tracking Personnel at Sensitive Sites
Michael's analysis reveals a more disturbing implication. The density of Flock cameras means the system could be used to track personnel traveling to and from sensitive government and military facilities. His research identified 22 such sites, including Eglin Air Force Base, CIA Headquarters, FBI Headquarters, Joint Base Andrews, and the Pentagon. People living within a 20-mile radius of these sites face a 57.22% to 93.94% chance of passing a Flock camera and being recorded.
The Trademark Complaint
Rather than addressing the security findings, Flock pursued legal action against the map itself. Doppel, a cybersecurity company specializing in social engineering defense, contacted Michael on behalf of Flock. The complaint alleged that Michael used the trademark "FLOCK SAFETY" without authorization and that it could confuse customers. Doppel requested the Flock Surveillance Map be taken down, even though the site displays a pop-up on first access stating otherwise.
Public reaction to the complaint has been skeptical. Commenters on the reporting questioned whether a company that could not properly secure its own website had grounds to invoke trademark law against someone who exposed that failure. The core tension remains unresolved: the security flaw that enabled the map has been fixed, but the data it exposed about the scale and reach of Flock's surveillance network is now permanently public.