Executive Summary
In 2026, security researchers successfully reverse-engineered Flock Safety's automatic license plate reader (ALPR) cameras, exposing critical security vulnerabilities in the widely-deployed surveillance infrastructure. The analysis revealed that while most sensitive data remained encrypted, poor security architecture left encryption keys stored on unencrypted partitions, allowing researchers to access extensive surveillance logs containing over one million captured images. The investigation uncovered that the cameras' computer vision software actively detects and catalogs people, vehicles, bicycles, and even specific details like bumper stickers and patches, generating dozens of images per passing vehicle. This breach of a major surveillance technology provider highlights significant privacy and security concerns in municipal and law enforcement surveillance systems.
This incident demonstrates the growing vulnerability of IoT surveillance infrastructure as researchers and malicious actors increasingly target physical devices that municipalities and businesses rely on for security operations.
Why This Matters Now
The proliferation of AI-powered surveillance cameras in smart cities creates new attack vectors where physical device compromise can expose massive amounts of surveillance data, highlighting urgent needs for proper encryption key management and zero-trust security in IoT deployments.
Attack Path Analysis
Attackers performed physical compromise of Flock ALPR camera through device capture, exploited poor encryption key management stored on unencrypted partition to access encrypted data, analyzed extracted surveillance data including license plates and person detection logs, established communication pathways through device interfaces, exfiltrated sensitive surveillance data and configuration details, and created operational impact by exposing mass surveillance capabilities and privacy violations.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Physical capture and acquisition of Flock automatic license plate reader camera device to gain direct hardware access
MITRE ATT&CK® Techniques
Hardware Additions
Unsecured Credentials: Private Keys
Direct Volume Access
File and Directory Discovery
Data from Local System
Data from Network Shared Drive
System Information Discovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Cryptography for Primary Account Data Protection
Control ID: 3.4.1
NYDFS 23 NYCRR 500 – Encryption of Nonpublic Information
Control ID: 500.15
DORA – ICT Risk Management Framework
Control ID: Article 11
CISA ZTMM 2.0 – Data Protection and Encryption
Control ID: Data Pillar
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001 – Key Management
Control ID: A.10.1.2
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Law Enforcement
Physical device compromise of Flock cameras exposes unencrypted surveillance data, compromising automated license plate readers and person detection capabilities critical to operations.
Government Administration
Municipal surveillance infrastructure vulnerabilities reveal poor encryption practices, exposing millions of citizen images and compromising public safety monitoring systems citywide.
Public Safety
ALPR system compromise demonstrates inadequate segmentation and encrypted traffic controls, potentially enabling lateral movement through connected emergency response networks.
Transportation
Traffic monitoring camera vulnerabilities expose vehicle tracking data and compromise zero trust segmentation, affecting intelligent transportation systems and fleet management operations.
Sources
- Reverse-Engineering Flock Camerashttps://www.schneier.com/blog/archives/2026/09/reverse-engineering-flock-cameras.htmlVerified
- Flock Safety Privacy Policy and Security Informationhttps://www.flocksafety.com/privacyVerified
- EFF Report on Automatic License Plate Readershttps://www.eff.org/pages/automatic-license-plate-readers-alprVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely have constrained the attack scope by limiting device connectivity and enforcing segmented access controls. While physical compromise cannot be prevented, Zero Trust segmentation could reduce the blast radius of data exfiltration and lateral movement capabilities.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Device isolation policies could likely have limited the compromised camera's ability to communicate with broader network infrastructure and cloud management systems
Control: Zero Trust Segmentation
Mitigation: Segmentation policies could likely have constrained access scope to specific data partitions and limited privilege escalation pathways within the device ecosystem
Control: East-West Traffic Security
Mitigation: Traffic inspection and micro-segmentation could likely have reduced the attacker's ability to move freely between device partitions and access multiple data repositories
Control: Multicloud Visibility & Control
Mitigation: Centralized visibility controls could likely have detected and constrained unauthorized analysis activities and anomalous device behavior patterns during forensic examination
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies could likely have restricted the volume and scope of surveillance data exfiltration by enforcing data loss prevention controls
While the physical device compromise would still expose surveillance capabilities, segmentation controls could likely have reduced the scope of accessible surveillance data and limited broader infrastructure exposure
Impact at a Glance
Affected Business Functions
- Law Enforcement Operations
- Public Safety Monitoring
- Traffic Management
- Crime Investigation Support
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of license plate data, vehicle images, pedestrian detection data, and location tracking information from ALPR systems. Poor encryption implementation could allow unauthorized access to surveillance data collected over several weeks, including over one million captured images.
Recommended Actions
Key Takeaways & Next Steps
- • Implement encrypted traffic controls and secure key management to prevent encryption key exposure on unencrypted partitions
- • Deploy zero trust segmentation to isolate sensitive surveillance device data and limit unauthorized access to critical partitions
- • Establish multicloud visibility and control mechanisms to monitor and detect anomalous device interactions and data access patterns
- • Enforce egress security policies to prevent unauthorized exfiltration of sensitive surveillance data from compromised devices
- • Implement threat detection and anomaly response capabilities to identify suspicious device compromise attempts and unauthorized data extraction activities



