Hackers Reveal Unexpected Facts About Highway License Plate Tracking Cameras
A group of hackers has reportedly breached the surveillance cameras owned by Flock Safety installed on highways. Flock Safety is a United States-based company. The developed cameras are intended for investigating traffic crimes, such as vehicle theft, as well as tracking fugitives and missing persons.
While both systems track license plates, Flock Safety’s cameras differ from Indonesia’s Electronic Traffic Law Enforcement (ETLE) system. ETLE is used for law enforcement and issuing fines for traffic violations. Flock Safety cameras continuously record all vehicles passing on the highway, whereas the ETLE system only captures images or video when a traffic violation occurs. Furthermore, Flock Safety operates exclusively in the United States, while ETLE is operated in Indonesia by the Indonesian National Police Traffic Corps (Korlantas Polri).
Regarding the breach of Flock Safety cameras, hackers are said to have taken almost complete copies of data from the devices and shared the documents with technology media outlets 404 Media and WIRED. This breach has unveiled how Flock’s surveillance cameras track the movement of vehicles and even pedestrians in public spaces. Additionally, the hackers published the vulnerabilities and the methods used to hack the software, hoping similar actions could be replicated by others.
Breaking Camera Encryption
This breach provided unprecedented investigative access to a system that Flock claimed was protected by high-level on-device encryption. In their action, the hackers managed to copy the camera’s storage data and recover the encryption keys within the device. These keys were subsequently used to unlock thousands of recorded vehicle detection videos.
Alongside the non-profit transparency organisation Distributed Denial of Secrets, the materials were handed over to 404 Media and WIRED for in-depth analysis through a joint investigation. Although most sensitive data from the Automatic License Plate Reader (ALPR) remained encrypted, analysis detected software within the cameras explicitly capable of recognising humans, vehicles, license plates, and even bicycles, as reported by 404 Media on Thursday (17/9/2026).
A single camera unit was reported to produce dozens of images for every passing vehicle. Based on activity logs over several weeks, the device recorded generating more than one million images. The internal computer-vision system even frequently isolated bumper stickers and specific attributes, such as flag emblems on motorcyclists’ bags.
Waves of Rejection and Sabotage
Acts of destruction and the forced removal of Flock cameras indicate that segments of the public are becoming increasingly angered by massive digital surveillance. In various regions, several individuals have been arrested for sabotaging these cameras. In response to the wave of protests, several US cities have decided to completely cease the use of Flock cameras. In fact, one local police department was forced to create fake 3D-printed replicas of the cameras solely to deceive vandals.
In an interview, a hacker from the collective known as stegan0gram levelled harsh criticism against this mass surveillance technology. “Why only destroy them when we can reverse engineer and find the secrets of those spying on us?” they stated. “We liberate the hardware in the field, disable it, and proceed to reverse engineer the cameras and their supporting devices.”
National Networks and Privacy Controversies
Flock cameras photograph passing vehicles and send the data to the company’s central server. The Flock system then reads the license plates, records physical vehicle characteristics, and stores them in a timestamped database. This data is not only accessible to the local agencies owning the cameras but is also connected to a national network accessible to thousands of other agencies, ranging from police and universities to airports and federal agencies.
While offering convenience for law enforcement, this integrated network has sparked major controversy. Previous investigations revealed how local authorities used the Flock network to assist Immigration and Customs Enforcement (ICE) in regions where such cooperation is prohibited, as well as for tracking citizens undergoing private medical procedures. These findings have triggered a national debate regarding the boundaries of privacy in public spaces.
Security Vulnerabilities and Technical Findings
Based on an analysis of the Android system files within the cameras, hackers found several unencrypted storage partitions, including directories containing the security keys used to unlock video files and camera captures. Previously, in early 2025, cybersecurity researcher Jon “GainSec” Gaines disclosed similar vulnerabilities that allowed root-level access to Flock devices. However, the company downplayed the severity at the time, claiming the flaw required direct physical access and that recordings would not persist on the device for long as they were promptly uploaded to the cloud.
From scanning activity logs over a 21-day period, the cameras were recorded photographing approximately 50,200 vehicles, generating a total of 1.6 million images. On average, a single camera monitors up to 4,300 vehicles per day, depending on the traffic density at the installation site. Responding to this breach, a spokesperson for Flock emphasised that the removal and destruction of cameras…