TL;DR
Get privacy and security gear delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
A cybersecurity researcher published a map of more than 170,000 Flock cameras and over 130,000 accompanying devices, drawn from Flock’s own database after a vulnerability exposed location data. The findings were cited at a Senate hearing, and a trademark infringement complaint has now been filed against the researcher’s site.
Flock Safety, the Atlanta-based surveillance company whose camera network was the subject of a U.S. Senate subcommittee hearing this week, is seeking to have taken offline a researcher-built map that documents roughly 300,000 of its devices across the United States, according to a complaint filed against the site. The map, published Wednesday by cybersecurity researcher Joshua Michael and reported by The Intercept, draws on location data from Flock’s own internal database and shows a national footprint far larger than the 120,000 cameras the company has publicly acknowledged.
Michael’s Flock Surveillance Map plots what he says are more than 170,000 cameras plus over 130,000 accompanying devices, including roughly 27,000 acoustic detection units and networking equipment that integrates third-party cameras. Unlike crowd-sourced efforts such as DeFlock, the map is built from a snapshot of Flock’s own records that Michael archived in December 2025, according to The Intercept. His findings were cited in Wednesday’s Senate Subcommittee on Crime and Counterterrorism hearing on Flock.
The Intercept reported that it visited six randomly selected Arizona locations from the map and found a Flock camera at each set of coordinates. The map color-codes devices by model — distinguishing Flock’s Falcon cameras from accompanying processing units called Picards — and a searchable dataset lists each device’s internal name, often a street address or identifying detail. One camera named “FBI Pilot Camera” appears at the J. Edgar Hoover Building in Washington, the FBI’s headquarters. Some 860 devices cluster near Chicago O’Hare International Airport at the Rosemont Public Safety Department, and multiple cameras appear inside detention centers, including one labeled “C-F-23 FOXTROT MALE HOLDING 2/SHOWERS” at Silverdale Detention Center in Chattanooga, Tennessee.
Michael discovered the location data in November 2025 after finding that Flock’s servers publicly exposed an access token that could be obtained without logging in, which he used to query ArcGIS, a third-party geographic platform Flock employs. He said he notified Flock three times; after the third attempt, the company replied that it was “internally triaging” the findings. Michael said he never heard back. After he published a technical blog post in January, the vulnerability appears to have been fixed. Despite the November disclosure, Flock published a blog post in January stating it had never been hacked. On Thursday, Michael was notified that Doppel, which describes itself as an “AI-native social engineering defense platform,” had filed a trademark infringement complaint against his site, claiming to be working on Flock’s behalf.
Stakes of the Device Count Dispute
The gap between Flock’s stated figure of 120,000 cameras and the map’s roughly 300,000 devices goes to the heart of ongoing scrutiny of the company’s scale and transparency. License plate readers and associated sensors record the movements of ordinary drivers, not just criminal suspects, and the map’s detail — down to individual camera names, FBI locations, and detention-center placements — makes that reach visible in a way company disclosures have not.
Michael argued the exposure has national security dimensions. “These cameras form a nationwide surveillance network that tracks where everyone drives,” he told The Intercept, “so foreign nations don’t need to send spies to harm our country. They can simply watch where our soldiers, federal agents, and politicians go.”
The takedown complaint also raises questions about how Flock responds to security research. An ACLU report previously found what it described as “a pattern of Flock regularly misleading or even lying about its business practices, safety record, commitment to privacy, and efforts to protect vulnerable populations.”
From Leaked Token to Senate Hearing
Flock has faced months of mounting criticism over its practices and transparency. This summer, amid growing concern about its network, the company told the press it operated more than 120,000 cameras nationwide.
In November 2025, Michael found Flock’s website leaked an unauthenticated access token. In his initial email to Flock dated November 13, 2025, he wrote that “all testing was strictly non-intrusive, limited to open unauthenticated endpoints, and did not involve bypassing authentication, modifying data, or invoking any billable ArcGIS or Google operations.” After two follow-ups, Flock replied: “Thank you for the findings. We are internally triaging them and will reach back out with next steps soon.” Michael says no further response came.
After Michael’s January blog post, Flock apparently fixed the vulnerability — and separately published a post stating: “Flock has never been hacked, and there has not been a leak of Flock information. Flock Safety’s cloud platform has never experienced a data breach.”
“These cameras form a nationwide surveillance network that tracks where everyone drives, so foreign nations don’t need to send spies to harm our country. They can simply watch where our soldiers, federal agents, and politicians go.”
— Joshua Michael, cybersecurity researcher, to The Intercept
Unanswered Questions on the Complaint
It is not yet clear whether the trademark infringement complaint by Doppel was filed at Flock’s direct instruction; The Intercept’s report was cut off mid-sentence on that point, noting only that Doppel claimed to be working on Flock’s behalf. Flock did not immediately respond to a request for comment from The Intercept.
The map’s full accuracy beyond the six Arizona sites independently verified by The Intercept has not been confirmed. The precise legal basis for the trademark claim — and whether it will result in the map’s removal — also remains unknown. Michael’s characterization of the exposed token as a security vulnerability is his own; Flock has maintained it has never experienced a data breach.
Watch the Hearing and the Takedown
The outcome of the Senate Subcommittee on Crime and Counterterrorism inquiry into Flock, and whether lawmakers pursue regulation of license plate reader networks, will shape the policy response. The trademark complaint against Michael’s site may proceed through takedown processes, and Michael could publicly respond or contest it. Flock may also issue a formal statement reconciling its 120,000-camera figure with the map’s device counts. Watch for further verification efforts by journalists and researchers testing the map’s coordinates in additional states.
Key Questions
How many Flock devices does the map show?
Joshua Michael’s map shows more than 170,000 cameras and over 130,000 accompanying devices — roughly 300,000 total, including about 27,000 acoustic detection units — based on a December 2025 snapshot of Flock’s own database.
How is this different from other Flock camera maps?
Crowd-sourced projects like DeFlock rely on user-submitted locations. Michael’s map is built from location data obtained from Flock’s own records via a leaked access token, and includes supplemental devices beyond license plate cameras.
How did the researcher get the data?
He found that Flock’s servers publicly exposed an access token that required no login, which could be used to query ArcGIS, a third-party geographic platform Flock uses. He says he notified Flock three times in November 2025 before archiving the data.
What does Flock say about the incident?
Flock has publicly stated that it “has never been hacked” and that “there has not been a leak of Flock information.” The company did not immediately respond to The Intercept’s request for comment on the map.
Why is there a takedown complaint against the map?
Doppel, a firm describing itself as an “AI-native social engineering defense platform,” filed a trademark infringement complaint against Michael’s site, claiming to work on Flock’s behalf. Whether Flock directly authorized the complaint is not yet clear.
Source: hn
Evergreen bestsellers Picks
bestsellers
As an affiliate, we earn on qualifying purchases.
