Flock Safety License Plate Reader Data Exposed in Security Breach
A security incident involving Flock Safety, a company operating nationwide license plate readers (LPRs), has raised concerns after a malicious actor published a website revealing the locations of over 300,000 Flock devices. The breach, disclosed in an email to Connecticut police departments, stemmed from unauthorized access to a third-party map service, though Flock asserts no images, video, or sensitive law enforcement data were compromised.
The website, flocksurveillance.org, was confirmed by investigative reporters and displays device locations, including decommissioned, planned, and active cameras, as well as other Flock products like drones and integrated surveillance tools. Flock claims the exposed data was limited to device names, locations, and types.
The breach first came to Flock’s attention in November 2025 when the individual responsible reported an exposed map access key. The company patched the vulnerability by December 2025 but did not notify customers or law enforcement at the time, citing no initial evidence of unauthorized data access. It was only after the website’s publication that Flock acknowledged the full scope of the incident and alerted clients.
Ledyard Police Chief Ken Cruetz, citing the breach as a key concern, announced plans to terminate his department’s contract with Flock. Researchers, including Ken Barone of the UConn Institute for Municipal and Regional Policy, have questioned the delay in disclosure, the lack of independent security assessments, and the transparency of Flock’s response. Barone also raised concerns about whether the exposed data publicly available device locations constitutes a prosecutable offense.
Flock stated that law enforcement is now investigating but did not specify which agency is involved. The company maintains that the vulnerability was addressed promptly, though critics argue the incident highlights broader risks in surveillance technology oversight.
Flock Safety TPRM report: https://www.rankiteo.com/company/flock-
"id": "flo1790886679",
"linkid": "flock-",
"type": "Breach",
"date": "9/2026",
"severity": "50",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'customers_affected': 'Law enforcement agencies, '
'municipalities (e.g., Ledyard '
'Police Department)',
'industry': 'Surveillance Technology',
'location': 'Nationwide (U.S.)',
'name': 'Flock Safety',
'type': 'Private Company'}],
'attack_vector': 'Unauthorized access to third-party map service (exposed '
'access key)',
'customer_advisories': 'Delayed notification to clients after public exposure '
'of the breach.',
'data_breach': {'data_exfiltration': 'Yes (published on '
'*flocksurveillance.org*)',
'number_of_records_exposed': '300,000+ devices',
'personally_identifiable_information': 'No',
'sensitivity_of_data': 'Low to moderate (no PII, images, or '
'video)',
'type_of_data_compromised': 'Device metadata (names, '
'locations, types)'},
'date_detected': '2025-11',
'date_resolved': '2025-12',
'description': 'A security incident involving Flock Safety, a company '
'operating nationwide license plate readers (LPRs), has raised '
'concerns after a malicious actor published a website '
'revealing the locations of over 300,000 Flock devices. The '
'breach stemmed from unauthorized access to a third-party map '
'service, though Flock asserts no images, video, or sensitive '
'law enforcement data were compromised. The website, '
'*flocksurveillance.org*, displays device locations, including '
'decommissioned, planned, and active cameras, as well as other '
'Flock products like drones and integrated surveillance tools.',
'impact': {'brand_reputation_impact': 'Negative publicity, loss of trust from '
'law enforcement clients',
'data_compromised': 'Device names, locations, and types of over '
'300,000 Flock devices',
'operational_impact': 'Potential risk to surveillance operations; '
'contract terminations by law enforcement '
'clients',
'systems_affected': 'Third-party map service, Flock Safety '
'surveillance devices'},
'initial_access_broker': {'entry_point': 'Exposed map access key'},
'investigation_status': 'Ongoing (law enforcement involved)',
'lessons_learned': 'Need for timely disclosure of security incidents, '
'independent security assessments, and improved '
'transparency in surveillance technology oversight.',
'post_incident_analysis': {'corrective_actions': 'Vulnerability patching, '
'delayed customer '
'notifications, ongoing law '
'enforcement investigation.',
'root_causes': 'Exposed third-party map service '
'access key, delayed incident '
'response and disclosure.'},
'recommendations': 'Conduct independent security audits, implement stricter '
'access controls for third-party services, and establish '
'clear incident disclosure policies.',
'references': [{'source': 'Investigative reporters, Flock Safety email to '
'Connecticut police departments',
'url': 'https://flocksurveillance.org'}],
'response': {'communication_strategy': 'Initial lack of disclosure; later '
'notification to clients after public '
'exposure',
'containment_measures': 'Patched vulnerability in third-party '
'map service',
'law_enforcement_notified': 'Yes (after website publication)',
'remediation_measures': 'Vulnerability patching, delayed '
'customer notifications'},
'stakeholder_advisories': 'Law enforcement agencies advised of the breach and '
'potential risks.',
'threat_actor': 'Malicious individual',
'title': 'Flock Safety License Plate Reader Data Exposed in Security Breach',
'type': 'Data Exposure',
'vulnerability_exploited': 'Exposed map access key'}