← Back to Tech & Science

Hackers Physically Compromise Flock Camera, Expose Millions of Images and Videos

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

A hacker collective known as stegan0gram has physically compromised a Flock roadside surveillance camera, extracting an encryption key and releasing 1.6 million images and 27,000 video clips captured over a 21-day period. The breach, which occurred on September 18, 2026, marks a significant escalation in attacks against connected infrastructure, moving beyond remote digital exploits to direct physical tampering with security hardware.

The intruders accessed the device at an unspecified roadside location, bypassing standard cybersecurity protocols by interacting directly with the hardware. Once inside the system, the group recovered the encryption key required to unlock the stored data. Within hours of securing the key, stegan0gram made the massive trove of visual data available online. The footage spans three weeks of continuous monitoring, capturing traffic patterns and public activity at the site.

Flock, a provider of automated roadside cameras designed for traffic monitoring and safety analysis, has not yet issued a public statement regarding the specific incident or the location of the compromised unit. The company's systems typically rely on end-to-end encryption to protect data stored on devices before transmission to cloud servers. However, this incident demonstrates that physical access to the hardware can render digital safeguards ineffective if attackers are able to extract cryptographic keys directly from the device.

The motive behind the attack remains unclear. stegan0gram has not provided a statement explaining why they targeted this specific camera or what they intend to do with the exposed footage. The collective, known for various cyber operations, has historically focused on exposing vulnerabilities in digital systems, but this operation highlights the risks associated with the physical security of Internet of Things (IoT) devices deployed in public spaces.

Security experts warn that the exposure of such a large volume of unredacted video and imagery could have significant privacy implications for individuals captured in the footage. The data includes high-resolution images and extended video clips, potentially identifying drivers, pedestrians, and license plates over the 21-day window. Law enforcement agencies have not confirmed if they are investigating the incident as a criminal act or monitoring the situation.

As of now, it is unknown how many other Flock devices may be vulnerable to similar physical attacks or if the encryption key recovered from this unit could compromise data stored on other cameras in the network. The group has not indicated whether further data will be released or if the attack was a one-time operation. Questions remain regarding the extent of the breach, the identity of the individuals appearing in the footage, and the steps Flock is taking to secure its remaining deployed units against physical intrusion.

Discussion

0 / 2000