Truth NWA
Misuse · Breaches

Cameras left open.

Security research and reporting on exposed feeds and administrative access.

← All documented cases

19 cities across 15 states January 2026

Security researcher found 67 exposed Flock camera feeds and debug interfaces across 15 states

Researcher "GainSec," with input from Benn Jordan and 404 Media's Jason Koebler, found 67 unauthenticated Flock PTZ and LPR feeds and debug web interfaces exposed on Verizon Business infrastructure. Exposed data included device serial numbers and camera IDs, RTSP digest credentials and session IDs, Auth0 tokens, FRP tunnel session identifiers, video file paths, cleartext passwords on some units, and system logs. The root cause was described as devices on cellular connections lacking carrier-grade NAT and ISP-level firewalling, combined with services binding to all interfaces.

The other side The researcher reported the findings before publishing, and says all 67 were no longer exposed by the final check.

Source · GainSec · read it

Multiple U.S. locations December 2025

Roughly 60 cameras found livestreaming to the open internet, including over a playground

A technologist working with reporters found at least 60 cameras reachable online with no encryption, username or password. Live feeds and 30 days of archived footage were accessible, along with administrative functions including camera settings, diagnostics, logs and video deletion. Locations included parking lots, stoplights, bike paths and a children's playground.

None of the data or video footage was encrypted. There was no username or password required.

— Benn Jordan

The other side Flock called it "a limited misconfiguration on a very small number of devices" that had "since been remedied."

Source · Straight Arrow News, December 22, 2025 · read it

Letter to FTC Chair Andrew N. Ferguson November 2025

Wyden and Krishnamoorthi ask FTC to investigate Flock's cybersecurity

The letter states Flock does not require multi-factor authentication for law enforcement accounts and does not natively support phishing-resistant MFA, relying on weaker methods such as SMS codes. It states at least 35 Flock customer account passwords were stolen and offered on cybercrime forums, and that password sharing among officers went undetected.

Flock does not require it, which the company confirmed to Congress in October.

— The letter to the Federal Trade Commission

The other side These are the senators' allegations. No FTC finding has been announced.

Source · U.S. Senate (Wyden) · read it

Company-wide May 2025

Flock built a people-search tool ("Nova") sourced in part from data breaches, then reversed course

404 Media obtained internal slides, Slack messages, and meeting audio showing Flock was building Nova, a tool linking plate reads to personal data drawn from people-search tools, data brokers, and data breaches, supporting 20 toggleable data sources. Internal Slack messages show employees raising ethics objections. Two weeks later Flock announced Nova would not use breached or stolen data.

I was pretty horrified to hear we use stolen data in our system.

— Employee Slack message

The other side Two weeks after the reporting, Flock announced Nova would not use breached or stolen data.

Source · 404 Media · read it