[ SYSTEM_ABUSE ]

When Oversight Fails: Contracts, Cover-ups & Stalking

> 1. Contractual Traps & The Trash Bag Problem

Analysis of Flock contracts reveals recurring issues that hold municipalities hostage once cameras are installed:

  • No Exit Clause: Cities cannot easily terminate the service before the contract expires.
  • Data Ownership: The vendor often retains rights to aggregate and anonymize data, which can then be sold.
  • "Black Box" Software: Municipalities have no control over what features (like phone scanning) are turned on remotely by the vendor.
  • Lack of Audit Logs: Internal searches (like stalking cases) often go undetected without independent oversight.

Once the pole is installed, the city is often held hostage by the technology and individual officers can exploit the system without detection.

> The "Trash Bag" Solution

When Dayton, Ohio and Evanston, Illinois officials realized they wanted to deactivate their Flock cameras, they discovered the contracts gave them no legal way to turn off the system remotely.

"In Dayton and Evanston, city officials told residents that they were not sure whether they could immediately deactivate or remove the cameras under the terms of their contracts. The trash bag, it turns out, was the only tool either city felt confident using."
- CNET News

Cities were forced to physically drape black trash bags over the lenses of active surveillance cameras - a low-tech fix to a high-tech dystopia born directly from these contractual constraints.

Read Full Report →

> 2. Immigration Surveillance Concerns

Multiple municipalities have canceled Flock contracts after discovering the data could be shared with federal immigration authorities (ICE), violating local sanctuary policies.

Despite promises of "public safety only," the centralized nature of the data made it easy for external actors to request access or for the vendor to share data under ambiguous "national security" clauses.

NPR Investigation →

> The "Side Door": Confirmed Under Oath

At the September 23, 2026 Senate hearing, Sen. Alex Padilla (D-Calif.) asked directly whether Flock shares data with Immigration and Customs Enforcement. Chad Marlow, senior policy counsel at the ACLU, responded that Flock does not provide data to ICE directly — but that any local officer with database access could run searches on federal agents' behalf, with little to nothing stopping it.

Alasdair Whitney of the Institute for Justice described the same pattern as "side door" access: federal agents ask local officers to run searches that state law would not allow federal agencies to run directly. Sen. Dick Durbin (D-Ill.) noted that Illinois has already banned this practice, prohibiting ALPR data from being used in immigration investigations.

In other words: the federal government doesn't need to knock on the front door when local police can let it in through the side.

Senate Hearing Coverage (Mashable) →
Senate Hearing Coverage (The Hill) →

> 3. Police Stalking Ex-Spouses & Romantic Interests

Perhaps the most disturbing abuse pattern involves officers using ALPR systems to track current or former partners without warrants. The Institute for Justice has now cataloged more than 200 incidents of ALPR abuse nationwide — including stalking, wrongful stops and detentions, and non-law-enforcement use — while investigating at least 18 documented cases of officers accessing ALPR databases to stalk romantic interests.

Sedgwick, Kansas: Police Chief Lee Nygaard tracked his ex-girlfriend's vehicle 164 times in 4 months
Kechi, Kansas: Lieutenant tracked estranged wife 228 times + her new partner 64 times in 2023
Wauwatosa, Wisconsin: Officer diverted public camera for personal use against "romantic interest"

> Update: Georgia, One Year, 19 Officers

Reporting presented at the September 2026 Senate hearing found at least 19 instances in a single year in Georgia alone where police officers were arrested or relieved of duty for using Flock's ALPR system for personal reasons — including tracking estranged romantic partners and conducting unauthorized surveillance of fellow officers and civilians. Victims often only discovered they were being tracked through independent public-records requests and citizen-built lookup tools.

Atlanta News First Investigation →

The lack of warrant requirements means any officer with system access can check where someone lives, works, and associates at any time. As noted by civil rights analysts: "Without the constitutional safeguard of a warrant requirement, that predictably allows officers to abuse their access to these systems."

Institute for Justice Report →

> 4. The Breach: Inside the Camera

In 2026, a hacker collective called Stegan0gram physically removed a Flock camera from a roadside pole and extracted its complete internal data - including an encryption key stored on the device itself, contradicting Flock's claims of secure on-device encryption.

> The 28 Photos Problem

A single passing vehicle generates approximately 28 images - some trigger more than 100 photos. The camera uses varying exposures to capture both license plates and the surrounding scene, then uploads everything over cellular networks.

Over just 21 days, the breached camera photographed 50,200 vehicles and produced 1.6 million images.

> People Detection Confirmed

Despite Flock's public insistence that cameras only read plates, the stolen software explicitly detects people, bicycles, vehicles, and license plates. When a person is detected, the software records their position in the frame and a confidence score.

WIRED independently tested the recovered computer vision models against test images - including a reporter's selfie - and confirmed the system readily identifies humans. In 21 days of recovered activity, 27,000+ video clips were recovered, along with 1.6+ Million photos, and several files in that set contained people (including those on motorcycles).

> The Encryption Illusion

Flock describes its cameras as protected by on-device encryption. Yet physical access allowed hackers to recover the encryption key and unlock thousands of videos and millions of images. While some sensitive storage remained inaccessible, the breach exposes a critical vulnerability: anyone with physical access to a camera pole potentially holds the keys to local surveillance data. Flock responded to Wired with only this statement:

"The unauthorized removal and tampering of a Flock camera is illegal."
- Flock Safety statement to WIRED

Whether that statement acknowledges the security flaw or deflects from it depends on whom you ask.

Read Full WIRED Investigation →

> No MFA: Law Enforcement Accounts for Sale on the Dark Web

Physical theft isn't the only way in. At the September 23, 2026 Senate hearing, cybersecurity engineer Benn Jordan testified that he probed Flock's systems in 2025 after learning the company did not require law enforcement clients to use multi-factor authentication. His investigation culminated in a worse discovery: Flock law enforcement accounts were being sold on the dark web by a Russian vendor.

Jordan had previously found dozens of Flock cameras streaming openly online. Anyone purchasing such an account could query the national plate database while impersonating police.

A camera network is only as secure as its weakest login screen.

HuffPost Hearing Coverage →

> 5. Media Investigations & CEO Apology Delay

> CBS Investigative Test

CBS News conducted their own investigation. Their license plate appeared in searches by police agencies four separate times. When contacted for comment, these agencies refused to explain why or provide documentation.

This mirrors the findings from the Have I Been Flocked? database, where ordinary citizens have documented thousands of warrantless plate reads - including reporters, journalists, and people simply going about their daily lives.

> CEO Forced Public Apology: August 2026

After mounting pressure and documented abuse cases, Flock Safety CEO Garrett Langley issued his first public apology during an interview with CBS News on August 13, 2026. The segment followed revelations from the Washington Post documenting 46 cases of officers misusing Flock data - including stalking women, tracking strangers, and one Texas officer searching for a woman who had a self-administered abortion.

"I apologize. It kills me that she went through that."
- Garrett Langley, Flock Safety CEO (CBS News)

Langley announced new safeguards including:

  • 7-day default data retention (reduced from 30 days)
  • Mandatory case numbers for every search query
  • Automated flagging of abnormal search activity with proactive user lockouts

But activists note these changes come after years of documented harm. Langley framed it as "Flock didn't create police abuse - we're the first company to shine a light on it" - deflecting responsibility while positioning the company as the solution to a crisis their own platform enabled.

Important context: Per CBS News (referenced in video linked below), these safeguards don't take effect until January 2027. Langley stated "we could have done more earlier" - admitting delayed action while the system continues operating under original terms for five additional months.

CBS News reports on CEO's apology, delayed implementation timeline, and ongoing lack of warrant requirements.

Read CBS Report →

> 6. Thirteen Days: The Wrongful Arrest of Lindsey Isaacs

On September 23, 2026, Lindsey Isaacs — a 23-year-old Florida woman — testified before the Senate Judiciary Subcommittee on Crime and Counterterrorism at the hearing "Always Watching: Flock's Nationwide AI Surveillance Network." Her story is what a misread plate looks like in human terms.

In October 2025, a crash killed three people in Florida. Investigators were searching for a black Dodge Durango, while witnesses had described a maroon vehicle. Isaacs's Durango was photographed by a Flock camera roughly two to three miles from the crash scene — and that single data point became the foundation of a vehicular homicide case against her.

"That piece of information became part of an investigation that ultimately led to my arrest on three counts of vehicular homicide and 13 days in jail for a crash I had nothing to do with."
- Lindsey Isaacs, sworn testimony before the U.S. Senate

Isaacs told the panel she was placed in solitary confinement for approximately three and a half days — including roughly 86 hours during which her cell door was never opened — before photos of her undamaged, impounded SUV and 13 days of detention finally ended the case. Prosecutors dropped all charges in May 2026. It took a wrongfully imprisoned young woman 13 days to prove a camera was wrong.

> Misreads Aren't Rare — They're a Pattern

The problem isn't one bad read. A California law enforcement department analyzed by the Institute for Justice found that most of its stolen-vehicle and felony alerts over two years were caused by misread plates. Cameras flag the wrong car; officers decide what to do with the flag.

"A technology now lets the government do something it can never do before, and that is, travel back in time and reconstruct your movements."
- Alasdair Whitney, Legislative Counsel, Institute for Justice — Senate testimony

Combine that retrospective power with error-prone reads, no warrant requirement, and officers who act on alerts without verifying plates — and the result is families stopped at gunpoint and innocent people in jail cells, all from a system nobody voted for.

Newsweek Hearing Coverage →
Mashable Hearing Coverage →

Notably, the CEOs of Flock Safety, Axon, Motorola Solutions, and Verkada were all invited to testify at the same hearing. None attended.

Flock isn't the only player. Vigilant, RedSpeed, PlateSmart, and the FBI are all bidding for nationwide real-time access to your movements.

Continue: Map the Ecosystem →