Security Flaw Exposed 335,701 Flock Device Locations: Now a Firm Wants the Map Taken Down

The researcher says Flock-linked mapping data was accessible without a login; a firm acting for Flock later sought removal of the resulting map through a trademark complaint

Flock surveillance map showing US device locations
A Flock licence plate reader monitors vehicles on a US roadway as the company faces scrutiny over a public map of its surveillance infrastructure Source: Wikimedia Commons Photo by: Tony Webster

A cybersecurity researcher says an unauthenticated flaw connected to Flock Safety's website allowed him to obtain device-location data later used to build a public map that now lists 335,701 Flock-linked devices across the United States. The next day, Doppel, a cybersecurity firm that said it was acting on Flock's behalf, submitted a trademark complaint seeking the site's removal.

The dispute centres on how location data linked to Flock's surveillance infrastructure became accessible without a login, and whether the public map built from that information will remain online.

Researcher Says Unauthenticated Token Exposed Device Locations

Joshua Michael said he discovered the issue in November 2025. The Intercept reported that an access token could be obtained without logging in and used to query ArcGIS, a third-party geographic information system connected to Flock's mapping environment.

Michael said he reported the issue to Flock on 13 November 2025 and followed up twice. According to his account, Flock eventually acknowledged the findings and said they were being reviewed internally, but he received no further response.

Michael downloaded a snapshot of the device-location data in December 2025. His January technical disclosure said the token issue remained unpatched as of 7 January. The Intercept later reported that the access path appeared to have been closed after he published his findings.

That token issue is distinct from a separate hard-coded ArcGIS API-key exposure Michael also documented, which he said provided access to additional private mapping layers.

Map Lists 335,701 Flock-Linked Devices

Michael's Flock Surveillance Map currently lists 335,701 devices. That figure is not a count of 335,701 licence-plate cameras.

The site identifies 175,269 Falcon licence plate readers, along with PTZ cameras, Picard processing units, Raven acoustic sensors, trailers, networking hardware and drone-related equipment. The map is based largely on a December 2025 snapshot, so it should not be treated as a live inventory of every device currently deployed.

The reporting reviewed for this article does not establish that motorists' stored licence-plate records were retrieved through the specific unauthenticated token flaw used to build the map. The dataset described in The Intercept's report concerned device locations and related descriptions.

Flock says its licence plate readers capture still, point-in-time images rather than continuously following individual vehicles. It also says customers control access to and sharing of data collected through their systems.

Trademark Complaint Seeks Map's Removal

Michael published the map on 23 September, the same day the US Senate Judiciary Subcommittee on Crime and Counterterrorism held a hearing on Flock's nationwide licence-plate-reader network.

The next day, Michael was notified of a trademark complaint from Doppel, which said it was acting on Flock's behalf, according to The Intercept. The complaint alleged unauthorised use of the 'FLOCK SAFETY' mark, said the use could cause customer confusion or harm, and requested that the site be taken down.

Michael's site states that it is independent and not affiliated with or endorsed by Flock. No court order requiring the map's removal was identified in the reporting reviewed as of 28 September.

Flock and Researcher Disagree Over Security Claims

In a blog post first published on 6 January 2026 and updated in July, Flock said its cloud platform had never been hacked, its cloud infrastructure had never been compromised and customer data had never been accessed or exfiltrated by an attacker.

Michael argues that those statements do not fully reflect what happened because he says he had already downloaded Flock's device-location database before the post appeared.

The technical scope matters.

Michael's reported map-building access involved device-location information obtained through an ArcGIS-related access path. Flock's more detailed security claims focus on compromise of its cloud infrastructure and customer-controlled data.

The evidence reviewed here does not establish that customer licence-plate records were taken through the token flaw used to create the map.

Route Modelling Raises Questions About Sensitive Sites

Michael also used the mapped locations to model drives from residential homes to 22 sensitive US sites. The locations include the Pentagon, CIA headquarters, FBI headquarters, Joint Base Andrews and Eglin Air Force Base.

Tom's Hardware, citing Michael's modelling, reported that between 57.22% and 93.94% of the modelled routes from homes within 20 miles of the sites passed a Flock camera. Michael's methodology says the results were weighted towards occupied homes and based on fixed modelled driving routes, rather than observed movements of identified people.

There is no evidence in the reporting reviewed that anyone used Michael's database to track military, intelligence or government personnel. The exercise illustrates a hypothetical risk raised by the researcher.

On 23 September, the US Senate Judiciary Subcommittee on Crime and Counterterrorism held a hearing titled 'Always Watching: Flock's Nationwide AI Surveillance Network.' Witnesses included cybersecurity engineer Benn Jordan, Lindsey Isaacs, Pinal County Sheriff Ross Teeple, Institute for Justice legislative counsel Alasdair Whitney and ACLU senior policy counsel Chad Marlow.

The hearing examined privacy, security and oversight concerns surrounding automated licence plate readers. Michael's map adds a related question: what happens when the physical footprint of the network itself becomes publicly visible?