Flock seeks takedown of a 335,701-device map built from its location data
Researcher Joshua Michael says an unauthenticated token exposed Flock's device inventory; his disclosure dates to November 2025, and the map appeared during a Senate hearing on September 23rd.
By RuntimeWire Staff · Published
Primary source: Tom's Hardware
Why it matters
Flock's system depends on a wide physical footprint. A map of that footprint makes the network's scale legible, while the dispute leaves a sharper operational question: how did an unauthenticated access path expose device locations, and what did Flock know about it?

Flock Safety is seeking to take down a public map of 335,701 devices after cybersecurity researcher Joshua Michael used location data he says he retrieved from Flock's mapping infrastructure. The request came through Doppel, which filed a trademark complaint on Flock's behalf on September 24th, according to Tom's Hardware. The map carries a disclaimer saying it is not affiliated with or endorsed by Flock.
For Garrett Langley, Flock's founder and CEO, Flock began with a neighborhood crime problem. After break-ins in his Atlanta neighborhood, he concluded that police lacked useful evidence and that conventional security cameras were too expensive to provide it. Flock grew from that pitch into a nationwide system of cameras and related equipment used by law enforcement, businesses and communities. The dispute over Michael's map puts a second question beside the original one: how securely can that distributed network's own footprint be managed?
What the map counts
Michael's Flock Surveillance Map lists 335,701 devices, including more than 170,000 cameras and more than 130,000 related devices, according to reporting by The Intercept. The inventory includes acoustic detectors and networking equipment used to connect third-party cameras. It is a device count, not a count of 335,701 license-plate cameras. The map says its data is a December 2025 snapshot.
That distinction changes what the number means. Flock has said it operates more than 120,000 cameras nationwide; Michael's larger tally includes different device types and therefore does not directly contradict Flock's camera count. The Intercept reported that it checked six randomly selected locations in Arizona and found Flock cameras at each. The map also identifies equipment by model and, in some cases, by labels that point to sensitive locations.
The location data came, Michael says, from an access token exposed through a Flock website without a login. He used it to query ArcGIS, a third-party mapping service Flock uses. In an email dated November 13th, 2025, he described his tests as limited to unauthenticated endpoints and said he had not bypassed authentication or changed data. He says he contacted Flock about the flaw, received an acknowledgment that the findings were being triaged, then heard no further response. Flock apparently fixed the vulnerability in January 2026, after Michael published his technical findings, according to his account.
The disclosure and the public map are separate events. Michael says he retrieved the device-location database in December 2025; he published the map on September 23rd, 2026, the day a Senate Judiciary subcommittee held a hearing on Flock's surveillance network. Flock's CEO had been invited to testify but did not appear, according to Roll Call's report on the hearing. The map added a concrete inventory to a debate that had largely focused on how agencies use the cameras and share their records.
A disagreement over what counts as a breach
Flock's security statement says its cloud platform has never experienced a data breach and that no customer data has been compromised. Michael disputes Flock's framing, telling The Intercept that Flock made that claim after he had retrieved the device database. The available accounts do not establish whether the access amounted to a breach under a particular legal definition, and the location inventory is not the same dataset as customer-submitted license-plate records. The technical question remains specific: what data the token exposed, what Flock knew about the access, and when it detected and closed the path.
Flock's trademark complaint does not resolve those questions. Doppel says the map uses the "FLOCK SAFETY" mark without authorization and could confuse customers; Michael's site says it is independent. Flock's prior dispute with the DeFlock project followed a similar route: in January 2025, Flock's lawyers demanded changes to the project's name and use of its marks, arguing they implied a false association. The Electronic Frontier Foundation represented the mapmaker in responding to that letter. That earlier exchange concerned a crowdsourced map; Michael's map relies on a snapshot of Flock's own device-location records, a materially different source of data.
The map brings the infrastructure question into view: device locations can reveal where the network is deployed, including around sensitive sites. Michael says the distribution could make it possible to observe people traveling to and from such locations. That is a risk assessment, not evidence that anyone used his map to track specific personnel.
Langley built Flock around the belief that better evidence could help communities solve crime. The network's scale has made that system useful to customers and made its deployment patterns consequential. Flock's security claim, Michael's account of a token that exposed its device inventory, and Flock's trademark complaint now sit alongside each other. A takedown request can challenge how a map uses a brand; it cannot, by itself, settle what the access token exposed or whether Flock's response was timely.