Hackers from a collective known as stegan0gram physically removed a Flock Safety automatic license plate reader camera from a roadway pole, copied nearly all of its stored data, and provided the files to 404 Media and WIRED for analysis.

The reporting, published Wednesday, detailed how the device's software detects not only vehicles and license plates but also people and bicycles. Recovered logs from roughly 21 days of operation showed the camera photographed about 50,200 vehicles and generated approximately 1.6 million images.

The hackers located an encryption key in an unencrypted partition labeled “media,” which unlocked videos and still images of vehicle detections. Much of the most sensitive storage remained encrypted and inaccessible. The camera runs on an Android-based system with a processor comparable to those in mid-range smartphones and includes about 20 Flock-built applications for tasks such as motion detection, image classification, and data uploads.

Analysis indicated that the camera itself does not read license plates or identify vehicle details like make, model, or color. Those functions occur on Flock's servers after the device transmits photos over cellular networks. When an object moves into view, the camera captures a rapid series of photos using different exposures, then selects and crops useful frames.

A typical vehicle generated about 28 images, though some produced more than 100. The software also isolated other elements, such as bumper stickers or graphics, in one instance cropping an American flag patch on a motorcyclist's saddlebag as if it were a plate.

The code explicitly logs detections of people, recording their position in the image and a confidence score. No evidence of active facial recognition appeared in the recovered software beyond default Android features.

Flock Safety stated that the unauthorized removal and tampering of its cameras is illegal. The incident highlights vulnerabilities in physical surveillance devices deployed for law enforcement purposes across numerous jurisdictions.

The data was also shared with the transparency nonprofit Distributed Denial of Secrets.