TL;DR
Get privacy and security gear delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
A cybersecurity researcher published a map of roughly 300,000 Flock surveillance devices using location data from Flock’s own database, which was exposed by an unauthenticated token. Days after the map was cited in a Senate hearing, a company filed a trademark infringement complaint seeking to take the site down. Flock has said it has never experienced a data breach.
A cybersecurity researcher who mapped roughly 300,000 Flock surveillance devices across the United States using location data from the company’s own database says his site is now the target of a trademark infringement complaint filed days after the map was cited in a Senate subcommittee hearing. The complaint, brought by Doppel, a company describing itself as an “AI-native social engineering defense platform,” claims to be working on Flock’s behalf, according to the researcher, Joshua Michael.
The map, published the week of September 24, 2026 and first reported by The Intercept, plots more than 170,000 cameras and over 130,000 accompanying devices, including roughly 27,000 acoustic detection devices and networking equipment that integrates third-party cameras. Unlike crowd-sourced efforts such as DeFlock, Michael’s map is built from a snapshot of Flock’s own records that he archived in December 2025.
Michael found in November 2025 that Flock’s website publicly leaked an access token that required no login. With it, he said, he could query ArcGIS, the third-party geographic information platform Flock uses, to retrieve device locations. He says he contacted Flock three times starting November 13, 2025, writing that his testing was “strictly non-intrusive, limited to open unauthenticated endpoints.” Flock replied once, saying it was “internally triaging” the findings, but Michael said he never heard back. The vulnerability appears to have been fixed after he published a technical blog post in January 2026.
The map’s dataset lists each device’s internal name from Flock’s database, often including street addresses. Examples include a camera named “FBI Pilot Camera” at the J. Edgar Hoover Building in Washington, roughly 860 devices concentrated at the Rosemont Public Safety Department near Chicago O’Hare International Airport, and cameras inside detention centers such as Silverdale in Chattanooga, Tennessee. The Intercept said it visited six random Arizona locations on the map and found a Flock camera at each. Flock did not immediately respond to a request for comment from The Intercept.
Why the Takedown Attempt Matters
The complaint arrives at a moment of intensified scrutiny of Flock. The map was cited in a Senate Subcommittee on Crime and Counterterrorism hearing on the company, and an ACLU report has accused Flock of “a pattern of regularly misleading or even lying about its business practices, safety record, commitment to privacy, and efforts to protect vulnerable populations.” The scale documented on the map — roughly 300,000 devices — far exceeds the more than 120,000 cameras Flock told reporters it operates this summer.
The episode also puts pressure on Flock’s public statements about security. In a January blog post, after Michael says he had already pulled the device database, Flock stated: “Flock has never been hacked, and there has not been a leak of Flock information.” Michael argues that claim leaves two possibilities: “Either they knew and chose not to disclose it for fear of bad press, or they didn’t know I exfiltrated the data at all. The first is a transparency failure. The second is a detection failure with national security implications.”
How the Map Was Built
Michael discovered the exposed token in November 2025 while examining Flock’s website. Because Flock’s servers disclosed the token without authentication, he could retrieve device location records from ArcGIS without logging in. He says he notified Flock on November 13, 2025, followed up twice more, and received a single acknowledgment before the correspondence went quiet. He downloaded the device data in December 2025 and published a technical write-up in January 2026, after which the vulnerability appears to have been patched.
The resulting map color-codes devices by model — such as the Falcon camera and the Picard processing unit — and goes beyond existing license plate reader maps by including supplemental hardware, illustrating clusters around airports, police departments, and detention facilities. “These cameras form a nationwide surveillance network that tracks where everyone drives,” Michael told The Intercept, “so foreign nations don’t need to send spies to harm our country. They can simply watch where our soldiers, federal agents, and politicians go.”
“These cameras form a nationwide surveillance network that tracks where everyone drives, so foreign nations don’t need to send spies to harm our country. They can simply watch where our soldiers, federal agents, and politicians go.”
— Joshua Michael, speaking to The Intercept
Unverified Claims Around the Complaint
Several elements remain unclear. Doppel’s trademark complaint claims to be working on Flock’s behalf, but Flock’s role in initiating or authorizing the complaint has not been independently confirmed, and Flock has not publicly commented on it. The precise legal basis of the trademark claim, and whether it targets the site’s name, branding, or content, is not detailed in the available reporting. The Intercept’s six-location verification in Arizona supports the map’s accuracy in that sample, but the full dataset has not been independently audited. It is also not confirmed whether Flock was aware, before its January 2026 blog post, that Michael had downloaded the device data.
Legal and Legislative Pressure Ahead
The immediate question is whether the hosting provider or registrar for Michael’s site will act on Doppel’s complaint, and whether Michael will contest it. Flock may face follow-up questions from the Senate subcommittee that cited the map, and the company’s public assertions about never experiencing a data breach are likely to be reexamined in light of the documented token exposure. Broader legislative attention to automated license plate readers and police surveillance networks — already the subject of the ACLU’s criticism — could accelerate as the map’s findings circulate.
Key Questions
What is the Flock Surveillance Map?
A map published by researcher Joshua Michael showing roughly 300,000 Flock surveillance devices across the U.S., built from a December 2025 snapshot of Flock’s own location database rather than crowd-sourced submissions.
How did the researcher get Flock’s device locations?
According to Michael, Flock’s website leaked an access token without requiring login, which could be used to query the ArcGIS platform Flock uses and retrieve device coordinates. He says he notified Flock three times, and the vulnerability appears to have been fixed after his January 2026 blog post.
What is the trademark complaint about?
Doppel, a company describing itself as an AI-native social engineering defense platform, filed a trademark infringement complaint against Michael’s site, claiming to work on Flock’s behalf. Flock’s exact role in the complaint is not independently confirmed.
Has Flock responded to the findings?
Flock did not immediately respond to The Intercept’s request for comment. The company has publicly stated it has never been hacked and has not had a leak of Flock information — a claim Michael disputes given that he downloaded the device database.
Why did the map come up in Congress?
The map and its findings were cited in a September 2026 Senate Subcommittee on Crime and Counterterrorism hearing examining Flock, part of growing scrutiny of the company’s surveillance network and transparency record.
Source: hn
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
