AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Prime Big Deal Days · Oct 6–7Offer from Amazon

Get privacy and security gear delivered free — and shop member deals

  • Fast, free delivery on millions of items
  • Access to Prime Big Deal Days deals on October 6–7
  • Prime Video, Amazon Music and more included
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

A cybersecurity researcher published a map of roughly 300,000 Flock surveillance devices using location data from Flock’s own database, which was exposed by an unauthenticated token. Days after the map was cited in a Senate hearing, a company filed a trademark infringement complaint seeking to take the site down. Flock has said it has never experienced a data breach.

A cybersecurity researcher who mapped roughly 300,000 Flock surveillance devices across the United States using location data from the company’s own database says his site is now the target of a trademark infringement complaint filed days after the map was cited in a Senate subcommittee hearing. The complaint, brought by Doppel, a company describing itself as an “AI-native social engineering defense platform,” claims to be working on Flock’s behalf, according to the researcher, Joshua Michael.

The map, published the week of September 24, 2026 and first reported by The Intercept, plots more than 170,000 cameras and over 130,000 accompanying devices, including roughly 27,000 acoustic detection devices and networking equipment that integrates third-party cameras. Unlike crowd-sourced efforts such as DeFlock, Michael’s map is built from a snapshot of Flock’s own records that he archived in December 2025.

Michael found in November 2025 that Flock’s website publicly leaked an access token that required no login. With it, he said, he could query ArcGIS, the third-party geographic information platform Flock uses, to retrieve device locations. He says he contacted Flock three times starting November 13, 2025, writing that his testing was “strictly non-intrusive, limited to open unauthenticated endpoints.” Flock replied once, saying it was “internally triaging” the findings, but Michael said he never heard back. The vulnerability appears to have been fixed after he published a technical blog post in January 2026.

The map’s dataset lists each device’s internal name from Flock’s database, often including street addresses. Examples include a camera named “FBI Pilot Camera” at the J. Edgar Hoover Building in Washington, roughly 860 devices concentrated at the Rosemont Public Safety Department near Chicago O’Hare International Airport, and cameras inside detention centers such as Silverdale in Chattanooga, Tennessee. The Intercept said it visited six random Arizona locations on the map and found a Flock camera at each. Flock did not immediately respond to a request for comment from The Intercept.

At a glance
reportWhen: developing — complaint filed late Septe…
The developmentA trademark infringement complaint was filed against the researcher’s Flock Surveillance Map site, shortly after the map — showing roughly 300,000 devices — was cited in a Senate subcommittee hearing.

Why the Takedown Attempt Matters

The complaint arrives at a moment of intensified scrutiny of Flock. The map was cited in a Senate Subcommittee on Crime and Counterterrorism hearing on the company, and an ACLU report has accused Flock of “a pattern of regularly misleading or even lying about its business practices, safety record, commitment to privacy, and efforts to protect vulnerable populations.” The scale documented on the map — roughly 300,000 devices — far exceeds the more than 120,000 cameras Flock told reporters it operates this summer.

The episode also puts pressure on Flock’s public statements about security. In a January blog post, after Michael says he had already pulled the device database, Flock stated: “Flock has never been hacked, and there has not been a leak of Flock information.” Michael argues that claim leaves two possibilities: “Either they knew and chose not to disclose it for fear of bad press, or they didn’t know I exfiltrated the data at all. The first is a transparency failure. The second is a detection failure with national security implications.”

How the Map Was Built

Michael discovered the exposed token in November 2025 while examining Flock’s website. Because Flock’s servers disclosed the token without authentication, he could retrieve device location records from ArcGIS without logging in. He says he notified Flock on November 13, 2025, followed up twice more, and received a single acknowledgment before the correspondence went quiet. He downloaded the device data in December 2025 and published a technical write-up in January 2026, after which the vulnerability appears to have been patched.

The resulting map color-codes devices by model — such as the Falcon camera and the Picard processing unit — and goes beyond existing license plate reader maps by including supplemental hardware, illustrating clusters around airports, police departments, and detention facilities. “These cameras form a nationwide surveillance network that tracks where everyone drives,” Michael told The Intercept, “so foreign nations don’t need to send spies to harm our country. They can simply watch where our soldiers, federal agents, and politicians go.”

“These cameras form a nationwide surveillance network that tracks where everyone drives, so foreign nations don’t need to send spies to harm our country. They can simply watch where our soldiers, federal agents, and politicians go.”

— Joshua Michael, speaking to The Intercept

Unverified Claims Around the Complaint

Several elements remain unclear. Doppel’s trademark complaint claims to be working on Flock’s behalf, but Flock’s role in initiating or authorizing the complaint has not been independently confirmed, and Flock has not publicly commented on it. The precise legal basis of the trademark claim, and whether it targets the site’s name, branding, or content, is not detailed in the available reporting. The Intercept’s six-location verification in Arizona supports the map’s accuracy in that sample, but the full dataset has not been independently audited. It is also not confirmed whether Flock was aware, before its January 2026 blog post, that Michael had downloaded the device data.

Legal and Legislative Pressure Ahead

The immediate question is whether the hosting provider or registrar for Michael’s site will act on Doppel’s complaint, and whether Michael will contest it. Flock may face follow-up questions from the Senate subcommittee that cited the map, and the company’s public assertions about never experiencing a data breach are likely to be reexamined in light of the documented token exposure. Broader legislative attention to automated license plate readers and police surveillance networks — already the subject of the ACLU’s criticism — could accelerate as the map’s findings circulate.

Key Questions

What is the Flock Surveillance Map?

A map published by researcher Joshua Michael showing roughly 300,000 Flock surveillance devices across the U.S., built from a December 2025 snapshot of Flock’s own location database rather than crowd-sourced submissions.

How did the researcher get Flock’s device locations?

According to Michael, Flock’s website leaked an access token without requiring login, which could be used to query the ArcGIS platform Flock uses and retrieve device coordinates. He says he notified Flock three times, and the vulnerability appears to have been fixed after his January 2026 blog post.

What is the trademark complaint about?

Doppel, a company describing itself as an AI-native social engineering defense platform, filed a trademark infringement complaint against Michael’s site, claiming to work on Flock’s behalf. Flock’s exact role in the complaint is not independently confirmed.

Has Flock responded to the findings?

Flock did not immediately respond to The Intercept’s request for comment. The company has publicly stated it has never been hacked and has not had a leak of Flock information — a claim Michael disputes given that he downloaded the device database.

Why did the map come up in Congress?

The map and its findings were cited in a September 2026 Senate Subcommittee on Crime and Counterterrorism hearing examining Flock, part of growing scrutiny of the company’s surveillance network and transparency record.

Source: hn

FALL

Fall Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

How Trail Of Bits Helps Verify The Integrity Of Signal Chats

Trail of Bits helps enhance the security verification process for Signal chats, raising questions about messaging integrity and security measures.

CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability Actively Exploited (CISA KEV)

A critical vulnerability in JFrog Artifactory allows unauthenticated attackers to gain admin access. Exploited in the wild, it raises urgent security concerns.

Understanding Emotional Stability Through the 16PF Lens

The 16PF reveals how emotional stability shapes your resilience; uncovering these insights can transform your approach to managing stress and emotions effectively.

Why the 16PF Still Has a Place in Modern Personality Assessment

Growing in relevance, the 16PF’s adaptability and technological advancements ensure it remains a vital tool in modern personality assessment, but there’s more to uncover.