Flock is asking that a website mapping its surveillance cameras be taken down, according to a report from The Intercept. The request follows research by Joshua Michael, who used ArcGIS, a third-party mapping and geospatial layer that Flock uses, to retrieve a database of Flock devices in November 2025.

Michael said he told the company about the security flaw right away. In an email dated Nov. 13, 2025, he said all of his testing was non-intrusive, limited to open unauthenticated endpoints, and did not involve bypassing authentication, modifying data, or invoking any billable ArcGIS or Google operations. Flock did not respond to his message, and it took him two more attempts before a representative replied. The company told him it was internally triaging his findings and would reach back out with next steps soon, but the researcher said Flock has still not replied.

Flock apparently fixed the vulnerability in January after Michael published his findings, but he was able to exfiltrate a Flock device location database before that. That information allowed him to build the Flock Surveillance Map website, which lists 335,701 cameras, presumably updated in December 2025.

The surveillance company said it has never been hacked, that Flock information has never been leaked, and that the Flock Safety cloud platform has never experienced a data breach. Michael says that does not reflect reality, telling The Intercept the announcement came after he pulled the company's database of devices. He said there are two possibilities: either Flock knew and chose not to disclose it for fear of bad press, or it did not know he exfiltrated the data at all. He described the first as a transparency failure and the second as a detection failure with national security implications.

The issue raises new questions about Flock's cybersecurity and privacy measures. Hackers recently found that Flock cameras stored encryption keys directly on the device, which allowed them to extract more than 27,000 clips and find that the system had taken more than 1.6 million images in a span of 21 days. There were also multiple instances of misuse, including police officers using the system to stalk romantic partners, and a car reviewer who was ambushed in a store parking lot and detained for an hour over a mistyped police report.

Michael also pointed out that the ubiquity of the system and the vulnerabilities he uncovered could be used to track personnel. Soldiers and civilians working in the defense industry could potentially be observed going to and from 22 sensitive sites, including Eglin AFB, CIA Headquarters, FBI Headquarters, Joint Base Andrews, and the Pentagon. People living within a 20-mile radius of those sites have a 57.22% to 93.94% chance of passing a Flock camera and being recorded.

Flock did not comment on The Intercept's reporting before publication. Michael said he received a trademark infringement complaint on his site: Doppel, a cybersecurity company focusing on social engineering defense, reached out on Flock's behalf and said he is using the trademark FLOCK SAFETY without authorization, which may confuse customers. The firm requested that the Flock Surveillance Map website be taken down, despite a pop-up on the site that appears when it is first accessed saying otherwise.

More gadget news from TechManNews.