In late 2025, Flock Security publicly claimed a portfolio of roughly 120,000 cameras covering the United States. Months later, a cybersecurity analyst released a detailed map that pushes the estimated count to more than 300,000 devices, including cameras, acoustic detectors and third-party networking gear.
Scale of the uncovered network
The interactive Flock Surveillance Map assembled by researcher Joshua Michael, plots the locations of over 170,000 cameras and an additional 130,000 ancillary pieces of equipment. Michael’s dataset also identifies 27,000 acoustic detection units and a cluster of 860 devices stationed near Chicago O’Hare International Airport, specifically at the Rosemont Public Safety Department. Other notable points include a camera named “FBI Pilot Camera” located at the J. Edgar Hoover Building in Washington, and a sensor labeled “C-F-23 FOXTROT MALE HOLDING 2/SHOWERS” inside the Silverdale Detention Center in Chattanooga, Tennessee.
When asked about the implications, Michael told The Intercept“These cameras form a nationwide surveillance network that tracks where everyone drives.” He added that foreign adversaries could monitor American troops, agents and officials without deploying traditional spies.
How the map was built
Unlike crowdsourced projects such as DeFlock, Michael’s map does not rely on user submissions. Instead, it draws on a snapshot taken in December 2025 from a publicly accessible access token that Flock’s own servers exposed. By feeding that token into ArcGIS – the geographic-information platform Flock uses – Michael retrieved precise coordinates for every registered device.
The methodology was strictly non-intrusive. Michael’s initial email to Flock on November 13, 2025 emphasized that he only accessed “open unauthenticated endpoints” and never altered data or triggered billable operations. After two silent weeks, a brief reply arrived: “Thank you for the findings. We are internally triaging them and will reach back out with next steps soon.” No further communication followed.
In Michael published a technical blog post detailing his extraction process. Within days, the company patched the exposed endpoint, suggesting that the vulnerability was indeed addressed.
Company reaction and legal pushback
While Flock Security quietly sealed the leak, it issued a public statement in the same month proclaiming that its cloud platform “has never been hacked, and there has not been a leak of Flock information.” The claim directly contradicts the fact that Michael successfully downloaded the full device list.
An American Civil Liberties Union report has previously criticized Flock for “regularly misleading or even lying about its business practices, safety record, commitment to privacy, and efforts to protect vulnerable populations.” Michael argued that the company either concealed the breach to protect its reputation or failed to detect the data exfiltration altogether – a “transparency failure” or a “detection failure with national security implications.”
Adding complexity, a firm called Doppel, which markets itself as an “AI-native social engineering defense platform,” filed a trademark complaint in Thursday (date unspecified) alleging that Michael’s site infringed on the “FLOCK SAFETY” brand. Doppel claimed the site could cause customer confusion and requested its removal. Michael responded by placing a disclaimer on the map site stating it is “not affiliated with or endorsed by Flock.”
The map’s credibility was further bolstered by on-the-ground verification. The Intercept visited six random coordinates in Arizona listed on the map, finding a functioning Flock camera at each location.



