335,000 Spy Cameras Exposed—Now They Want the Map Deleted

ideko

So there are 335,000 license plate cameras scattered across America, and until a few weeks ago, you could pull up a map showing exactly where every single one of them is. Past tense, because the company that runs them – Flock Safety – is now scrambling to get that map taken down. And here’s the kicker: the only reason we know about this is because their system had a security hole you could drive a truck through.

The Vulnerability Nobody Was Supposed to Find

Here’s what happened. A security researcher was poking around Flock Safety’s systems and found something pretty damning – you didn’t need to authenticate to access their API. No password, no login, nothing. Just ask nicely and the system would hand over the precise GPS coordinates of 335,701 cameras nationwide.

335,000 Spy Cameras Exposed—Now They Want the Map Deleted

Think about that for a second. This is a company that’s sold itself to police departments and neighborhoods across the country on the promise of making communities safer through surveillance. Their whole pitch is “trust us with watching your streets.” And they couldn’t be bothered to put a basic password on the database that shows where all their cameras are located.

The Map That Flock Really, Really Doesn’t Want You to See

The researcher did what researchers do – they built an interactive map. You could zoom in on your city, your neighborhood, maybe your street, and see exactly where Flock’s automated license plate readers are watching. It went live, people started sharing it, and suddenly everyone could see just how extensive this surveillance network actually is.

Now Flock wants it gone. They’re threatening legal action, claiming the map violates the Computer Fraud and Abuse Act. Which is… well, it’s rich, isn’t it? You leave your data completely exposed, someone points out that you left your data completely exposed, and your response is to threaten them with federal hacking charges.

Why Does Any of This Matter?

Look, I’m not some privacy absolutist who thinks all cameras are evil. But there’s something deeply unsettling about the fact that this surveillance infrastructure has been built out so extensively, so quietly, and most people have no idea it even exists until someone accidentally exposes the whole network.

335,000 Spy Cameras Exposed—Now They Want the Map Deleted

These aren’t just security cameras. Flock’s system captures every license plate that drives by, logs the time and location, and stores that data for 30 days (or longer, depending on what the customer pays for). It can flag plates on hot lists, track patterns of movement, build out a pretty detailed picture of where people go and when. And apparently there are 335,000 of these things out there.

“The vulnerability exposed not just camera locations, but the entire scope of a surveillance network most Americans didn’t know existed.”

The Streisand Effect in Real Time

What’s interesting here – and by interesting I mean predictable – is that Flock’s aggressive response to get the map taken down has probably done more to spread awareness of it than if they’d just quietly fixed the vulnerability and moved on. Screenshots are circulating. People archived the data. The map might be gone from its original location, but the information? That’s out there now.

And honestly, maybe it should be. If a company is operating hundreds of thousands of surveillance cameras in public spaces, shouldn’t the public have some right to know where those cameras are? Flock would probably argue no – that exposing camera locations makes them vulnerable to tampering or helps criminals avoid detection. But I’d argue that secret surveillance is fundamentally at odds with how democracy is supposed to work.

The thing is, we’ve been having this conversation backwards. We keep talking about whether individuals have a right to privacy in public spaces, whether Ring doorbells are creepy, whether your phone tracking your location is an acceptable trade-off for convenience. Meanwhile, companies like Flock have been building out a massive, interconnected surveillance infrastructure that can track vehicles across entire metro areas, and we’re only finding out about it because someone found an unsecured API.

What This Actually Means

This isn’t really about one vulnerable database or one map. It’s about the fact that surveillance technology has gotten so cheap, so easy to deploy, and so normalized that a private company can put up a third of a million cameras and most people don’t even notice. And when the scope of that surveillance is finally revealed – through a security flaw, not through transparency – the company’s first instinct is to hide it again.

I’ve been covering tech for 15 years now, and this pattern just keeps repeating. Build first, ask permission never, fight like hell to avoid accountability when someone shines a light on what you’ve actually built. Flock isn’t unique here. They’re just the latest example.

The vulnerability is apparently patched now. The map is in legal limbo. And I’m willing to bet most of those 335,000 cameras are still up and running, still logging plates, still feeding data into systems that most people don’t understand and never consented to. We just won’t be able to see where they are anymore.

Which, if you think about it, is exactly how Flock wants it.

Share:

Emily Carter

Emily Carter is a seasoned tech journalist who writes about innovation, startups, and the future of digital transformation. With a background in computer science and a passion for storytelling, Emily makes complex tech topics accessible to everyday readers while keeping an eye on what’s next in AI, cybersecurity, and consumer tech.

Related Posts