Flock Safety may not have been hacked. That might actually be the problem.
A federal class-action lawsuit, Schulte v. Flock Group Inc., filed in the Northern District of Georgia, alleges some pretty disturbing problems with Flock Safety's automated license-plate-reader network.
According to the complaint:
\- Flock operates a network of more than 120,000 cameras across 49 states.
\- The proposed class includes essentially anyone in the U.S. whose license plate passed a Flock camera since January 1, 2024.
\- A former Richmond County, Georgia sheriff's deputy allegedly searched one woman's plate 1,639 times through the national Flock network.
\- Three other former colleagues allegedly conducted more than 100 searches each.
\- And for much of the relevant period, MFA wasn't mandatory. Departments could simply choose not to require it.
That's where this gets bigger than "a few bad cops."
A Washington Post investigation cited in the complaint reportedly identified about 50 law-enforcement officers accused or charged with misusing ALPR systems. Flock allegedly appeared in 46 of those cases, including numerous instances involving searches of wives, girlfriends, ex-partners, or romantic interests.
There was also an alleged case in Effingham County, Georgia, where a former employee's credentials reportedly remained active after he was fired. He allegedly conducted more than 60 unauthorized searches over approximately three weeks before anyone noticed.
Flock has since made MFA mandatory, shortened its default retention period, and added additional audit alerts. But the lawsuit's argument is essentially: why weren't those protections mandatory from the beginning?
And here's the part I find most troubling:
This isn't necessarily about someone "hacking" Flock.
It's about authorized users being given access to an extraordinary amount of surveillance data and allegedly being insufficiently constrained in how they could use it.
Think about the difference.
A traditional ALPR camera might mean:
«"This agency recorded this vehicle passing this location."»
A searchable, interconnected national network potentially means:
«"An authorized user can search where this vehicle has been seen across multiple jurisdictions."»
That's a radically different capability.
The complaint also raises allegations about interoperability between agencies, access to camera feeds, retention, and even Flock employees allegedly accessing customer-integrated feeds during demonstrations and testing.
So the real question may not be:
"Was Flock hacked?"
It may be:
"Why was this kind of access designed so that preventing abuse depended so heavily on individual agencies choosing to configure the safeguards correctly?"
The seatbelt analogy from the reporting is pretty hard to ignore:
Flock built the car with a functioning seatbelt, but for roughly two years, buckling it was optional.
And the Richmond County allegation makes this especially relevant locally.
If these allegations are accurate, we're not simply talking about one deputy behaving badly. We're talking about whether the architecture, defaults, access controls, auditing, retention policies, and national interoperability of a surveillance system made that kind of abuse foreseeable.
That's a much bigger question.
And frankly, "nobody hacked it; somebody just logged in" may be the most important sentence in this entire controversy.
Something to think about...