Flock Safety Data Exposed in Security Breach

A malicious actor mapped over 300,000 security device locations after accessing a third-party service.

Updated on Sept. 30, 2026 in Cybersecurity

Bold flat-color editorial illustration depicting a single red architectural pillar on a cream background, representing systemic security vulnerabilities.
Flock Safety has confirmed a security breach that exposed the geographic coordinates of over 300,000 surveillance devices through a third-party mapping service. AI Illustration. Upload story photo >

Live Poll

Do you trust companies to transparently notify customers immediately after discovering a potential security vulnerability?

Flock Safety has notified police departments, including those in Connecticut, that a security breach exposed the locations of more than 300,000 devices. The company confirmed that a malicious actor exfiltrated this data through a third-party map service.

Why it matters

The incident has prompted local agencies, such as the Ledyard Police Department, to reconsider their reliance on surveillance vendors. This breach underscores the security risks inherent in integrating third-party mapping services with sensitive law enforcement infrastructure.

The breach exposed 300,000 device locations, a figure significantly higher than the 120,000 active license plate reader cameras the company confirmed were in operation as of June 2026. The vulnerability stemmed from an exposed map access key.

The players

Flock Safety

A surveillance technology provider that supplies license plate recognition cameras and security software to law enforcement agencies.

Ledyard Police Department

A municipal law enforcement agency in Connecticut that has requested the termination of its contract with Flock Safety following the security incident.

The details

The compromise occurred when a malicious actor utilized an exposed map access key to exfiltrate proprietary data from a third-party mapping service. This data included device names, types, and geographic coordinates. While an individual had reported the vulnerability to Flock Safety in November 2025—which the company stated it closed in December 2025—the actor successfully published the information on a website, forcing the company to confirm the breach to its law enforcement clients.

Timeline

  1. November 2025: An individual reported the map access key vulnerability to Flock Safety.

  2. December 2025: Flock Safety stated that it eliminated the vulnerability.

  3. June 2026: Flock Safety reported having 120,000 active cameras.

  4. September 2026: Flock Safety notified police departments of the breach.

The Tech Race

This breach follows the pattern of the 2023 breach of police surveillance footage providers, highlighting the ongoing security challenges of centralizing law enforcement data. It marks a significant departure from the company's growth-focused reporting of its 120,000 camera-strong network.

Police departments across Connecticut are currently evaluating the security of their existing surveillance contracts in light of this disclosure. Residents should monitor local municipal council meetings, as departments like Ledyard work to determine if they will move to sever ties with the vendor.

The takeaway

This incident highlights the cascading risks of third-party dependencies in high-stakes public infrastructure. Interested parties should track upcoming municipal contract reviews in Ledyard to see if the city proceeds with its move to terminate the Flock Safety agreement.

Further reading

For more information on regional digital security, visit the Cybersecurity section.

Source note: This article includes information reported by Investigatetv.

Live Poll

Do you trust companies to transparently notify customers immediately after discovering a potential security vulnerability?