Flock now says it got hacked mere weeks before Bishop Fox arrived
Flock promised a Bishop Fox report in September. It published a summary saying no customer data was accessed. Three days later, its lawyers said confidential customer data had been taken.
by H.C. van Pelt
10 min read
Image: Flock demand letter to Joshua Michael
security
This is a follow-up to this post about the Flock Bishop Fox report, in which I described Flock hiring Bishop Fox to “engage in complex, multistage and multilayer adversarial testing across all of Flock’s products,” in February, along with a promise of transparent updates, followed by months of silence. Flock now confirms testing is done, and has posted a summary of results on its corporate blog (archive).
The blog post is shocking for its omissions. Despite Flock’s public promise that findings would be “communicated transparently to reinforce confidence in Flock’s strong security posture,” the company does not publish them alongside the blog post. More worryingly, Flock now says it experienced a data breach weeks before Bishop Fox began testing its systems. Flock missed it. If Bishop Fox caught it, Flock’s summary does not say so.
Flock’s lawyers write in a demand letter dated September 25, 2026, that Flock determined an exposed access key was used to “unlawfully access Flock’s system, obtain confidential data, retain that data, and later publish it.” The information “includes proprietary and confidential information belonging to Flock and its customers.” Three days earlier, the blog post about Bishop Fox’s testing said:
“No customer data or systems were ever accessed by anyone outside of Flock as a result of this testing.”
“None of these findings resulted in any customer data or systems being accessed by anyone outside Flock.”
Four days after the blog post, I noted the oddly hedged language in an X post:[1]
Flock won’t publish details on 2 critical cloud security holes, but promises “no customer data or systems were ever accessed by anyone outside of Flock as a result of this testing.”
Access from the inside, or “as a result of” anything other than “this testing,” is left unsaid.
The language in the post is ambiguous, and a summary of vulnerabilities is all we get. Whether Flock wrote it knowing data had been extracted, or could have been extracted, is unclear from the blog post, and the full report is available only to customers.
What is worrying is the timing. The post says the “testing window” was “January 12, 2026 – March 27, 2026.” The demand letter says Joshua Michael used the exposed key in November 2025, and Flock’s notice to customers describes the data as “accurate as of December 2025.” Bishop Fox arrived weeks later, with access to all of Flock’s source code, and found 2 “critical” and 7 “high” vulnerabilities. Nine serious vulnerabilities do not appear in two months. Most or all of them existed while Michael had access.
Flock says none of those findings resulted in outside access. Someone had to look for past access to say that. So either:
Neither Flock nor Bishop Fox looked beyond the specific findings, and missed “proprietary and confidential information belonging to Flock and its customers” leaving through a credential exposure Flock had known about for two months; or
Flock already knew about the breach, failed to disclose it, and the September 22 blog post was deliberately misleading.
Either way, Flock’s “Security Advisories” page was last updated before the blog post and the demand letter. The company alleges in a demand letter that a data breach occurred, promised to “publish an advisory when a patch or mitigation is available,” and yet its website still says “Flock has not yet published a security advisory under this policy.”
We might give Flock some grace for not publishing the Bishop Fox findings as CVEs — after all, the company that has been collecting personal information on millions of Americans for nearly a decade only wrote “InfoSec” into its terms back in August — but Flock also hasn’t updated any of the CVEs from Jon Gaines and Benn Jordan’s research. Those were logged in late 2025. The blog post claims a Secure Boot fix for a “publicly reported vulnerability,” but the CVE records show no update, including the two rated 9.8/10.
Flock did, for once, notify its customers. Michael posted the notice:
We are writing to inform you of the following security incident: On Tuesday, Sept. 22, 2026, a malicious actor published a website with location data of customer devices, accurate as of December 2025, that included device name, location, and device type. This data was unlawfully accessed and exfiltrated from a third party map service. No LPR images, video footage, or CJIS data were exposed. The person in question originally reported an exposed map access key to Flock’s Security Team in November 2025. Flock validated the finding, eliminated the vulnerability, and closed the issue in December 2025. At the time, there was no indication of unauthorized access to data. Based on the recent publication, it is now apparent that the individual exploited the reported vulnerability in late 2025 to both unlawfully access and unlawfully retain data. Flock has notified law enforcement. We are also taking all available measures to ensure the offending website is taken down. We will provide you material updates as we have them.
Flock says it saw “no indication of unauthorized access” until the website appeared. It validated a report of an exposed key, closed the ticket, and either never checked whether anyone had used the key or checked and missed it.
There is a slight irony in Flock invoking the spectre of a “third party map service” as a way to shift its responsibility. One of my criticisms of Surveillance-as-a-Service has been that police agencies can’t adequately audit third-party system logs. Flock now implies it is less responsible for reviewing its own vendor’s logs.
Flock tells its customers the data was limited to device name, location, and device type, and that “No LPR images, video footage, or CJIS data were exposed.” That may be true of what Michael took. It does not describe what was reachable. According to Michael, an earlier default key, hardcoded in 53 public files and reaching the same camera data, also listed access to 50 private map items behind FlockOS.[2] By his reading of Flock’s code, the map behind those items includes:
Flock911 live incident locations and transcript access tokens
Officer mobile app location data (phone, smartwatch)
Axon body-worn camera locations
People searches rendered as tracked objects on the map
Saved search filters, analyst searches persisted as spatial objects
Camera registrant names, addresses, and phone numbers
Live and historical patrol car GPS positions
CAD (Computer-Aided Dispatch) event layers and patrol history
…and more.
He publicly posted the findings January 9, 2026, after Flock acknowledged his report and then went quiet.
Knowing Flock’s poor history of reporting vulnerabilities to its customers, after seeing his post, I reported the findings to the Iowa Department of Public Safety,[3] and the FBI, each responsible for overseeing intelligence data systems. I urged them to investigate the scope of the incident and any resulting data loss, and to order the vendor’s ArcGIS logs preserved. I received no response, and no action appears to have been taken.
PDF Attachment: Iowa DPS letter
Law enforcement is now involved. Flock called them on Michael; per WFSB/I-Team:
The I-Team also asked why Flock did not ask law enforcement to investigate in November. A spokesperson said, “Flock addressed the reported vulnerability as a security finding at the time. Given there was no indication of unauthorized access, a notification to law enforcement was not made until the recent publication made the unlawful activity apparent.”
They did not answer our questions about which law enforcement agency is investigating.
The notice says Flock “has notified law enforcement.” The demand letter, sent no earlier than the notice, says only that Flock “reserves the right” to do so.
According to Michael’s blog post, he told Flock about the vulnerability on November 13, 2025, and it was still unpatched on January 7, 2026. Flock says it closed the issue in December.[4] Both accounts leave the hole open for weeks after the report, long enough for data Flock itself calls “accurate as of December 2025” to leave. In February, Flock wrote, “We do not wait for third parties to surface issues.”
The resulting timeline is outrageous:
November 13, 2025: Michael discloses the vulnerability to Flock.
December 2025: Michael downloads Flock’s device locations. Flock says it closed the issue this month.
January 6, 2026: Flock publishes a blog post saying, “Flock has never been hacked, and there has not been a leak of Flock information.”
January 9, 2026: Michael publishes his findings. He says he received no substantive response and that the hole was still open two days earlier.
January 9, 2026: I ask DPS and FBI to act.
January 12, 2026: Bishop Fox begins its testing.
… crickets …
September 22, 2026: Flock publishes blog post about Bishop Fox’s findings; says everything is fine.
September 24, 2026: Doppel sends a trademark notice to Joshua Michael.
September 24,[6] 2026: Flock notifies customers of a breach, denying sensitive data was exposed, and saying unspecified “law enforcement” has been notified.
September 25, 2026: Flock sends a demand letter, accusing Michael of unlawfully obtaining and publishing confidential Flock and customer information, and saying it “reserves the right” to notify police.
Flock did not notice any data had been taken. It hired Bishop Fox. If Bishop Fox noticed, Flock’s summary does not say so. Flock tells its customers nothing sensitive was exposed, while its lawyers tell Michael he took “proprietary and confidential information belonging to Flock and its customers.”
There are no advisories on Flock’s security advisories page. There are no new CVEs. There are no updates to old CVEs. There are blog posts and emails saying everything is fine, and demand letters and police referrals saying it is not.
Flock wants all of this to “reinforce confidence in Flock’s strong security posture.”
Of course, it could also be because if Bishop Fox had gained unescorted access to CJI, it would have violated CJIS rules and triggered reporting obligations. ↩︎
Michael says he did not open those items and cannot confirm their contents. His comparison table lists the token he reported in November as reaching camera locations, with no access to the private items. ↩︎
I mistakenly wrote “2025” instead of “2026” a couple of times in the letter. ↩︎
Flock says December 2025. Michael says the hole was open on January 7, 2026. The Intercept reports the fix appears to follow his January post. If you know the exact date, let me know. ↩︎
Flock’s notice dates the website to Tuesday, September 22. Michael and The Intercept date it to Wednesday, September 23. ↩︎
The notification date is uncertain, but Michael cites it on September 25, indicating it went out on or before that date. ↩︎