8 Sep 2026, Tue

A Deputy Searched One Woman’s License Plate 1,639 Times. Flock Safety’s Fix Was a Checkbox Nobody Had to Click.

cars on road during night time

A former sheriff’s deputy in Richmond County, Georgia searched one woman’s license plate through Flock Safety’s national camera network 1,639 times. Three of his former colleagues each ran more than 100 searches of their own, according to a federal class-action complaint filed August 25 in the Northern District of Georgia. None of them needed a warrant. For most of the two years covered by the lawsuit, they barely needed a password, because the single strongest safeguard on Flock’s system, multi-factor authentication, was something a police department could simply choose not to turn on.

That detail is the real story buried inside Schulte v. Flock Group Inc., and it matters more than any single deputy’s obsession. The case, filed by Georgia resident Grace Schulte, seeks to represent every person in the United States whose license plate has passed in front of one of Flock’s more than 120,000 cameras since January 1, 2024. Given that Flock’s network already covers 49 states, that isn’t a niche class of plaintiffs. That’s most of the country that owns a car.

The Number Nobody Can Explain Away

Buried in the complaint is a statistic drawn from a Washington Post investigation cited in the filing: of roughly 50 law enforcement officers nationwide charged with or accused of misusing automated license plate readers, Flock’s system was involved in 46 of those cases. In 26 of them, officers allegedly used the network to track wives, girlfriends, ex-partners, or women they had a romantic interest in pursuing. This isn’t a story about a handful of bad actors slipping through the cracks. Forty-six out of fifty isn’t a crack. It’s most of the floor.

This publication has tracked pieces of this pattern for months. A DeKalb County, Georgia sheriff’s sergeant was charged with a felony this summer after allegedly misusing the county’s Flock system, and a Milwaukee officer accused of running his girlfriend’s plate 124 times and her ex-boyfriend’s plate 55 times surfaced in a separate oversight letter. Those stories read like isolated failures of judgment. This lawsuit argues something different: that the failures were the predictable output of how Flock built its product, not the exception to it.

The Checkbox That Wasn’t

Here’s the mechanism, according to the complaint. When a former employee of the Effingham County Sheriff’s Office in Georgia wanted to keep digging through license plate histories after being fired, he reportedly didn’t need to hack anything. His login still worked. He allegedly ran more than 60 unauthorized searches over three weeks before anyone noticed. When asked how a terminated employee could still reach a system built to track the movements of millions of people, a Flock executive is quoted in reporting on the case saying multi-factor authentication was available to every customer, but optional. Departments had to choose to require it themselves.

That’s not a rounding error in a security policy. Multi-factor authentication, the requirement that a login also be confirmed with a phone, a code, or a hardware key, is baseline practice for any system holding sensitive personal data. It’s mandatory at your bank. It should have been mandatory the day Flock installed its first fixed camera on a residential utility pole. Instead, by the plaintiffs’ account, it stayed optional for most customers until this August, after the misuse it was meant to prevent had already been documented, repeatedly, in agency after agency across the country.

Flock has since made MFA mandatory for every customer, cut its default data retention window, and added new audit alerts, changes this publication detailed after Texas began pulling state funding tied to the program. The class-action complaint’s answer to that timeline is simple: the fix arrived after roughly two years of documented exposure, not before it.

When the Watcher Doesn’t Watch Itself

The complaint’s most uncomfortable allegation isn’t about a rogue officer at all. It alleges that Flock’s own employees accessed customer-integrated camera feeds pointed at sensitive locations, including a children’s gymnastics room and a Jewish community center, during an internal demonstration and testing meeting. If accurate, that detail undercuts the company’s entire pitch. Flock has built its brand on being the trusted intermediary that decides who gets to see what a camera captures. A surveillance company that can’t keep its own staff out of a children’s gym camera during a sales demo isn’t really selling security. It’s selling access, and hoping nobody asks who else has it.

A Border Nobody Voted For

The complaint also points to Illinois, where a state audit found that Flock’s system had let U.S. Customs and Border Protection access Illinois license plate data despite a state law restricting that kind of sharing. Nobody in Springfield voted to hand a federal immigration agency a window into state residents’ driving patterns. It happened anyway, because Flock’s interoperability settings let one agency’s camera feed bleed into another agency’s search results by default, across state lines and jurisdictional boundaries that were supposed to mean something.

Congress saw pieces of this coming well before the lawsuit. In November 2025, Senators Ron Wyden and Raja Krishnamoorthi asked the Federal Trade Commission to investigate Flock’s cybersecurity practices, arguing the company had built a sprawling surveillance network without the safeguards to match. That request went largely unanswered for months. The class-action complaint effectively picks up where the senators left off, translating a policy warning into a legal claim with financial teeth.

Function Creep, Right on Schedule

None of this should surprise anyone who has watched how automated license plate readers were sold in the first place. The original pitch, going back more than a decade, centered on stolen vehicle recovery and Amber Alerts: narrow, popular, hard-to-argue-with use cases. A similar private network built largely on repossession tow trucks made the same pitch and has since scanned roughly 9 billion plates with barely any judicial pushback. Once the cameras and the databases exist, expanding what they’re used for costs a company almost nothing and generates almost pure profit. Restricting that use, by contrast, costs money, slows down onboarding, and annoys the law enforcement customers footing the bill. Flock chose growth. The lawsuit argues drivers paid for that choice without ever agreeing to it.

What Every Driver Should Take From This

Flock’s own marketing has long insisted the company has never been hacked, and as far as anyone can tell, that’s accurate. That claim, though, misses the point this lawsuit raises. Nobody broke into Flock’s system to track a woman’s movements 1,639 times. Someone just logged in. The software worked exactly as it was configured to work. The configuration was the problem.

If you’ve driven past a boxy camera bolted to a utility pole anytime in the last two years, your plate is very likely sitting in a database that thousands of people, some still employed, some not, could search with nothing more than a username and a password they were never required to protect. That’s the detail worth remembering here, longer than any number in the complaint: Flock built the equivalent of a car with a functioning seatbelt, and for two years, left buckling it up entirely optional.

By Shawn Henry

Shawn Henry has been writing about cars long enough that it's less a job than a habit he can't shake. He covers a little of everything—classic machines, the newest tech, and wherever the industry happens to be heading—and he's the type who actually understands what's going on under the hood, not just how to describe it. Mostly, he just likes telling a good car story.

Join the conversation

No comments yet — be the first to share your take.

Your email address will not be published. Required fields are marked *