Flock Safety’s website says “there has not been a leak of Flock information.” Joshua Michael has 335,701 Flock device records on a public map, and now someone acting for Flock wants it gone. Not over the data. Over the name.
Joshua Michael, a cybersecurity researcher, runs a website called the Flock Surveillance Map, which plots 335,701 device records belonging to Flock Safety, the Atlanta-based company whose license plate cameras watch roads across the country. Last week, The Intercept reported, Michael was notified that a brand-protection company called Doppel had filed a trademark infringement complaint against the site, saying it was acting for Flock. The complaint said the map used the “FLOCK SAFETY” mark without authorization and “may cause customer confusion / harm,” and it asked for the site to come down. When we checked on Monday, Sept. 28, the map was still online.
Every one of those records came out of Flock’s own systems. How they got out, and what Flock said afterward, matters more to drivers than the trademark fight does, because this Flock camera map is the most complete public answer anyone has produced to a question police departments and Flock rarely answer themselves: where are the cameras that log your car?
Mapping credentials handed out before anyone logged in
Michael laid out the timeline in a disclosure paper dated Sept. 2, 2026. He writes that two Flock web services, which he identifies as Planner and Beefeater, issued working credentials for the company’s ArcGIS and Google mapping accounts before a user ever logged in. He reported that to Flock on Nov. 13, 2025, and followed up on Nov. 14 and Nov. 19. After the second follow-up, according to the paper, Flock replied that the findings were being triaged internally and that next steps would follow. He says nothing further came.
On Dec. 14, 2025, Michael used that same reported flaw to pull what he describes as a production export of 335,701 device and deployment records. The paper is candid about one thing that cuts against him: “I did not separately tell Flock that I had acquired the dataset.” Flock closed the hole after Michael published a technical write-up in January, according to The Intercept.
Twenty-three days after that export, on Jan. 6, 2026, Flock published a post on its own site titled “Has Flock Been Hacked? No, Here’s Flock’s Security Record.” It says Flock’s cloud platform “has never experienced a data breach, and no customer data has ever been compromised,” and, separately, that “There has not been a leak of Flock information.” The post was last updated July 24, 2026, and it still makes both claims.
Those two sentences are not equally sturdy. A list of where Flock’s own hardware sits may not be “customer data” in the company’s vocabulary, so the first claim can survive Michael’s export on a narrow reading. The second is harder to square with a 335,701-row file of Flock device records sitting on a public website. Michael told The Intercept the situation leaves two possibilities: “Either they knew and chose not to disclose it for fear of bad press, or they didn’t know I exfiltrated the data at all.” Given that he never told Flock he had the file, the second possibility is a real one. Flock did not immediately respond to The Intercept’s request for comment, according to that outlet.
A takedown tool built for phishing sites, aimed at a research map
Doppel’s own website describes it as an “AI-Native Social Engineering Defense Platform,” and says its takedowns are automated “by agentic AI across registrars, social platforms, ad networks, and telcos,” with a median takedown time of under 10 hours for domains. That machinery exists to knock out fake login pages and scam sites that impersonate a brand. A complaint sent to a domain registrar or web host is a request under that company’s terms of service. It is not a lawsuit, and no judge weighs a fair-use defense before the provider decides what to do. The Intercept’s account does not say where Doppel sent this one.
If the dispute ever reached a courtroom, Flock would have to show that the map is likely to confuse people about who is behind it, which is the core test for trademark infringement under the Lanham Act. Michael’s site opens with a pop-up that says it is “Not affiliated with or endorsed by Flock Safety, Flock Group, Inc., or their products,” and that Flock names and marks “are used only to identify the research subject.” Using a company’s name to talk about that company is what courts call nominative use. Congress wrote it into the dilution section of the statute, 15 U.S.C. § 1125(c)(3), which exempts nominative fair use, criticism and commentary, news reporting, and “Any noncommercial use of a mark.”
Infringement claims don’t come with that list of exemptions, but the courts have handled critic sites before. In Lamparello v. Falwell, decided Aug. 24, 2005, the U.S. Court of Appeals for the Fourth Circuit held that a noncommercial site at fallwell.com that criticized the Rev. Jerry Falwell created no likelihood of confusion, because anyone reading it could see it wasn’t his. The Flock map is a less clean case in two ways. Its name and its domain, flocksurveillance.org, lead with Flock’s name, and the Supreme Court held in Jack Daniel’s Properties v. VIP Products in 2023 that a mark used as a label for your own product gets the ordinary confusion analysis rather than extra First Amendment protection. And the pop-up cites 17 U.S.C. § 107, which is the fair-use section of copyright law. Trademark has its own fair-use doctrine, so the citation protects less than it appears to.
None of that decides anything until a court is asked, and a registrar reviewing a brand-protection complaint is not a court, which is the practical advantage of the route Flock’s representative chose.
Whether pulling the data broke federal hacking law
Not everyone sees a researcher here. Riverside County, California, Sheriff Chad Bianco, president of the California State Sheriffs’ Association, told the Daily Caller News Foundation, “As far as the information illegally accessed and published, those accountable need to be arrested and held accountable.” Chad Marlow, a policy counsel at the ACLU, told the same outlet it is “ridiculous that a company that clearly does not care about other people’s privacy at all is suddenly incredibly worried about its own privacy.” No charges against Michael have been reported.
Whether pulling data through a credential that a server hands to anyone counts as a crime is an open question under the federal Computer Fraud and Abuse Act. In Van Buren v. United States, decided June 3, 2021, the Supreme Court read the law as a “gates-up-or-down inquiry”: one either can or cannot get into a system, or a part of it. The Court said in a footnote that it was not deciding whether those gates are only technical barriers or also rules written into contracts and policies. Michael’s position fits that reading, since the mapping credentials were issued before login. His own paper says he used a flaw he had already reported to get the export, and a prosecutor could argue that knowing it was a flaw is the same as knowing the gate was supposed to be down.
Federal prosecutors also work under a 2022 Justice Department policy. The current Justice Manual says a prosecutor “should decline prosecution if available evidence shows the defendant’s conduct consisted of, and the defendant intended, good-faith security research.” The same section says the guidelines “do not create any enforceable rights,” and they don’t bind state prosecutors or a company filing a civil suit.

What the map shows about the roads you drive
The Intercept’s analysis of the dataset counted more than 170,000 cameras plus more than 130,000 other devices, including 27,000 acoustic detection devices, against the roughly 120,000 cameras Flock has cited publicly. The records include planned and decommissioned devices as well as active ones, and the map lets users filter by status, so the totals are not a count of cameras running today. The outlet found 860 devices clustered around Chicago’s O’Hare International Airport and one camera labeled “FBI Pilot Camera” at FBI headquarters.
Michael also used the locations to model commutes. He routed drives from homes within 20 miles to 22 sensitive sites, including the Pentagon, CIA headquarters, Eglin Air Force Base in Florida and the headquarters of Lockheed Martin and Northrop Grumman. His model found that at a typical site, two of every three trips pass a camera he could confirm by direction and road, and that a confirmed round trip passes 3.17 cameras on average. Over a working year of 250 trips, he estimates the same car gets recorded roughly 792 times. Those are his modeled estimates, not Flock’s figures, and they come with sensitivity tests he publishes alongside them.
His point is about soldiers and defense workers, but the arithmetic is the same for anyone with a commute. As Michael notes, the cameras don’t need a readable plate to log a car. The records pulled from a single camera, which The Auto Wire reported on last week, showed how much a Flock unit keeps about each vehicle that passes it. Where those units sit is usually decided by a police department and a vendor contract, and the public often finds out one pole at a time. Florida’s St. Lucie County ordered 52 plate cameras off its roads this month and could not account for all of them in its own permit file. Drivers help pay for these networks, too: Texas funded part of its rollout with a fee on auto insurance policies.
Volunteer projects have tried to build the same picture from the ground up. DeFlock, which The Intercept describes as crowdsourced, relies on locations that users submit. Michael’s map is different because the locations came from Flock, and that is the part of it Flock would most like gone.
What happens to the map now
The immediate decision belongs to whichever registrar or host received Doppel’s complaint, and Michael can dispute it with that company. If Flock wants a binding answer, it would have to file suit in federal court, where a judge would weigh the disclaimer, the noncommercial purpose and the domain name before any ruling. Flock and Doppel did not immediately respond to requests for comment from the Daily Caller News Foundation, according to that outlet.
For a driver, the practical fact is simpler. No federal law requires police or Flock to publish where plate readers stand, and state public-records rules vary on whether camera locations can be withheld. As of Monday, the most detailed public list of where Flock’s devices sit exists because the company handed out mapping credentials without a login, and its survival depends on a brand-protection complaint that no judge has reviewed.
Have you looked up how many plate cameras are on your commute? If you checked the map, what surprised you?

