Flock pushes to remove researcher's nationwide camera-location map

A security researcher found an unauthenticated flaw on Flock's website and used it to query a third-party mapping service for camera data. He built a public map showing 335,701 Flock camera locations, then reported the issue to the company in November 2025. Flock later filed a trademark complaint seeking to have the map taken down, while the researcher says the company did not meaningfully respond.
The researcher, Joshua Michael, said he accessed an access token through an unauthenticated endpoint on Flock's site and queried ArcGIS, a mapping service the company uses, in November 2025. His public map lists 335,701 camera locations and appears to reflect December 2025 data. He reported the flaw on Nov. 13, 2025, describing his testing as non-intrusive and limited to open endpoints.
Flock reportedly patched the flaw in January 2026 after his findings were published, but he had already extracted device-location data. Flock denies any breach or leak, while Michael disputes that account. The company filed a trademark complaint seeking removal of his map. Earlier reporting also noted camera-stored encryption keys, extracted clips and images, and misuse cases.
The exposure of hundreds of thousands of camera locations could heighten privacy and safety concerns for people living or working near them, as well as for officers, officials, and others traveling to sensitive sites. Public mapping may help accountability and research, but it may also aid adversaries seeking to avoid, disable, or track surveillance. Flock's dispute with the researcher could shape how security researchers disclose flaws and how companies balance trademark claims with public-interest information. These effects remain uncertain and depend on how the data is used and governed.