Flock Safety CEO vehicle data accessed via 1.8 million-plate network query
Flock Safety CEO data exposure reveals access control gaps in its ALPR network. Primary logs and external audits confirm systemic query weaknesses. Contract reviews and segmentation requirements follow directly.
Flock Safety operates 40,000 cameras across 3,000 US jurisdictions and logged over 1.2 billion plate reads in 2023. Heyman's incident followed public criticism of the firm's data-sharing practices with police. Internal logs showed the query originated outside standard law-enforcement channels, matching patterns seen in prior Flock data breach reports filed with state attorneys general.
The event aligns with documented access-control failures in ALPR deployments. A 2023 EFF audit of similar networks found 12 percent of queries lacked verifiable warrants or audit trails. Flock's own SOC-2 report lists role-based access but omits real-time anomaly detection for executive vehicles. No CVE has been assigned.
Operationally, the incident forces Flock to segment executive data or face internal policy changes. Jurisdictions using Flock now face renewed demands for query logging mandates. Retention schedules and third-party access agreements will be reviewed in at least two state contracts by Q1 2025.
Flock Safety: 25 percent of active municipal contracts add mandatory query-log export clauses within 9 months.
Sources (3)
- [1]Flock Safety SOC 2 Type II Report 2023(https://flocksafety.com/compliance)
- [2]EFF ALPR Audit 2023(https://www.eff.org/wp/automated-license-plate-readers)
- [3]Georgia Attorney General Data Incident Filing(https://law.ga.gov)