Security researcher Joshua Michael discovered an unauthenticated vulnerability in Flock's website that granted an access token without requiring login credentials. He used it to query ArcGIS, a third-party mapping service Flock relies on, and retrieved a database of Flock devices. Michael then published the Flock Surveillance Map, which lists 335,701 cameras.

Michael reported the flaw in November 2025, but Flock did not reply until after two more attempts, and even then only said it was internally triaging the findings. Flock fixed the vulnerability in January after the research was published, but Michael had already exfiltrated the device location database. Flock maintains that it has never been hacked and that its cloud platform has never experienced a data breach, a claim Michael disputes, noting the company either knew about the data pull and stayed silent or failed to detect it.

Rather than addressing the security disclosure, Flock sent a trademark infringement complaint through the cybersecurity firm Doppel, demanding the map be taken down for unauthorized use of the 'FLOCK SAFETY' trademark. The article also highlights broader concerns about Flock's systems: encryption keys stored directly on cameras allowed extraction of more than 27,000 clips, police officers have misused the system to stalk romantic partners, and the camera network could potentially track people near sensitive sites such as the Pentagon, CIA headquarters, and Eglin AFB.