Jason Hunyar was watching a video when he recognized the frame. It was a suburban park outside Atlanta, the one he and his wife used to walk in when she was pregnant. He was not seeing it on a news broadcast or a neighborhood group. He was seeing it in a clip made by a critic who says he pulled the live feed off the internet.
That moment, reported by The Wall Street Journal, is the sharp end of a story Flock Safety has spent most of 2026 trying to contain. The company’s cameras now sit in more than 5,000 communities and feed roughly 4,500 law enforcement agencies. Its chief executive, Garrett Langley, has an explanation for how some of those feeds ended up publicly viewable. The explanation is technically about SIM cards, and it is narrower than the record supports.
The short version
- What Langley says: a supplier shipped the wrong SIM cards, which gave a small batch of cameras public IP addresses. He puts the affected share at 0.05 percent and credits the critic who found it
- What researchers documented: 67 live camera and plate reader feeds, plus debug interfaces, reachable with no login at all. The SIM cards explain the address. They do not explain the missing password
- Who found it: security researchers in January, then musician and YouTuber Benn Jordan in August, who says he bought cameras legally and took control of one
- Who is asking questions: Senator Ron Wyden, who wrote to the FTC arguing Flock skipped industry standard multi-factor authentication on law enforcement accounts
- The other problem: a resident filed more than 200 public records requests and found Flock staff had viewed one suburb’s cameras over 1,000 times
What the CEO actually said
Langley’s account to the Journal is specific. A supplier sent SIM cards configured with public IP addresses rather than private ones, which put a batch of devices directly on the open internet instead of behind carrier network address translation. He says 0.05 percent of Flock cameras were affected, that the company fixed it as soon as it saw Jordan’s video, and that he appreciates the person who found it.
Credit where it is due, that last part is not nothing. Plenty of surveillance vendors respond to independent researchers with lawyers. But the explanation has a hole in the middle of it, and the hole is the interesting part.
A public IP address makes a device reachable. It does not make it open. Everything on the internet with a public address is reachable, including your bank. What determines whether a stranger can watch the feed is whether the device asks for credentials. In the January findings, it did not. Researchers reported that no authentication was required because none had been configured.
| The claim | What the documented record shows |
|---|---|
| “Faulty SIM cards from a supplier” | Correct as far as it goes. Wrong SIMs put 60 to 70 devices on public addresses. That is a supply chain slip. |
| Implied: the exposure was the addressing | The feeds had no password. A camera on a public address behind a login is not a live stream for strangers. These were. |
| “0.05 percent of cameras” | Pair that with the 60 to 70 devices Flock described and the arithmetic implies a fleet somewhere north of 100,000 units. Small percentages of very large numbers are still large numbers. |
| “We fixed it as soon as we were notified” | Researchers published similar findings in January. The August video was not the first notice, it was the loudest one. |
This has a timeline, and it is longer than one summer
The reason the SIM card framing lands awkwardly is that the exposure has been documented repeatedly, by different people, using different methods, over eight months.
Jordan’s role in this is worth spelling out, because it is not the usual security researcher story. He is a musician and YouTuber who has become one of Flock’s loudest critics, and he bought cameras legally on the resale market to test them. He says he was able to take control of one by repeatedly pressing a button, and separately found a way to reach a camera online and broadcast what it saw.
When Flock held its annual conference in Atlanta this month, Jordan ran a counter event a few miles away in Marietta. Roughly 100 people showed up in person and about 1,000 watched online. That is a small crowd by conference standards and a very large one for a company that would prefer this conversation stayed technical.
The audit logs are the second story
Hunyar, the Atlanta area resident who recognized the park, did not stop at recognizing it. He filed more than 200 public records requests and pulled audit logs showing Flock employees had viewed cameras in the suburb of Dunwoody more than 1,000 times.
Dunwoody’s police department is one of Flock’s showcase customers, and its cameras were used in sales demonstrations. Langley confirmed the company has stopped using that department’s cameras for demos, and pointed out, reasonably, that the audit log is the reason Hunyar could find this at all. A system that logs access and releases those logs under public records law is more accountable than one that does not.
Standing near a playground, Hunyar put it plainly to the Journal: he does not want his son growing up in a world where he can be watched by anyone.
Exposure is not the only failure mode
It is worth separating two different problems that keep getting merged in coverage of this company. One is technical: cameras reachable without credentials. The other is human: authorized users searching for the wrong reasons, which no amount of encryption fixes.
The second category has a fuller paper trail. A review of media reports counted at least 28 cases of law enforcement officers using Flock or similar plate reader systems to track romantic partners. We covered one of the starkest examples in detail when a Florida officer ran his wife’s plate 717 times and the system asked him for a reason and simply believed the answer. A 2026 study from researchers at Christopher Newport University found majority-Black neighborhoods monitored at close to four times the rate of majority-white ones.
Two different questions, often asked as one
“Can a stranger see this feed?” is a security question, and it has a patch. “Should this feed exist, and who gets to search it, and for how long is it kept?” is a policy question, and no patch addresses it. Flock’s public answers have been mostly to the first. The DeFlock movement, the city council votes and the ACLU’s warrantless tracking argument are all aimed at the second.
Where the pressure is actually coming from
The backlash has stopped being an online phenomenon. Volunteers have mapped Flock installations across the country, and cities have started voting contracts down. One congressional candidate was arrested over allegations of cutting cameras down, which is a sign of temperature rather than a strategy anybody should copy.
Meanwhile the technology keeps widening. Plate readers were sold as a way to identify a car. Newer deployments are moving toward device signals, which is why plate reader networks are increasingly capable of tracking the phone in the car rather than the plate on it. The privacy argument that treats these as vehicle tools is already a generation behind the hardware.
What would actually settle this
Langley has called for a national compromise, which is the sort of phrase companies use when they would prefer one federal rule to 5,000 local fights. He is not wrong that the current situation is incoherent. Whether a camera network can watch your street is currently decided by whichever city council meeting had the better turnout.
But a compromise needs terms, and the terms that would matter are boring and testable. Mandatory multi-factor authentication on every law enforcement account, which is what Wyden asked the FTC to look at. Published retention limits. Audit logs released by default rather than by records request. Independent verification of the fleet, not a percentage quoted in an interview.
Until something like that exists, every incident will follow the same shape. A researcher finds something, the company narrows it to a component, the number sounds small, and the next researcher finds it again. The SIM cards were real. They were also the least interesting part of what got found.

