HomeIntelligenceBrief
BREACH BRIEF 🟠 High ThreatIntel

Flock AI Camera’s Encryption Key Exposed via Unencrypted Partition, Enabling Potential Data Harvest

Researchers reverse‑engineered a Flock surveillance camera and found the encryption key stored in clear text on an unencrypted partition, giving full access to millions of captured images. The flaw highlights a control gap in key‑management that must be addressed for audit and privacy readiness.

Verisq™ Intelligence · 📅 September 22, 2026 · 📰 schneier.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
2 recommended
📰
Source
schneier.com

Flock AI Camera’s Encryption Key Exposed via Unencrypted Partition, Enabling Potential Data Harvest

What Happened — Researchers who captured a Flock camera reverse‑engineered its firmware and discovered that an unencrypted partition stored the decryption key for an encrypted data partition. The flaw allowed full access to the device’s internal storage, including logs showing the camera had captured more than a million images of vehicles, people, and other objects.

Why It Matters for Trust & Control Assurance

  • The incident illustrates a classic control‑gap: encryption keys must never be stored in clear text on the same system they protect. Continuous control‑assurance programs flag such misconfigurations during evidence collection.
  • A compromised device can exfiltrate large volumes of personally identifiable information, creating audit‑ready evidence requirements for privacy and data‑protection obligations.
  • Detecting and documenting this gap early supports a defensible audit trail and demonstrates due‑diligence to regulators and partners.

Who Is Affected — Companies deploying AI‑enabled surveillance cameras in retail, transportation, smart‑city, and enterprise environments.

Recommended Actions

  • Conduct a control‑mapping review of encryption‑key management on all edge devices; verify that keys are stored in hardware‑based secure modules or separate management systems.
  • Collect and retain evidence of key‑storage configurations as part of your continuous monitoring program.
  • Update vendor risk assessments to include secure‑configuration checks for IoT and AI hardware. Source: Schneier on Security

Technical Notes

  • Attack vector: misconfiguration – clear‑text key on an unencrypted partition.
  • No CVE assigned; the flaw was uncovered via reverse engineering of the device firmware.
  • Data types potentially exposed: high‑resolution images, vehicle license‑plate data, incidental captures of individuals. Source: same as above
📰 Original Source
https://www.schneier.com/blog/archives/2026/09/reverse-engineering-flock-cameras.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →