TL;DR
Get privacy and security gear delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
A map by cybersecurity researcher Joshua Michael plotted more than 300,000 Flock devices using location data from the company’s own records, including cameras and supporting equipment. The Intercept reported that the site was taken offline after Michael was notified of a trademark complaint filed by Doppel; the complaint’s outcome and the map’s current availability are unclear.
A map showing the locations of more than 300,000 Flock devices was taken offline after its creator, cybersecurity researcher Joshua Michael, was notified that Doppel had filed a trademark infringement complaint, according to The Intercept. The map had drawn on a snapshot of Flock’s own records and showed a wider network than the more than 120,000 cameras the company said it operated nationwide this summer.
The map, published Wednesday, plotted more than 170,000 cameras and more than 130,000 related devices, according to The Intercept’s account of Michael’s work. The accompanying equipment included about 27,000 acoustic detection devices and networking equipment used to integrate third-party cameras. The map assigned device types and displayed names from Flock’s database, some of which included addresses or other identifying details.
Michael based the map on location data from a snapshot of Flock records he said he archived in December 2025. He told The Intercept that he found a publicly accessible access token on Flock’s website in November 2025, which he said allowed him to query ArcGIS, a geographic information platform used by the company. He said he notified Flock and described his tests as limited to open endpoints, without bypassing authentication or changing data. Flock acknowledged receiving his findings, according to an email quoted by Michael, but he said the company did not follow up.
The Intercept said it visited six randomly selected Arizona locations on the map and found a Flock camera at each indicated location. The report also described mapped devices at public safety sites, detention centers and other locations. The findings were cited at a Senate Subcommittee on Crime and Counterterrorism hearing on Flock, according to the report. Flock did not immediately respond to The Intercept’s request for comment on the map.
A Wider View of Flock’s Network
The map offered a detailed view of the geographic reach and composition of Flock’s surveillance system, including equipment beyond its license plate cameras. That scope matters to communities and public officials assessing how surveillance infrastructure is distributed and what kinds of devices contribute to it.
Its records also raised questions about the handling of location data. Device names and coordinates could reveal sensitive placements, while the mapped presence of cameras at government facilities drew attention to who might be monitored and how the system is managed. The map’s publication made those details easier to search; its removal now limits public access to the presentation Michael assembled.
The reported complaint adds a separate dispute over the site itself. The available report does not establish whether the complaint caused the site to go offline, whether Doppel was acting for Flock, or what legal steps may follow. Those points remain relevant to understanding why the map disappeared and whether it will return.
From Database Finding to Public Map
Michael said he identified the exposed access token in November 2025 while reviewing Flock’s website. In an email quoted in the report, he told the company his testing was non-intrusive and did not involve authenticated access or data modification. He said Flock replied that it was triaging the findings, but did not later provide him with next steps.
Michael downloaded device location data in December and published a technical account in January. The Intercept reported that Flock appeared to have fixed the vulnerability after his post. In a blog post that January, Flock said its cloud platform had never experienced a data breach and that company information had not been leaked. Michael disputed the company’s assurances, arguing that the episode showed either a disclosure or detection failure; those were his interpretations, not findings independently established in the report.
The new map differed from crowd-sourced projects such as DeFlock, which rely on locations submitted by members of the public. Michael’s map instead used a snapshot of Flock’s own records and included supplemental devices. Flock’s summer statement that it operated more than 120,000 cameras and the map’s count of more than 170,000 cameras are not directly comparable without further detail on dates, definitions and database coverage.
“These cameras form a nationwide surveillance network that tracks where everyone drives.”
— Joshua Michael, speaking to The Intercept
The Complaint and Exposure Questions
The Intercept reported that Michael was notified Thursday that Doppel had filed a trademark infringement complaint concerning his site. The report excerpt does not detail the complaint’s legal basis, identify the exact party it names, or establish whether the filing required the map to be taken offline. The complaint’s status and any response from Michael or Doppel are not given.
It is also unclear whether the map or its underlying dataset remains accessible elsewhere. The reported device counts come from a December 2025 snapshot, not a live tally. The source material does not specify how many listed devices were active when the map was published, how Flock defines its camera count, or whether the figures include duplicate, retired or otherwise inactive devices.
Flock did not immediately comment to The Intercept on the map. The report also does not independently determine whether Michael’s access to the data constituted a breach under any legal or technical definition, or what Flock knew about the exposure before publishing its security statement.
Updates on the Site and Filing
The next developments to watch are whether the map returns, whether Michael or Doppel provides details about the complaint, and whether the filing leads to further legal action. Any new statements from Flock could also clarify how it counts devices, what it knew about the access token, and how it assessed the data exposure.
Until then, the map’s published totals should be treated as counts from a dated snapshot of Flock records, as described by Michael and reported by The Intercept. The status of the complaint and the availability of the map remain unresolved.
Key Questions
What did the Flock Surveillance Map show?
It plotted more than 170,000 cameras and more than 130,000 associated devices using location data from a snapshot of Flock records archived in December 2025, according to The Intercept.
Why was the map taken offline?
The Intercept reported that Michael was notified Doppel had filed a trademark infringement complaint regarding his site. The available report does not establish whether the complaint legally required the map’s removal or give the filing’s outcome.
How did Michael get the location data?
Michael said he found a publicly accessible access token on Flock’s website that let him query ArcGIS for device locations. He said he notified Flock in November 2025 and limited his testing to open endpoints.
How do the map’s figures compare with Flock’s camera count?
Flock said this summer that it operated more than 120,000 cameras nationwide. Michael’s map showed more than 170,000 cameras plus more than 130,000 other devices. The figures refer to different descriptions and dates, and the report does not establish that their counting methods are directly comparable.
Source: hn
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
