top of page

Flock’s Police Misuse Scandal Exposes Surveillance Without Guardrails

Aug 31
13 min read

Flock Safety built a network of more than 120,000 cameras, but at least 50 officers were charged or accused of abusing license-plate readers. This techmeme analysis examines a conflict that reaches beyond individual misconduct. A system designed for rapid police searches expanded faster than the safeguards intended to restrain its users.

The reported cases include officers searching for romantic partners, former partners, relatives, and other people unrelated to legitimate investigations. Flock equipment appeared in 46 of the cases identified by The Washington Post. In 26 cases, investigators said officers targeted wives, girlfriends, former partners, or women they wanted to meet.

The central tension is no longer whether automated license-plate readers can help police. Departments have used them to locate missing people, find stolen vehicles, and investigate violent crimes. The harder question is whether a nationwide surveillance network can remain accountable when local agencies control access, policies, and audits.

The Investigation Exposed a National Pattern, Not an Isolated Breach

The most important finding is that personal surveillance appeared across multiple departments, jurisdictions, and relationships.

Automated license-plate readers, commonly called ALPRs, photograph passing vehicles and convert their plates into searchable records. Each record can include a time, location, vehicle image, and other visible characteristics.

A single camera provides a limited observation. A searchable network can reconstruct where a vehicle appeared across many cameras and jurisdictions. Repeated searches can reveal routines involving homes, workplaces, medical appointments, schools, relationships, and religious activity.

The police-record analysis reviewed thousands of pages of court records and internal police reports. Reporters also interviewed seven alleged victims. Authorities had charged or accused at least 50 officers of unauthorized license-plate-reader use when the investigation appeared.

The scale matters because the cases were not confined to one malfunctioning department. They involved different officers using similar access for comparable personal purposes. That repetition points toward a control problem built around permissions, monitoring, and enforcement.

Marci Bakely’s experience in Georgia illustrates how that control failure can affect an individual. Bakely said her former boyfriend, Braselton police chief Michael Steffman, appeared to know when she visited stores, doctors, or dates.

She reportedly searched her home for hidden cameras and asked mechanics to check her vehicle for trackers. The surveillance source was less visible. Steffman had access to Flock’s network through his law-enforcement position.

Search logs later indicated that he queried plates associated with Bakely and her teenage daughter roughly 600 times. The searches covered about 13 months, with many occurring between midnight and 4 a.m.

Steffman was arrested in November 2025 on charges that included stalking, harassment, and license-plate-reader misuse. He died by suicide in April 2026 before the case reached trial. The charges therefore did not produce a final judicial determination of guilt.

Bakely did not discover the full search pattern through routine departmental oversight. She used Have I Been Flocked, a project that aggregates search logs obtained through public-records requests.

That sequence captures the larger reversal. The system recorded enough activity to reveal alleged misuse, yet the intended supervisors did not identify it promptly. A victim and outside researchers became the effective auditors.

The original investigation counted at least 50 accused or charged officers. Subsequent reporting raised the known total to at least 69 police officials accused, charged, or convicted of misuse.

The increase does not establish how frequently misuse occurs across all searches. It does show that the original count was a documented floor rather than a complete measure.

Flock told reporters that accused users represented a small share of its 140,000 active users. That denominator provides context, but it does not resolve the oversight question.

An undetected abuse rate cannot be calculated from cases discovered through complaints, public records, or journalism. The relevant unknown is how many suspicious searches never attracted an outside observer.

Why the Flock Network Creates Unusual Pressure

Flock’s scale turns a local officer’s credentials into potential access to a much broader map of human movement.

The company told The Washington Post that its cameras operated across more than 6,000 communities. Those cameras reportedly produced 20 billion plate scans each month.

Flock’s network is searchable because participating agencies can share data across jurisdictional boundaries. This design helps an investigator follow a suspect whose vehicle moves between cities or states.

The same feature changes the consequences of unauthorized access. An officer does not need to install a tracker or personally follow someone. The network can supply observations created by cameras the officer never deployed.

Flock says customers own the data collected by their cameras. However, ownership does not fully describe who can retrieve records through sharing agreements.

A department can authorize searches by other agencies, sometimes across a large geographic area. Users may therefore reach information that originated outside their own community.

This architecture creates pressure on police departments because each agency becomes part of a shared security environment. Weak controls in one department can expose data gathered by another.

It also creates pressure on municipalities that approved cameras as local tools. Residents may discover that a city’s equipment contributes to investigations or searches performed elsewhere.

The system’s value and risk come from the same technical characteristic. More cameras produce greater investigative coverage, while greater coverage makes personal searches more revealing.

Traditional internal controls were not designed uniformly for that reach. Some agencies lacked written policies, regular audits, or formal training for Flock searches.

Later reporting found at least 15 known cases in which victims, activists, or journalists first detected suspected misuse. That finding shifts attention from individual intent to institutional detection.

In Indianapolis, reporters identified an officer who appeared to search vehicles used by his wife and two personal acquaintances. The search history showed 3,759 queries over 10 months.

The department suspended the officer without pay and opened investigations after journalists raised the activity. A department official acknowledged that regular audits had not previously been standard practice.

In Highland Heights, Ohio, the police department reportedly had no Flock policy and had not audited usage before a journalistic inquiry. One employee appeared to have searched five plates more than 1,000 times each.

In Haines City, Florida, authorities had not audited Flock use during a period when an officer allegedly searched his wife’s vehicle repeatedly. The officer later confessed to a supervisor and was charged after reporters made inquiries.

These cases do not show that every suspicious search was criminal. Search counts require context, and legitimate investigations can involve repeated queries.

They do show that conspicuous patterns could remain unexamined. A system can preserve an audit trail without creating accountability if nobody reviews that trail.

The pressure extends beyond Flock. Other vendors offer license-plate recognition, camera networks, and integrated police platforms. Axon, Motorola Solutions, and Rekor operate in adjacent markets or provide comparable capabilities.

Flock’s prominence makes it the central subject, but the governance problem applies across vendors. Any searchable movement database needs clear authorization, independent review, retention limits, and meaningful consequences for misuse.

Techmeme Analysis: The Guardrails Were Optional Until the Backlash Was Not

Flock’s central failure was not the absence of safeguards, but its decision to leave critical safeguards optional during rapid expansion.

Before the August backlash, Flock offered an Audit Assistance feature that scanned searches for unusual patterns. Those patterns could include repeated queries for one vehicle or activity performed while an officer was off duty.

Agencies had to activate the feature voluntarily. Flock said only about one-third of its 7,000 law-enforcement customers were using it before the company announced mandatory changes.

That choice placed responsibility on local departments with widely different resources and technical practices. A large agency might employ compliance staff, while a small department might rely on one administrator.

Local control can reflect community priorities. It can also create inconsistent protection for people whose movements enter the same national network.

The problem becomes sharper when the department’s administrator is the suspected user. Several reported cases involved chiefs or other senior officials who held authority over the systems they allegedly misused.

A policy requiring supervisors to review searches offers limited protection when the supervisor controls the account. Effective oversight must account for insiders with administrative privileges.

Flock recorded searches in audit logs and encouraged agencies to inspect them. CEO Garrett Langley argued that those records helped expose officers who abused their authority.

That argument contains an important truth. Detailed logs are better than an unrecorded search system, and they gave investigators evidence for examining alleged misconduct.

Yet logging and monitoring are separate controls. A record sitting unread does not interrupt stalking, warn a potential victim, or suspend a suspicious account.

This distinction explains why the investigation produced such a strong reaction. The technology had evidence of repeated activity, but many departments had not built a process to interpret it.

Flock’s previous approach assumed agencies would adopt recommended protections. Langley later said he expected state and local lawmakers to mandate optional safeguards, but those mandates did not arrive quickly.

The company eventually decided to move faster itself. That response tacitly recognizes that decentralized adoption did not produce consistent oversight.

Flock’s scale made voluntary governance increasingly difficult to defend. A platform connecting thousands of agencies cannot treat every safety control as a local preference.

The issue resembles security defaults in consumer and enterprise software. Optional multifactor authentication protects users who activate it, while mandatory authentication changes the baseline for everyone.

Surveillance systems demand an even higher standard. A poorly secured personal account primarily endangers its owner. A poorly governed police account can expose people who never chose to enter the system.

The product’s convenience also changes user behavior. A search that once required a request, a detective, or physical surveillance can become a quick database query.

Lower friction supports legitimate investigations, but it also removes practical barriers to curiosity searches. The act becomes easier, quieter, and harder for the subject to detect.

Ian Adams, a criminology professor at the University of South Carolina, told the Associated Press that personal curiosity searches were reasonably foreseeable. Other law-enforcement databases have faced similar misuse.

That history matters because it weakens the claim that these cases represented an unpredictable use of a new tool. Insider misuse is a known risk whenever employees can retrieve sensitive information.

A responsible design therefore starts from expected misuse, not ideal behavior. It asks how the product limits, detects, and escalates access before a complaint arrives.

Flock’s New Controls Address Detection but Not Every Power Imbalance

The new safeguards improve the technical baseline, but their effectiveness still depends on review quality and institutional independence.

Flock announced that agencies would have to tie every search to a criminal case number. This requirement creates a structured justification that supervisors can compare with actual investigations.

Emergency overrides will remain possible, according to the company. Those overrides are expected to receive automatic scrutiny, which should make unexplained searches easier to isolate.

Flock also plans to make automated abnormal-activity reviews mandatory. A flagged user can be locked out while the agency conducts an internal review.

The company intends to shorten its default retention period from 30 days to seven. Data linked to a documented case can be preserved longer as evidence.

A shorter retention window reduces the historical movement data available for casual searches. It does not prevent real-time monitoring or repeated queries conducted during those seven days.

The mandatory guardrails are scheduled for implementation across law-enforcement customers by January 1. Their rollout offers the clearest near-term test of Flock’s response.

The company will also give departments more control over data sharing. Agencies can specify which investigation types permit outside searches, potentially allowing violent-crime queries while rejecting immigration-related access.

These changes address several weaknesses identified by journalists and privacy advocates. They create searchable reasons, lower retention, standardize anomaly detection, and narrow some cross-agency access.

However, a case-number field can become a weak control if users enter unrelated or fabricated references. Software can confirm that a field contains a valid format, but it cannot always establish investigative relevance.

Automated anomaly detection has similar limits. Rules can flag unusually frequent searches, off-duty activity, or repeated interest in one vehicle.

A determined user might reduce frequency, spread searches across accounts, or use plausible case descriptions. Detection thresholds can also miss harmful behavior that involves only a few targeted lookups.

False positives present another challenge. Officers working on surveillance-intensive investigations may trigger alerts despite legitimate conduct.

Departments will need reviewers who understand both the investigation and the risk. Otherwise, alerts can become another queue that receives minimal attention.

Internal review also remains vulnerable to conflicts of interest. A department investigating its own chief, administrator, or popular officer may not provide the independence victims expect.

Chuck Wexler of the Police Executive Research Forum described the problem as a balance between privacy and effective policing. He argued that department policy would likely matter more than company changes.

That view identifies a boundary Flock cannot solve through software alone. The vendor can flag behavior and restrict an account, but public authorities determine discipline, disclosure, and prosecution.

Bakely expressed a related concern after the changes were announced. She welcomed efforts to reduce abuse but questioned why stronger action followed public exposure rather than earlier warnings.

Her reaction illustrates why a technical fix cannot repair trust immediately. Victims judge the system by whether it protected them before harm, not only by its response after publication.

The new controls should therefore be measured by outcomes. Useful questions include how many alerts appear, how quickly departments review them, and how often searches receive independent scrutiny.

Agencies should also disclose aggregate findings without exposing active investigations. Public reporting can show whether mandatory safeguards function across different department sizes.

The Hardest Question Is Who Watches the Watchers

Accountability fails when the same institution controls surveillance, auditing, discipline, and public disclosure.

The reported cases show that misuse can originate at different levels. A patrol officer may perform a personal search, while a chief can hold both search access and administrative authority.

That structure makes independent oversight essential. Local elected officials, inspectors general, courts, state regulators, and civilian review bodies can provide checks unavailable inside a department.

Only 13 states reportedly require law-enforcement agencies to audit license-plate-reader usage. The remaining policy landscape includes departments with voluntary rules, informal practices, or no specific auditing mandate.

The absence of a comprehensive federal framework produces different protections across state lines. A vehicle’s data can still move through a network that crosses those boundaries.

Public-records laws have become an unexpected safeguard. Search logs obtained through those laws helped journalists, activists, and potential victims identify suspicious behavior.

Have I Been Flocked converted scattered public records into a more accessible form. That work demonstrates how transparency can reveal patterns hidden within individual departments.

However, public-records enforcement varies by jurisdiction. Agencies can delay responses, apply exemptions, or produce logs in formats that are difficult to analyze.

Transparency after the fact also cannot substitute for prevention. A person being tracked may not know which department holds the relevant records or which plate searches to request.

Courts face a separate question involving constitutional limits. License plates are visible on public roads, but large databases can reveal patterns that isolated observations cannot.

The Supreme Court has recognized privacy concerns involving prolonged location tracking in other technological contexts. Yet license-plate-reader rules remain unsettled across jurisdictions and factual situations.

Privacy advocates argue that networked ALPR searches can become warrantless mass surveillance. Police supporters respond that cameras record vehicles already visible in public and help investigate serious crimes.

Both positions address real characteristics of the system. Cameras observe public movements, but network aggregation creates knowledge no single officer could easily collect.

The policy choice is therefore not simply cameras or no cameras. It includes retention duration, search authorization, geographic sharing, acceptable cases, audit frequency, and access to remedies.

The risk is particularly serious in intimate-partner abuse. An officer can combine professional database access with personal knowledge about a victim’s routines, relatives, and vulnerabilities.

A normal account suspension may not address that threat. Departments need procedures for notifying potential victims, preserving evidence, revoking broader database credentials, and arranging outside investigations.

Officers also use multiple information systems. Restricting Flock access does not necessarily block motor-vehicle records, dispatch information, criminal databases, or other location tools.

This is why the primary conflict is surveillance capability against accountable access. Flock competes with other vendors, but vendor rivalry does not resolve who should authorize a search.

A department switching platforms can carry weak policies to the replacement. The interface changes while the institutional vulnerability remains.

Public agencies should treat ALPR access like other sensitive credentials. That means named users, minimal permissions, frequent reviews, tamper-resistant logs, and immediate escalation for suspicious patterns.

Administrators also need oversight. High-level accounts should not receive exemptions simply because their holders supervise other users.

The strongest system would separate detection from adjudication. Software could flag activity, while an independent authority reviews high-risk searches involving personal connections or senior personnel.

Such an arrangement would add friction. That friction is a safety feature when the database can reconstruct another person’s life.

Three Signals Will Show Whether the Response Is Working

The next test is whether mandatory safeguards change behavior before another victim or journalist discovers a pattern.

The first signal is Flock’s January 1 implementation deadline. Observers should examine whether every law-enforcement customer activates case-linked searches, anomaly detection, and automatic lockouts.

A complete rollout would strengthen Flock’s claim that it changed the baseline. Delays, broad exemptions, or optional implementation would weaken that claim.

The second signal is departmental audit reporting. Agencies should disclose how often they review searches, how many anomalies appear, and what happens after a flag.

The later audit findings show why this matters. Reporters found departments that began investigations only after receiving questions about suspicious logs.

Regular public reporting would indicate that audits have become an operating practice. Silence would leave residents unable to distinguish active oversight from unused software.

The third signal is legislative action. Lawmakers can establish minimum retention rules, permitted uses, warrant requirements, cross-agency limits, and independent audit standards.

Federal action would create a common baseline, while state laws could address local policing structures. Either path would strengthen accountability if it includes enforcement and remedies.

Policy must also preserve legitimate emergency uses. Missing-person cases and immediate threats can require rapid searches without ordinary delays.

Emergency access should create more review, not less. Every override should generate a durable record and prompt examination after the urgent situation ends.

Flock’s commercial position will offer another indirect indicator. More than 50 agencies or jurisdictions had reportedly canceled, suspended, rejected, or deactivated contracts during 2026.

Contract decisions reveal whether municipalities accept the new controls. Renewals may indicate restored confidence, while cancellations may show that the trust problem extends beyond product settings.

Public opinion is already moving. A YouGov survey reported that more Americans opposed police use of license-plate readers than supported it.

In another survey of about 1,000 adults, 43 percent said the technology made them feel neither safer nor less safe. Twenty-seven percent said it made them feel safer.

More than four in ten respondents believed cameras were used to stalk, harass, or build cases against innocent people. The surveillance polling reflects distrust that technical controls alone may not reverse.

Those surveys do not determine the legality or effectiveness of ALPR systems. They show that public legitimacy has become a material constraint for vendors and police departments.

This techmeme analysis ultimately points to a familiar security lesson. Capability spreads quickly when it saves time, while governance often arrives after visible harm.

Flock’s network made vehicle searches fast, extensive, and quiet. Those features supported police work, but they also increased the damage one authorized insider could cause.

The company’s mandatory safeguards are meaningful because they replace optional controls with a shared baseline. They remain incomplete because institutions still decide what an alert means and who faces consequences.

Readers should watch the January rollout, published audit results, and binding legislation. Together, those signals will show whether accountability is becoming systematic or merely reactive.

The practical question is not whether one vendor can promise responsible surveillance. It is whether every search leaves a justified record, receives credible oversight, and triggers action before outsiders expose abuse. Keep following this techmeme analysis as agencies release audit data and lawmakers define enforceable limits. The next documented case will test whether the system learned from its warnings or simply became better at managing criticism.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page