Full Report
After an affair with a fellow police officer ended, a Georgia cop used Flock to track her movements—and those of a man whose vehicle often showed up near hers, internal investigation records show.
Analysis Summary
# Incident Report: Insider Abuse of ALPR Surveillance Systems
## Executive Summary
A patrol officer with the Alpharetta Police Department (APD) engaged in an unauthorized surveillance campaign against a former romantic partner and a fellow officer using the Flock Safety license plate reader system. The subject performed 85 unauthorized searches over a three-month period to track their personal movements. The incident resulted in the officer's resignation following an internal investigation into the misuse of law enforcement technology.
## Incident Details
- **Discovery Date:** July 2026 (Internal investigation launch)
- **Incident Date:** March 2026 – May 2026
- **Affected Organization:** Alpharetta Police Department (APD)
- **Sector:** Public Safety / Law Enforcement
- **Geography:** Alpharetta, Georgia, USA
## Timeline of Events
### Initial Access
- **Date/Time:** March 2026
- **Vector:** Authorized User Credentials
- **Details:** Officer Dustin Bozzo utilized his legitimate department-issued credentials to access the Flock Safety ALPR database for non-official, personal purposes.
### Lateral Movement
- **Details:** Not applicable in the traditional sense; the subject leveraged existing broad access permissions within the Flock Safety platform to pivot from tracking one individual (the ex-partner) to a second individual (the fellow officer) based on proximity data.
### Data Exfiltration/Impact
- **Details:** Unauthorized access to location telemetry and movement history of two private citizens/officers. 56 searches were conducted for the ex-partner's plate and 29 for the second officer's plate.
### Detection & Response
- **How it was discovered:** Internal investigation records (likely triggered by internal audits or a formal complaint).
- **Response actions taken:** The officer was placed on paid administrative leave on July 20; the officer resigned in August during the ongoing investigation.
## Attack Methodology
- **Initial Access:** Valid user credentials (Insider Threat).
- **Persistence:** Maintained through active employment and legitimate account status.
- **Privilege Escalation:** None required; the subject had sufficient privileges to conduct searches.
- **Defense Evasion:** Abuse of "official use" justifications (if prompted by the system).
- **Credential Access:** Legitimate login.
- **Discovery:** Used the ALPR database to identify the vehicle of the second officer by observing proximity to the primary target.
- **Lateral Movement:** N/A.
- **Collection:** Manual querying of license plate numbers to generate location history.
- **Exfiltration:** Visual observation and manual tracking of surveillance data.
- **Impact:** Breach of privacy, violation of department policy, and unauthorized surveillance.
## Impact Assessment
- **Financial:** Costs associated with internal investigation and administrative leave.
- **Data Breach:** Compromise of PII (Personally Identifiable Information) and location data of two individuals.
- **Operational:** Loss of one patrol officer; damage to internal trust.
- **Reputational:** Public scrutiny regarding the police department's ability to safeguard surveillance technology and civil liberties.
## Indicators of Compromise
- **Behavioral indicators:** High frequency of searches for specific license plates not associated with active criminal investigations.
- **Behavioral indicators:** Searches conducted outside of typical mission parameters or without corresponding case numbers.
## Response Actions
- **Containment measures:** Subject placed on administrative leave; access to department systems revoked.
- **Eradication steps:** Internal affairs investigation conducted to verify the scope of the abuse.
- **Recovery actions:** Acceptance of subject's resignation; review of internal access policies.
## Lessons Learned
- **Audit Gaps:** The delay between the activity (March–May) and discovery (July) suggests a lack of real-time automated alerting for repetitive searches of the same plate.
- **Policy Enforcement:** Workplace dating bans were violated prior to the surveillance, indicating a need for better enforcement of conduct policies to prevent escalations.
- **Technology Risk:** ALPR systems provide powerful surveillance capabilities that are highly susceptible to "loveint" (stalking romantic interests) without strict oversight.
## Recommendations
- **Reason-Code Enforcement:** Require a valid case number or incident ID for every ALPR search conducted.
- **Automated Alerting:** Implement "Hot List" alerts or anomaly detection to flag when an officer repeatedly searches a specific plate that is not flagged as stolen or wanted.
- **Regular Audits:** Conduct monthly random audits of ALPR usage logs to ensure searches align with official police business.
- **Privacy Training:** Mandatory annual training specifically addressing the legal and ethical consequences of misusing surveillance databases.