Full Report
Like many Florida municipalities, officials in St. Lucie County recently decided to get rid of all their automated license-plate readers made by Flock, the company whose cameras have drawn scrutiny over police misuse and data privacy concerns. County officials thought they had 52 of the cameras — which law enforcement agencies use to record passing…
Analysis Summary
# Incident Report: Discovery of Unauthorized Surveillance Hardware
## Executive Summary
St. Lucie County officials discovered 14 unauthorized and unpermitted Flock automated license-plate reader (ALPR) cameras installed on public roads. The discovery occurred during a decommissioning project intended to remove the county’s known fleet of 52 cameras. The origin, ownership, and data destination of these additional devices remain unconfirmed, posing significant privacy and supply chain security concerns.
## Incident Details
- **Discovery Date:** October 2026 (Reported)
- **Incident Date:** Unknown (Deployment occurred prior to October 2026)
- **Affected Organization:** St. Lucie County
- **Sector:** Government / Public Safety
- **Geography:** Florida, USA
## Timeline of Events
### Initial Access
- **Date/Time:** Unknown
- **Vector:** Physical installation on public infrastructure.
- **Details:** Unauthorized third parties (or the vendor) installed 14 ALPR cameras on main county roads without obtaining the necessary permits or informing county officials.
### Lateral Movement
- **Details:** Not applicable in a traditional network sense; however, the devices represent a "lateral" expansion of a surveillance footprint into unauthorized geographic zones.
### Data Exfiltration/Impact
- **Details:** The 14 unauthorized cameras recorded passing vehicles’ license plates, times, and locations. It is currently unclear where this data was transmitted or who retained access to the PII (Personally Identifiable Information).
### Detection & Response
- **How it was discovered:** During a physical audit and removal process of the 52 authorized Flock cameras.
- **Response actions taken:** Discovery triggered an investigation into the ownership and permitting status of the surplus hardware.
## Attack Methodology
*Note: This incident involves physical "Shadow IT" or unauthorized surveillance rather than a traditional cyber intrusion.*
- **Initial Access:** Physical deployment/mounting of hardware on public utility poles or main roads.
- **Persistence:** Maintaining hardware in plain sight, disguised as legitimate county infrastructure.
- **Discovery:** Physical reconnaissance to identify high-traffic areas for placement.
- **Collection:** Automated license plate recognition and metadata logging.
- **Exfiltration:** Likely cellular or wireless transmission of captured plate data to a cloud-based dashboard.
- **Impact:** Unauthorized surveillance and potential violation of data privacy ordinances.
## Impact Assessment
- **Financial:** Costs associated with the labor to identify and remove uncontracted hardware.
- **Data Breach:** Exposure of vehicle movement patterns for an unknown number of citizens.
- **Operational:** Disruption of the county’s decommissioning plan; resource diversion to investigate the mystery cameras.
- **Reputational:** Increased public scrutiny regarding police misuse and lack of oversight for surveillance technology.
## Indicators of Compromise
- **Physical indicators:** Flock-branded camera hardware located at sites without matching county permit documentation.
- **Inventory Mismatch:** Count of physical devices in the field (66) exceeding the count of contracted devices (52).
## Response Actions
- **Containment measures:** Identification of all non-permitted hardware locations.
- **Eradication steps:** Scheduled physical removal of the 14 unauthorized units along with the 52 authorized units.
- **Recovery actions:** Reconciliation of inventory and auditing of vendor billing/contracts.
## Lessons Learned
- **Inventory Control:** A lack of a central, audited asset registry for physical "Internet of Things" (IoT) devices allowed unauthorized hardware to remain undetected.
- **Vendor Oversight:** Surveillance vendors may deploy "trial" or "shadow" hardware without explicit municipal approval, leading to liability and privacy risks.
## Recommendations
- **Asset Auditing:** Implement biannual physical audits of all roadside IoT and surveillance equipment.
- **Permit Reconciliation:** Require that every physical MAC address or serial number in a vendor's fleet be tied to a specific municipal permit and GPS coordinate.
- **Zero-Trust Physical Infrastructure:** Ensure all third-party hardware installations are verified by a county inspector during the deployment phase.