Full Report
St. Lucie County in Florida discovered (alt link) a dozen Flock cameras whose ownership it can’t identify, and that the county government had not permitted. I am reminded of the decade-old story of StingRay cell phone surveillance devices in Washington, DC, whose operators were also unknown. My guess is that in the StingRay case, the devices were operated by foreign actors. This Flock case is more likely some local government entity that didn’t bother getting approval. Were I a foreign actor, I would rather hack the existing Flock network—like Israel ...
Analysis Summary
# Incident Report: Unauthorized Surveillance Infrastructure Discovery
## Executive Summary
St. Lucie County, Florida, discovered approximately one dozen unauthorized Flock Safety license plate reader (LPR) cameras installed within its jurisdiction. The county government has been unable to identify the owner or operator of these devices, which were installed without legal permits or official authorization. The incident highlights the risks of "shadow" surveillance infrastructure and the potential for both domestic and foreign actors to exploit normalized surveillance networks.
## Incident Details
- **Discovery Date:** October 1, 2026 (Reported)
- **Incident Date:** Unknown (Duration of unauthorized operation TBD)
- **Affected Organization:** St. Lucie County Government
- **Sector:** Government / Public Safety
- **Geography:** St. Lucie County, Florida, USA
## Timeline of Events
### Initial Access
- **Date/Time:** Unknown
- **Vector:** Physical Installation
- **Details:** Unauthorized parties physically installed approximately 12 Flock cameras on public or private property without obtaining the necessary county permits or right-of-way approvals.
### Lateral Movement
- **N/A:** As these are physical hardware devices, "lateral movement" in this context refers to the deployment of multiple units (a dozen) across various geographic locations within the county.
### Data Exfiltration/Impact
- **Details:** The cameras likely captured vehicle license plates, timestamps, and location data. Because the operator is unknown, the destination of this data stream remains unidentified.
### Detection & Response
- **Detection:** Discovery by county officials (method of discovery not specified in the text, likely via maintenance or public works audit).
- **Response:** The county initiated an investigation to identify the owners; however, as of the report, the operator remains unidentified.
## Attack Methodology
- **Initial Access:** Physical deployment of IoT surveillance hardware.
- **Persistence:** Unauthorized placement in public/private spaces, masquerading as legitimate public safety infrastructure.
- **Defense Evasion:** Lack of identifying markers on the hardware; bypass of official permitting processes.
- **Collection:** Automated License Plate Recognition (ALPR) and visual metadata.
- **Exfiltration:** Likely cellular transmission (standard for Flock cameras) to an unknown cloud repository.
- **Impact:** Unauthorized mass surveillance of residents and visitors.
## Impact Assessment
- **Financial:** Minimal direct cost to the county, though removal and investigation costs may accrue.
- **Data Breach:** Compromise of locational privacy for citizens whose movements were tracked by unauthorized entities.
- **Operational:** Potential interference with legitimate law enforcement surveillance and public works management.
- **Reputational:** Public concern regarding government oversight of surveillance technology and the "normalization" of invasive infrastructure.
## Indicators of Compromise
- **Physical Indicators:** Unmarked Flock Safety camera units (LPRs) lacking county-approved permit stickers or documentation.
- **Network Indicators:** Unknown cellular data transmissions originating from public rights-of-way.
## Response Actions
- **Containment:** Audit of all known LPR locations within the county.
- **Investigation:** Outreach to Flock Safety and local municipalities to determine if the devices belong to a neighboring jurisdiction (suspected local government "shadow" deployment).
## Lessons Learned
- **Normalization Risk:** The widespread acceptance of surveillance tools makes it easier for unauthorized actors (foreign or domestic) to hide their own devices in plain sight.
- **Asset Management:** A lack of a centralized registry for authorized IoT devices in public spaces allows unauthorized hardware to go undetected for extended periods.
## Recommendations
- **Permit Auditing:** Implement a mandatory physical tagging system (e.g., QR codes or tamper-evident seals) for all authorized street-level IoT devices.
- **Vendor Accountability:** Require vendors like Flock Safety to provide a "master map" to county jurisdictions of all activated devices within their boundaries to cross-reference against permits.
- **Unauthorized Hardware Removal:** Establish a clear policy for the immediate decommissioning and forensic analysis of any hardware found in the public right-of-way without a valid permit.