TL;DR
Get privacy and security gear delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
A map published by cybersecurity researcher Joshua Michael plots more than 300,000 Flock devices using location data he says came from the company’s records. The Intercept reported that a company called Doppel filed a trademark complaint concerning the site; the supplied reporting does not establish who filed it on Flock’s behalf or whether the map was taken offline.
Cybersecurity researcher Joshua Michael published a map plotting more than 300,000 devices associated with surveillance company Flock Safety, and The Intercept reported that a company called Doppel filed a trademark complaint concerning the site. The map uses location coordinates from a snapshot of Flock’s own records, according to the report; the complaint’s full details and the map’s current status are not established in the supplied material.
The map identifies more than 170,000 cameras and more than 130,000 accompanying devices across the United States, based on location data Michael says he obtained from Flock’s records. The dataset includes about 27,000 acoustic detection devices and networking equipment used to connect third-party cameras. Flock told the press this summer that it operated more than 120,000 cameras nationwide, The Intercept reported. Those figures describe different categories: the map includes devices beyond cameras.
The project differs from crowd-sourced camera maps, including DeFlock, because it relies on a snapshot Michael archived in December 2025 rather than locations submitted by users. The Intercept said it checked six randomly selected locations in Arizona and found a Flock camera at each indicated location. The map also labels device models and includes a searchable table with names drawn from Flock’s database. Some labels appear to identify specific sites, including one listed as “FBI Pilot Camera” at the FBI headquarters in Washington.
The map’s findings were cited at a Senate Subcommittee on Crime and Counterterrorism hearing on Flock. Separately, The Intercept reported that Doppel, which describes itself as an AI-based social engineering defense platform, filed a trademark infringement complaint regarding Michael’s site. The supplied account cuts off before explaining the complaint’s full basis or the company’s claimed relationship to Flock. Flock did not immediately respond to The Intercept’s request for comment about the map.
A Wider View of Flock’s Network
The map offers a view of Flock’s reported device footprint that is broader than camera counts alone. By including acoustic sensors and networking equipment, it shows how a surveillance system can involve multiple kinds of hardware distributed across public agencies and other locations. That scope matters to residents and officials assessing where devices may be operating and what kinds of data collection could be involved.
The published names and coordinates also raise questions about how much operational detail should be publicly searchable. Michael’s map makes individual entries easier to inspect, while the underlying data came from records he says were accessible without logging in. The report does not establish that every location or device label remains current, or that each device is active. Readers should treat the map as a representation of the archived dataset, not a live inventory.
The complaint adds a separate dispute over the site itself. A trademark claim may affect the project’s availability, but the source material does not say whether a court or platform acted on it. The public interest in understanding a surveillance network now intersects with unresolved questions about data security, disclosure and the right to publish information derived from exposed records.
How the Location Data Emerged
Michael told The Intercept that in November 2025 he found an access token exposed through Flock’s website. He said the token allowed queries to ArcGIS, a geographic information system platform used by Flock, to retrieve device locations without a login. He said he contacted Flock three times that month. In an email quoted by the report, he described his testing as “strictly non-intrusive” and said it did not involve bypassing authentication or modifying data.
According to Michael, Flock replied that it was “internally triaging” his findings, but did not later provide him with an update. He downloaded the location data in December and published a technical post in January. The Intercept said the vulnerability appeared to have been fixed after that post. Flock wrote in January that its cloud platform had not experienced a data breach and that “there has not been a leak of Flock information.” Michael disputes the company’s public characterization, saying it came after he had retrieved the device database. The report does not independently establish what Flock knew or when.
““These cameras form a nationwide surveillance network that tracks where everyone drives.””
— Joshua Michael, speaking to The Intercept
Questions Around the Complaint
The available reporting does not provide the full complaint, explain precisely what trademark rights Doppel says are involved, or establish whether it filed on Flock’s behalf. The report’s final account is incomplete, so the complaint’s requested remedy and any response from Michael remain unknown. It is also unclear whether the map has been removed, restricted or remains accessible.
Other key details are unresolved. Flock did not immediately comment to The Intercept on the map. The supplied material does not say whether the company notified customers or authorities about the exposed token, how long it was available, or whether anyone besides Michael accessed the location records. Nor does an archived December snapshot establish the network’s present size or the current operating status of each listed device. Claims about surveillance or security implications should be distinguished from what the map itself documents: device coordinates and database labels.
The Site and Security Response
The next concrete developments depend on the complaint and any response from Michael, Doppel or Flock. The supplied report does not identify a hearing date, court filing or deadline, so no timetable for resolving the trademark dispute can be confirmed. The Senate hearing’s citation of Michael’s findings may also lead to further questions from lawmakers about the mapped network and Flock’s handling of the exposed access token.
Further reporting or statements from Flock could clarify whether the company investigated the access issue, what it disclosed to customers, and whether it disputes the map’s counts or entries. Until then, the map should be read as an analysis of an archived company dataset, while the complaint and the current availability of the site remain developing matters.
Key Questions
How many devices does the map show?
It plots more than 300,000 devices, including more than 170,000 cameras and more than 130,000 accompanying devices, according to The Intercept’s account of Michael’s map.
How did Michael obtain the location data?
Michael told The Intercept that an exposed access token on Flock’s website let him query location records held through ArcGIS without logging in. He said he notified Flock in November 2025 before archiving the data in December.
Was the map taken offline?
The supplied reporting says Doppel filed a trademark complaint concerning the site, but it does not confirm that the map was taken offline or describe its current availability.
Did Flock confirm a data breach?
No. Flock said its cloud platform had not experienced a data breach. Michael said he had retrieved the device location data, but the supplied material does not establish what Flock knew, whether other parties accessed it, or how the company classified the incident.
Source: hn
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
