Back to all lessons
Awareness Lessons
4 weeks ago

Physical Camera Compromise Exposes Millions of License Plate Images and Encryption Keys

Hackers physically accessed a Flock Safety surveillance camera and extracted its onboard storage, recovering an encryption key and millions of vehicle and pedestrian images — data that was never intended to be accessible at the device level. The root cause lies in poor device hardening: encryption keys stored alongside the data they protect offer no real security, and physical access to the device yielded full access to sensitive records. This matters because surveillance infrastructure operates at the intersection of physical and cyber security, and a compromise of one camera can expose the operational logic and data of an entire network. The incident also reveals that these systems collect far more data than publicly disclosed, raising serious privacy and civil liberties concerns.

Tactical Insight

Immediate actions

  • Audit all deployed edge/IoT cameras to confirm encryption keys are stored in secure hardware enclaves (e.g., TPM chips) and never co-located with the encrypted data.
  • Conduct a physical security review of all deployed camera units to ensure tamper-evident seals and physical access controls are in place.

Long-term improvements

  • Implement a Zero Trust architecture for IoT devices so that physical compromise of a single unit cannot expose broader system data or credentials.
  • Enforce strict data minimization policies, ensuring cameras retain only the minimum data necessary and purge records on a defined schedule.
  • Require third-party penetration testing — including physical attack simulations — for all surveillance hardware before and during deployment.

Detection measures

  • Deploy tamper-detection alerts that notify operators immediately when a device is opened or storage is accessed outside normal operational parameters.
  • Establish continuous integrity monitoring of device firmware and configuration to detect unauthorized changes resulting from physical or remote compromise.