Flock Plans Rideshare Dashcams and Coaches Police, Reveals Leak

The surveillance company Flock Safety is expanding into rideshare dashcams and coaching police to secure contracts, according to a leaked report.

By Central
A former employee alleges Flock Safety gave ICE direct camera access while denying it internally.
Highlights
  • Flock Safety is expanding into rideshare dashcams to capture video and audio during trips.
  • The company coached police on how to manipulate city council meetings to secure contracts.
  • A former employee claims Flock Safety gave ICE direct camera access despite internal denials.

The surveillance technology company Flock Safety, best known for its automated license plate readers that have become ubiquitous in American suburbs, is planning to expand into rideshare dashcams and has been secretly coaching police on how to manipulate city council meetings to secure contracts, according to revelations published this week. The disclosures, which also include a former employee alleging the company lied about granting direct camera access to Immigration and Customs Enforcement and Customs and Border Protection, paint a picture of a company aggressively expanding its reach while managing its public image with precision tactics that extend into the political process itself.

Flock Safety has already installed its camera networks in thousands of communities across the United States, typically marketed as a tool for solving property crimes and catching stolen vehicles. The company’s technology captures license plate data from every vehicle that passes through its network, storing that data for a period of time and making it searchable by law enforcement. The new revelations suggest the company is now moving into adjacent markets and deploying sophisticated public relations strategies to overcome local resistance.

Flock’s Rideshare Dashcam Ambitions Signal Broader Surveillance Expansion

The rideshare dashcam initiative represents a significant strategic pivot for Flock, moving beyond fixed infrastructure into mobile surveillance systems that could accompany drivers for Uber, Lyft, and other ride-hailing services. Dashcams mounted in rideshare vehicles would capture continuous video and potentially audio of every trip, creating a vast new data stream that Flock could integrate with its existing license plate recognition network. This would effectively extend the company’s surveillance reach into the interior of vehicles and onto routes that fixed cameras never cover, filling gaps in the current system with data collected by private drivers.

The implications for privacy are substantial. Rideshare trips are inherently transactional, but passengers do not typically expect their conversations, behavior, and travel patterns to be recorded and analyzed by a third-party surveillance company with strong ties to law enforcement. If Flock’s rideshare dashcams feed data into the same backend systems that power its police-facing products, the distinction between voluntary rideshare participation and involuntary surveillance becomes dangerously blurred. Drivers might be incentivized or required to install the cameras, and passengers would have no meaningful choice about whether to be recorded.

Former Employee Alleges Flock Gave ICE Direct Camera Access While Denying It Internally

Jonathan Paz, a former Flock government affairs manager, told 404 Media that he quit in July 2025 and turned down equity and severance after learning that the company had given ICE and CBP direct camera access through a pilot program. The allegation is particularly damaging because Paz claims Flock told its own staff internally that it did not work with ICE, even as a pilot program granting direct access to federal immigration enforcement agencies was already underway.

Direct camera access is a significant escalation from the standard law enforcement partnerships Flock maintains with local police departments. It means that ICE and CBP agents could pull live or historical footage from Flock cameras without going through local police channels, effectively giving federal immigration authorities a direct pipeline into the surveillance networks that Flock has installed in cities and towns across the country. Many of those communities likely believed their Flock cameras were serving local law enforcement, not federal immigration agents.

Paz’s decision to walk away from equity and severance suggests the discrepancy between Flock’s internal messaging and its actual practices was serious enough to constitute a breach of trust that he could not reconcile with continued employment. Equity in a privately held company valued at billions of dollars is not something employees surrender lightly, making his departure a strong signal that the issue cut to the core of the company’s integrity.

Leaked Coaching Guide Shows Flock Teaches Police to Control City Council Narratives

Separately, a leaked coaching guide obtained by 404 Media reveals the specific tactics Flock teaches police to use when presenting the company’s technology to city councils and other local governing bodies. The guide instructs officers to brief council members and city managers privately before public meetings, a practice that effectively preempts public debate and locks in support before the community has a chance to raise concerns.

The guide also advises officers to come with a scripted presentation, which reduces the likelihood of straying into unvetted territory or being caught off guard by questions about privacy, data retention, or civil liberties. More significantly, it tells officers to shift the argument from cost to “the cost of unresolved crime,” a framing that reframes the debate in emotional terms that are difficult for elected officials to oppose. No council member wants to be seen as voting against public safety, and the cost-of-unresolved-crime framing makes opposition to the surveillance system appear tantamount to opposing crime reduction itself.

These tactics are not illegal, but they raise serious questions about the democratic process by which communities decide whether to adopt surveillance technology. When the company selling the equipment is also scripting the presentations that police give to city councils, and when those presentations are delivered in private sessions before the public has a chance to weigh in, the entire decision-making process becomes tilted in favor of approval. The public is left reacting to a fait accompli rather than participating in a genuine debate about whether the technology is appropriate for their community.

How the Coaching Guide Undermines Democratic Oversight of Surveillance Contracts

The coaching guide effectively turns police officers into sales representatives for Flock, blurring the line between law enforcement’s duty to protect public safety and the company’s interest in selling more cameras. Police departments are trusted sources of information for city councils, and when that trust is weaponized to sell a specific product, the public interest suffers. The guide’s emphasis on private briefings before public meetings is particularly concerning because it allows Flock and its allies to shape the narrative before opponents have a chance to organize or present counterarguments.

This strategy mirrors tactics used by other surveillance technology vendors, but the leaked guide offers unusually direct evidence of the specific techniques employed. The shift from cost to cost-of-unresolved-crime is a classic rhetorical move that relies on the difficulty of quantifying the harms of mass surveillance against the easily understood costs of actual crime. A city council member trying to weigh the privacy implications of a camera network against the emotional appeal of a victim’s story is almost certain to choose the cameras, especially when the presentation has been scripted by the company that profits from the decision.

Flock’s Surveillance Network Already Faces Growing Scrutiny

Flock Safety has faced increasing criticism from privacy advocates, civil liberties groups, and some local governments concerned about the scope of its data collection and the lack of transparency around how that data is used. The company’s license plate readers are typically mounted on streetlights, traffic poles, and other public infrastructure, and they capture data on every vehicle that passes, not just those suspected of criminal activity. This means that law-abiding citizens are routinely tracked, and their location data is stored in Flock’s systems for extended periods.

The company has argued that its technology is narrowly focused on solving crimes and that its data retention policies are designed to balance privacy with public safety. But the new revelations about the ICE pilot program and the coaching guide suggest that the company’s actual practices may be more aggressive than its public statements suggest. If Flock is willing to give ICE direct camera access while telling its own employees it does not work with the agency, and if it is willing to script police presentations to city councils, then its claims about privacy protections and community engagement cannot be taken at face value.

Critical Infrastructure Under Fire: Cyberattacks on US Water Systems Hit 12 States

While Flock’s surveillance expansion raises concerns about privacy and democratic governance, a separate but related set of cybersecurity incidents highlights the vulnerabilities in the physical infrastructure that Americans depend on every day. Cyberattacks on US water systems have now hit utilities in at least 12 states, according to reporting that expands on the seven states the FBI acknowledged a week earlier. The affected states include Michigan, Minnesota, Georgia, New Jersey, and South Dakota, among others not yet publicly identified.

The attacks are not merely theoretical intrusions into administrative networks. In several cases, hackers reached the industrial control systems that operate pumps, valves, and pressure controls directly. The Clayton County Water Authority in suburban Atlanta, which serves 300,000 people, experienced an intrusion last month that dropped water pressure and forced a boil-water advisory. Although service returned within hours, the incident demonstrated that attackers can disrupt critical water infrastructure in ways that directly affect public health and safety.

Some utilities lost remote control of their systems entirely and had to operate equipment by hand, a dramatic step backward in operational capability that underscores the severity of the intrusions. The hackers were able to reach the same types of industrial controllers that the CyberAv3ngers group, tied to Iran’s Revolutionary Guard, exploited in 2023 by using factory-default passwords that had never been changed. Despite repeated warnings from federal agencies, many utilities continue to operate with weak security configurations that make them easy targets for sophisticated adversaries.

The July 30 Federal Alert and What It Tells Utilities to Do

On July 30, the FBI, the Environmental Protection Agency, and the Cybersecurity and Infrastructure Security Agency issued a joint alert telling utilities to disconnect their industrial controllers from the internet and to tighten passwords and firewalls. The controllers in question are small computers that run physical equipment like pumps and valves, and they are often connected to the internet for remote monitoring and maintenance. That convenience comes at a steep security cost, as the attacks have repeatedly demonstrated.

Federal investigators still suspect Iran-backed hackers are behind the water system intrusions, but they have made no formal attribution. The lack of attribution is itself significant, as it suggests the attackers have covered their tracks effectively or that the evidence trail does not point definitively to a single state sponsor. The ambiguity makes it harder for utilities to assess their threat profiles and for federal agencies to coordinate a response.

Officials have emphasized that drinking water has remained safe throughout the incidents, but this reassurance is cold comfort for communities that have lost water pressure or been forced to boil water for days. The attacks are not yet causing catastrophic failures, but the trajectory is clear: adversaries are probing critical infrastructure, and they are finding persistent vulnerabilities that can be exploited with relatively low effort.

Defense Contractor IEH Corp Breached Through Phishing Attack on Microsoft 365

In a separate incident that underscores the vulnerability of sensitive supply chains, IEH Corporation, a Brooklyn manufacturer that supplies electrical connectors to defense and aerospace programs, disclosed to securities regulators that an intruder broke into a company email account. The breach began when an employee received a message from someone posing as a prospective business contact with a legitimate-looking Microsoft file-sharing link. The link led to a fake login page that captured the employee’s credentials, handing the attacker access to the company’s Microsoft 365 environment.

Once inside, the intruder could reach email, attachments, customer correspondence, purchase orders, engineering documentation, and potentially technical information covered by US export controls. Export-controlled material cannot be legally shared with foreign nationals without a license, meaning that if the attacker exfiltrated this data, the breach could have national security implications far beyond the typical corporate data theft.

IEH connectors are used in the Patriot air-defense system, AMRAAM and THAAD missiles, and the Mark 48 torpedo, making the company a high-value target for foreign intelligence services. The disclosure came in an 8-K form filed with the Securities and Exchange Commission, the standard mechanism for public companies to report significant events. IEH said it found the intrusion on August 4 and has not said how long the attacker was inside. The company reported no evidence that data was copied out, though Microsoft 365 logging does not reliably capture theft, and no one has attributed the attack.

This incident is a textbook example of the supply chain risk that pervades the defense industrial base. A single employee clicking on a plausible phishing link can give an adversary access to technical data about weapons systems that are central to American national security. The attacker did not need to breach a heavily guarded facility or compromise a sophisticated network. They simply needed to impersonate a business contact and trick someone into typing their password into a fake page.

Ransom Cartel Creator Sentenced to 16 Years in Federal Prison

In a positive development for law enforcement, Maksim Silnikau, a 40-year-old Belarusian national who built and ran the Ransom Cartel ransomware operation, was sentenced to 16 years in prison. Prosecutors said the group attacked at least 18 companies between 2021 and 2023, targeting a range of victims including law firms, schools, a small medical technology startup, and multinational corporations in California, New York, and Nebraska.

Silnikau had been active on Russian-speaking cybercrime forums since 2005 and started recruiting for Ransom Cartel in 2021. According to the US Department of Justice, he supplied the people who carried out the attacks with stolen passwords and the software to lock victims’ computers, and he built a control panel for tracking break-ins, communicating with victims, and negotiating ransom payments. Some of the targets were knocked offline for months, and the group attempted to extract at least $5.2 million from its victims.

The 16-year sentence is notable both for its length and for the signal it sends to other ransomware operators. Silnikau was not a low-level affiliate; he was the architect and operator of the entire scheme. His prosecution demonstrates that US law enforcement has the capability and the will to pursue ransomware operators across international borders, even when they are based in countries with limited extradition treaties. The sentence also reflects the severity of the harm caused by ransomware attacks, which can cripple small businesses, disrupt schools, and delay medical care.

However, the Silnikau case is also a reminder of how much work remains. Ransomware attacks continue to proliferate, and the operators are often based in jurisdictions where US law enforcement has limited reach. The Ransom Cartel was just one of dozens of ransomware groups operating at any given time, and while taking down a major operator is a significant victory, it does not address the structural factors that make ransomware so profitable and so difficult to eradicate.

The Convergence of Surveillance, Cyberattack, and the Erosion of Trust

Take together, the stories from this week reflect a broader pattern in which technology companies, state actors, and cybercriminals are all pushing the boundaries of what is possible, often at the expense of privacy, security, and democratic processes. Flock’s rideshare dashcam plans and its coaching guide for police represent a commercial strategy that treats local governance as a hurdle to be managed rather than a process to be respected. The water system attacks and the IEH breach demonstrate that critical infrastructure remains dangerously exposed to adversaries who are willing to exploit even the simplest vulnerabilities. And the Silnikau sentencing shows that law enforcement can achieve results, but only after the damage has been done.

What is missing from this picture is a coherent public policy response that matches the scale of the challenges. Surveillance technology is being deployed with minimal oversight, critical infrastructure is being operated with security practices that would be unacceptable in any other industry, and the supply chains that support national defense are one phishing email away from compromise. The federal government has issued alerts and guidance, but it has not mandated the kinds of changes that would actually prevent these incidents from recurring.

For communities considering Flock cameras or any other surveillance technology, the leaked coaching guide should serve as a warning that the pitch they hear from their local police department may not be the product of independent analysis but rather a carefully scripted presentation designed to minimize opposition and maximize approval. The question that council members and citizens should ask is not whether the technology can reduce crime, but whether the process by which the decision is being made is genuinely democratic or whether it has been captured by the vendor’s strategic communications.

For utilities, the message from the water system attacks is unmistakable: industrial controllers should not be connected to the internet without robust security controls, and default passwords are an invitation to disaster. The cost of implementing these security measures is negligible compared to the cost of a prolonged service outage or a contamination event.

And for the defense industrial base, the IEH breach is a reminder that security is only as strong as the weakest link in the supply chain. A small manufacturer in Brooklyn may not seem like a high-value target, but the technical data it holds about missile systems makes it exactly that. The attacker who got in through a fake Microsoft login page did not need to target a prime contractor or a military facility. They found a path through the periphery, and that was enough.

Share This Article