Just after noon on a Saturday last month, a Skydio X10 quadcopter hovered roughly 200 feet above a San Francisco apartment complex, tracking a man who had fled from his vehicle. The drone had already followed him across the city, zooming in on his SUV’s license plate and keeping the vehicle centered in its video frame until he pulled over. Now, as police closed in, the suspect hid behind a parked car, unaware that a second Skydio drone had arrived to cover the scene from another angle. Within seconds, officers converged, weapons drawn, and tackled him. The entire street-and-sky response stemmed from what the San Francisco Police Department described as an alleged “auto boost/strip” incident — the suspected theft of car parts from a vehicle. The footage of this takedown was not voluntarily released by the SFPD. It was accidentally livestreamed onto the open internet via Skydio’s own website, exposing the full reach of modern drone-enabled police surveillance to anyone who found the public web address.
How the San Francisco Police Drone Leak Exposed Live Surveillance Feeds
Security researchers Sam Curry and Maik Robert discovered that the SFPD was leaking all real-time footage from five of its surveillance drones, including both color and thermal video, along with accompanying location metadata and the drone pilots’ names and email addresses. The feeds were hosted at a fully public web address on Skydio’s platform. Anyone who stumbled upon the URL could watch police operations as they happened: multiple arrests, vehicle pursuits, apartment visits, and searches of alleyways populated with homeless individuals. The researchers reported the exposure to Skydio within two days, and the feed was taken offline shortly after. By then, however, they had archived a substantial portion of the data.
What Was Exposed in the Drone Feed: Scope and Scale of the Data Leak
The archive captured by Curry and Robert provides a detailed record of SFPD drone operations over approximately 48 hours in mid-June. It includes 60 videos from 20 separate flights, with each mission recorded from three camera feeds: a color camera, a thermal camera that renders people as heat signatures, and a third view from the drone’s rooftop dock. Automated analysis of the color footage detected hundreds of people and vehicles across the 20 flights. In a single frame, as a drone hovered over a downtown intersection, the software counted 34 people crossing the street or standing on the sidewalks. The videos clearly showed the faces of dozens of individuals. The archive also contains second-by-second telemetry logs for every flight — more than 5,000 GPS points tracing over 44 miles — recording each drone’s latitude, longitude, altitude, speed, heading, and battery level from takeoff to landing. Six SFPD pilots’ names and email addresses appeared across the logs.
Why This Drone Surveillance Leak Raises Serious Privacy Concerns
The leak is not merely a technical glitch. It reveals the operational reality of aerial surveillance in a major US city. Police drones can follow a suspect across town, track a vehicle’s license plate in real time, and coordinate multiple quadcopters to maintain coverage from different angles. The footage captured two forced detentions, a police visit to an apartment in a high-rise building, and an apparent search of an alley where homeless people were present. Because the feed was publicly accessible, any individual with the URL could observe these operations live, including the faces of bystanders, residents, and suspects. “There’s a certain trust given to the police to use these things correctly,” Curry said. “When you’re watching a drone feed live, you can look into dozens of different apartments, you can see police zooming in on people, you can see arrests. The fact that all of this was exposed feels like a really big issue from a privacy perspective.”
What Does the Skydio Drone Data Leak Mean for Civil Liberties?
This incident demonstrates that the technical infrastructure for police drone surveillance can fail in ways that expose sensitive operations and the private lives of citizens. The metadata alone — GPS coordinates, flight paths, pilot identities — provides a detailed map of police surveillance patterns across the city. When combined with live video, the exposure creates a real-time window into law enforcement activities that most police departments, including the SFPD, rarely release voluntarily, even in response to public records requests. The breach underscores the gap between the trust placed in police to use surveillance technology responsibly and the actual security measures protecting that data.
What Affected Users Should Do Now
While this specific leak has been closed, the incident is a reminder that surveillance infrastructure can expose personal data inadvertently. Anyone concerned about their privacy in areas where police drones operate should take practical steps to protect themselves. Use a reputable VPN service with a verified no-logs policy and AES-256 encryption when accessing the internet from public or unsecured networks to prevent location tracking and data interception. Enable two-factor authentication on all accounts that support it, and monitor financial accounts and credit reports for signs of identity theft if you believe your personal information may have been exposed. Consider contacting local representatives to advocate for clear oversight policies regarding police drone operations, including requirements for encryption, access controls, and public transparency. The most effective defense against surveillance exposure is a combination of strong personal security practices and informed civic engagement.