Somebody Stole the Camera's Source (09/16/2026)

September 16, 2026
Somebody Stole the Camera's Source (09/16/2026)
Key Intel / TL;DR
  • Hackers extracted the software from Flock cameras, exposing how the system actually tracks cars and people.
  • Boston canceled its Flock contract after the company shared city data nationwide in violation of a contract term.
  • ShinyHunters published thousands of Florida driver records after the state declined to pay a ransom.
  • An ICE contract revealed the nationwide architecture behind a little-known HSI tracking program.
  • Login.gov has begun assigning browsers a persistent identifier tied to analytics including IP address.

Three separate things happened to the same surveillance company today, and together they describe a system losing control of itself from every direction at once. Its code was extracted, one of its largest municipal customers canceled over a contract breach, and a state database full of the records these systems query had its contents published.

Top 5 Critical Privacy Alerts

1. The Camera Software Was Extracted and Read

A group of hackers pulled the software off Flock cameras and published an account of how the system actually tracks cars and people, which moves the conversation from what the vendor says the product does to what the code does. Communities debating these deployments have been arguing from marketing material and contract language, because no independent party had the artifact. An extraction like this is the first time the technical claims become checkable by somebody outside the company. 404 Media has the reporting.

2. Boston Canceled After Data Went Nationwide

Boston abandoned its plate reader deployment after city officials determined the company shared Boston data nationwide in violation of a contract provision. The contract said the data stays local, the data did not stay local, and the city found out afterward. That sequence is the one every municipality signing one of these agreements should read closely, since the protection they negotiated existed on paper and was discovered to be unenforced only after the sharing had happened. PogoWasRight has the cancellation.

Operator Note: Any contract term restricting where your data may go needs an audit right attached to it, because a term you cannot verify is a term you will only test after it has been broken.

3. The Florida Records Were Published

ShinyHunters leaked thousands of driver records taken from the Florida motor vehicle database after the state agency declined to pay a ransom demand, completing the incident we covered on Friday. The state made a defensible decision and the people in the database absorbed the consequence, which is the structural problem with ransom in a government dataset. Nobody in those files chose to be there and none of them had a say in the negotiation. TechCrunch has the leak.

4. An ICE Contract Exposes a Nationwide Tracking Architecture

A relatively small Immigration and Customs Enforcement contract revealed unusually specific detail about a little-known Homeland Security Investigations program that centrally manages the agency’s tracking capability nationwide. Procurement documents keep turning out to be the most informative public record of surveillance programs, because the technical requirements have to be written down for a vendor to bid. The contract is where the architecture has to become describable, because a vendor cannot bid on a capability nobody has written down. Biometric Update has the analysis.

5. Login.gov Started Assigning Browsers a Persistent ID

The federal identity platform has quietly begun attaching a persistent identifier to browsers, tied to analytics that include IP address, as the government pushes Login.gov toward being the common gateway for online public services. A persistent identifier on the single sign-on for federal services links a person’s sessions across every agency that platform fronts. The word quietly is doing a lot of work in that sentence, and it is the part worth objecting to. Biometric Update has the change.

Operator Note: When you add analytics to an authentication flow, write down whether the identifier survives logout and across properties, because that single property is what turns measurement into tracking.

Additional Privacy Alerts

Courts

  • A court ruled that embedding links is legal under a new test: Two decades of precedent holding that linking and embedding do not infringe copyright survived a significant challenge. EFF

International Transfers

  • Kenya published cross-border data transfer guidance: The Office of the Data Protection Commissioner issued detailed guidance notes on September 8, using familiar concepts with local differences that matter for anybody operating there. Inside Privacy

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Jeff Welch
Chief Executive Officer
Jeff Welch
Architect of the 'Cognitive Firewall.'

A PhD candidate in Health Psychology and former Corrections Officer, Jeff founded GTA to dismantle passive security models. He focuses on the 'Human Zero-Day', mitigating executive burnout and decision fatigue before they become security breaches.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)