Joshua Michael, a cybersecurity researcher, discovered that Flock Security's servers were publicly leaking an access token — no login required — that allowed anyone to query the company's ArcGIS-hosted geospatial database and retrieve the coordinates of every Flock surveillance device in the country. He contacted Flock three times in November 2025. Flock acknowledged the report, then went silent. Michael downloaded the data in December 2025 and published a searchable, color-coded map of roughly 300,000 devices this week. The map reveals a surveillance footprint substantially larger than Flock's own public claims. The company told press it operates more than 120,000 cameras. Michael's data, drawn from Flock's own records, shows over 170,000 cameras plus more than 130,000 supplementary devices — including 27,000 acoustic detection units and networking equipment that integrates third-party cameras. The Intercept visited six random Arizona locations on the map and confirmed a Flock camera at each one. The dataset exposes not just scale but placement. Some 860 devices cluster around Chicago O'Hare Airport at the Rosemont Public Safety Department. Cameras appear inside detention centers — one labeled "C-F-23 FOXTROT MALE HOLDING 2/SHOWERS" at Silverdale Detention Center in Chattanooga, Tennessee. Another, named "FBI Pilot Camera," sits at the J. Edgar Hoover Building in Washington. These entries, drawn from Flock's own naming conventions, illustrate how deeply the network has penetrated law enforcement and federal infrastructure. Flock's response timeline is damning. After Michael's three November 2025 contacts and his January 2026 blog post, Flock published its own January statement claiming it had "never been hacked" and had "not experienced a data breach." As Michael puts it: either Flock knew about the data exposure and chose not to disclose it, or Flock's detection capabilities failed to notice a researcher pulling their entire device database. Both options carry serious implications for a company selling security infrastructure to law enforcement and federal agencies. Rather than address the substance, Flock turned to suppression. On Thursday, Doppel — a firm describing itself as an "AI-native social engineering defense platform" — filed a trademark infringement complaint against Michael's site on Flock's behalf, claiming his use of the name "FLOCK SAFETY" could cause confusion. Michael had included a disclaimer on the site stating it is not affiliated with or endorsed by Flock. The complaint requests the site be taken down entirely. The findings were cited in Wednesday's Senate Subcommittee on Crime and Counterterrorism hearing on Flock. An ACLU report had already documented "a pattern of Flock regularly misleading or even lying about its business practices, safety record, commitment to privacy, and efforts to protect vulnerable populations." Michael's map provides the most granular evidence yet of that pattern — if it stays online. The core question here is structural: a private company has built a nationwide vehicle-tracking network used by law enforcement, federal agencies, and detention facilities, and the public has no effective mechanism for auditing its scope, accuracy, or security. The only reason the scale is now visible is because a researcher found an unauthenticated endpoint the company left open. Flock's instinct — silence, denial, then legal takedown — tells you everything about the accountability gap.