Research Blog, Reference Library, Data Repository

Flock in Reverse: SparrowMap Tracks Police Cars. Fusion Centers Are Watching.

SparrowMap is an open-source counter-surveillance network built to identify and publish police-vehicle sightings. A Massachusetts fusion center has now included the project in an intelligence product even while saying it had no indication of criminal intent in the state. The deeper story is not that activists stole Flock. It is that automated vehicle surveillance is beginning to work in both directions.
A composite image of highway traffic, police vehicles, surveillance cameras, monitoring screens, and a smartphone map interface tracking a police car at night.
Contents

SparrowMap is a real open-source counter-surveillance project that uses volunteer cameras and other sensors to identify police vehicles and publish selected sightings to a public map. Government intelligence centers are now documenting that activity. But the viral version of the story needs an important correction: SparrowMap is not stolen Flock software, and the hackers who recently reverse-engineered a Flock camera are a separate group.

The more consequential story is that automated vehicle surveillance is becoming reciprocal.

For years, systems such as Flock Safety have made it possible for police agencies to turn ordinary vehicle observations into searchable location records. SparrowMap is attempting to apply part of that same logic in the opposite direction: cameras watch public roads, software identifies likely police vehicles, humans review the candidates, and confirmed sightings can become publicly visible.

At the same time, Reason obtained a Massachusetts Commonwealth Fusion Center intelligence product discussing online calls to monitor government vehicles and the use of SparrowMap. The document reportedly said the information was being circulated for "situational awareness."

The same product also contained the most important sentence in the story: according to Reason, the Commonwealth Fusion Center said it had no indication that threat actors in Massachusetts intended to use the information for criminal or nefarious purposes.

That does not prove improper surveillance by the government. It does create a legitimate question about how far law-enforcement intelligence collection should extend from actual sabotage, threats or interference into lawful political opposition and public counter-surveillance.

And SparrowMap itself deserves similar scrutiny. Its developers have built meaningful privacy protections for ordinary motorists, but a review of its public code shows that the simple description "civilian data is deleted" leaves out an important detail: the system can temporarily correlate repeat sightings of the same private vehicle through a keyed hash even though it does not retain the readable civilian plate number.

The result is a much more complicated story than "activists built Flock for cops."

What Is SparrowMap?

SparrowMap describes itself as a volunteer-run system for monitoring government vehicles on public roads.

A contributor can point a compatible camera at a street. The architecture is designed to keep raw video on the contributor’s device. Depending on the contribution path, local software performs detection and privacy filtering while small detection events or plate-illegible crops can be sent onward for classification and review. A suspected police vehicle is not supposed to become a public police record solely because an automated classifier says so. The project says a human reviewer must confirm the classification before publication.

The public map currently exposes government-vehicle sightings and also advertises layers involving Flock and other ALPR camera locations, police stations, radar detections, government aircraft, drone Remote ID, police-radio activity and patrol hotspots. Several of those functions are explicitly labeled beta or staged, so they should not all be treated as equally mature capabilities. SparrowMap’s current guides nonetheless show that the project is already expanding beyond a simple license-plate-reader mirror.

Its emerging model is better described as a distributed counter-surveillance platform.

That matters because the public-policy question changes as the system becomes more capable. A map that occasionally records a marked patrol car is one thing. A platform that can combine vehicle sightings with cameras, aircraft, drones, radio activity and other sensors can reveal considerably more about patterns of government activity.

What Did the Fusion Center Actually Do?

The government side of this story also needs precision.

Reason reported on September 23 that an intelligence product compiled in Massachusetts and redistributed through a Wisconsin fusion center discussed SparrowMap and online advocacy for tracking government and law-enforcement vehicles.

The document reportedly said that users had mapped government-vehicle movement through SparrowMap and that the Commonwealth Fusion Center was providing the information for situational awareness. It then stated that the center had no indication of criminal or nefarious intent by threat actors within Massachusetts.

Those facts establish that SparrowMap-related activity entered a law-enforcement intelligence-sharing system.

They do not establish that the Department of Homeland Security headquarters opened a criminal investigation into SparrowMap, that SparrowMap’s operators have been charged with a crime, or that every person discussing the project has become an investigative target.

That distinction matters because "fusion center" and "DHS" are often collapsed into one thing.

The Department of Homeland Security itself says state and major-urban-area fusion centers are owned and operated by state and local authorities. They participate in the broader homeland-security information-sharing system, but they are not simply field offices of DHS.

The Massachusetts Commonwealth Fusion Center is a program within the Massachusetts State Police Division of Homeland Security and Preparedness. Massachusetts describes it as the state’s principal repository for homeland-security, criminal-information and incident reporting and as an interface for sharing information with federal, state and local partners.

Executive Order 476 similarly designates the center as Massachusetts’ central fusion hub and primary interface with the federal government for information collection, analysis and dissemination.

So the strongest supported description is straightforward:

A Massachusetts State Police fusion center produced intelligence about SparrowMap-related activity, and that information circulated through the national fusion-center network.

Calling that "government monitoring" is fair.

Calling it a proven DHS criminal investigation is not.

The Most Important Detail: The Report Said It Had No Indication of Criminal Intent

There are legitimate reasons for law enforcement to monitor actual threats against surveillance infrastructure.

Flock cameras have been physically damaged, removed and sabotaged. Online accounts have circulated instructions for interfering with ALPR equipment. Police agencies do not have to pretend those acts are merely political speech when they cross into destruction of property or other crimes.

But the SparrowMap intelligence product is more interesting because, according to the language reported by Reason, the center simultaneously acknowledged that it had no indication of criminal or nefarious intent within Massachusetts.

That does not automatically make the intelligence product unlawful. Fusion centers issue situational-awareness products that are not necessarily criminal-intelligence files about a particular suspect.

Still, the distinction between monitoring criminal conduct and cataloging lawful political activity adjacent to criminal conduct has long been a civil-liberties fault line.

For covered criminal-intelligence systems, 28 C.F.R. § 23.20 provides a useful benchmark. It says criminal-intelligence information about an individual should be collected only when there is reasonable suspicion of criminal conduct, and it restricts collecting political, religious or social activities unless they directly relate to criminal conduct and the reasonable-suspicion standard is met. It also prohibits harassment or interference with lawful political activity as part of the intelligence operation.

That regulation does not mean every fusion-center situational-awareness bulletin is automatically governed by every provision of 28 C.F.R. Part 23. We do not yet know enough about the Massachusetts product’s precise classification, retention or downstream use to make that claim.

The unanswered question is therefore narrower and stronger:

Was SparrowMap information being retained as criminal intelligence, general situational awareness, officer-safety information, or something else?

That classification matters.

Government Monitoring of Anti-Flock Activity Predates SparrowMap

The SparrowMap report did not appear in a vacuum.

In August, 404 Media obtained fusion-center bulletins showing that law-enforcement intelligence centers were already monitoring anti-Flock social-media activity, warning agencies about calls to damage ALPR cameras, discussing devices capable of locating Flock equipment and tracking public DeFlock events.

Some of those bulletins dealt with actual vandalism or online encouragement to destroy cameras. That is a legitimate law-enforcement concern.

But the same intelligence ecosystem also discussed DeFlock’s political activities, including a national week of public meetings, marches and community organizing against automated license-plate readers. DeFlock’s creator, Will Freeman, told 404 Media that the project had never called for vandalism and that some destructive activity was being conducted by unrelated accounts using the DeFlock name without authorization.

That distinction is central to understanding the current story.

There is no single unified "anti-Flock movement" in which public-record activists, local organizers, people vandalizing cameras, security researchers and SparrowMap operators are all interchangeable.

Law enforcement may have good reason to investigate a person cutting down a camera pole.

That does not make everyone who maps a camera, opposes an ALPR contract or builds a lawful counter-surveillance system part of the same criminal enterprise.

SparrowMap Did Not Come From the Stolen Flock Camera

This is the other major correction to the viral narrative.

On September 16, WIRED and 404 Media published a forensic investigation of a physically compromised Flock camera. A hacker collective calling itself stegan0gram removed a Flock camera from a roadway, copied much of its storage and shared the material with journalists.

The recovered files provided an unusually detailed look inside the roadside device. Across about 21 days of recovered logs, the camera had generated roughly 1.6 million images associated with about 50,200 vehicle detections. Investigators also found more than 27,000 short video clips and computer-vision software capable of detecting vehicles, license plates, bicycles and people.

We examined those findings separately in Inside the Flock Camera Hack: What 1.6 Million Images Reveal About How the Cameras Actually Work.

One of the hackers summarized the group’s motivation to WIRED as preferring reverse engineering over simply destroying the equipment.

That development is relevant because it shows that opposition to surveillance technology is becoming technically sophisticated.

But we found no evidence that SparrowMap was built from the recovered Flock code, uses stolen Flock software, received the hacked camera files or is operated by stegan0gram.

The responsible way to connect the stories is therefore conceptual, not organizational:

  • DeFlock maps surveillance infrastructure.
  • Some unrelated actors have damaged or removed ALPR cameras.
  • stegan0gram reverse-engineered a Flock device.
  • SparrowMap built an independent open-source system for monitoring police vehicles.

They are part of the same broader conflict over automated surveillance.

They are not one project moving through four stages.

Is SparrowMap Really "Flock in Reverse"?

As a metaphor, partly. Technically, no.

Both systems use automated observations on public roads to turn passing vehicles into structured data. Both become more powerful when separate sightings can be connected across locations and time.

But their architectures, access rules and data-retention choices are materially different.

Question Flock Safety ALPR SparrowMap
Primary subject Passing vehicles generally Police/government vehicles selected for publication
Readable civilian plates Stored as part of the ALPR record Project code says readable private plate text is not stored
Civilian correlation Authorized users can search retained plate/vehicle records Private sightings can be temporarily linked internally through keyed hashes
Ordinary retention Flock now recommends/defaults new law-enforcement customers to 7 days, subject to local policy and preserved evidence Private-tier sightings default to 14 days in the public code
Government-vehicle records Handled within the same ALPR system Public tier; designed for persistent publication/search
Who can search target records Approved users under agency/customer controls Public government-vehicle data can be searched without an account
Search logging Flock says every law-enforcement search is logged SparrowMap says public searches are deliberately not logged
Raw video The compromised device contained short local clips; that does not mean all clips become searchable police records Project says raw video remains on contributor devices
Human review Depends on workflow; Flock requires human verification for some alerts/actions Project says police-vehicle publication requires human confirmation
Source code Proprietary Open source

Flock’s current law-enforcement access documentation says approved users must have defined investigative reasons, that searches are automatically recorded and that supervisors can review search activity.

Flock also announced in August 2026 that its recommended/default retention period for new law-enforcement customers was being reduced from 30 days to seven days, while agencies can have different periods based on local law or policy. Its current LPR policy describes a seven-day default.

SparrowMap makes almost the opposite governance choice: limit whose identifying information is retained, then make the selected government records broadly public.

That is not merely Flock with the labels switched.

SparrowMap’s Civilian Privacy Protections Are Real, but the Simple Version Is Incomplete

This is where SparrowMap deserves both credit and scrutiny.

Its public guide says ordinary vehicles are stripped of readable plate information and that private sightings disappear after 14 days. It also says raw video does not leave the contributor’s device and that only a human-confirmed government candidate can become a public government-vehicle record.

Our review of the public SparrowMap source code supports much of that description.

The project’s privacy.py file states that readable civilian plate text is never written to disk. Instead, a private plate is normalized and converted into a keyed hash. The stated purpose is to allow the same private vehicle to be recognized across cameras without storing its readable plate number.

The code adds two limits:

  • private sightings are deleted after a default 14-day window;
  • the secret key used to generate plate hashes rotates on a default 30-day cadence, preventing the same hash from becoming a permanent identifier.

The repository also deliberately disables a public lookup path for asking where a particular private plate has been seen.

Those are meaningful privacy controls.

But they also expose a subtle problem with the project’s simplest public wording.

The public guide says an ordinary vehicle has "nothing to correlate." Read literally, that is not true at the internal processing level. The system’s keyed hash exists specifically so repeat private-vehicle sightings can be correlated during the limited retention window.

The more accurate description is:

SparrowMap says it does not retain readable civilian plates or expose civilian plate histories to the public, but it does temporarily retain pseudonymous identifiers that can associate repeat sightings of the same private vehicle.

That does not make SparrowMap equivalent to Flock.

It means privacy-preserving surveillance is still surveillance infrastructure, and its protections should be judged by what the code actually does rather than by slogans from either supporters or critics.

There is one more limitation worth keeping in view: public source code tells us what the software is designed to do. It does not by itself independently prove that every live deployment is configured correctly at every moment. SparrowMap attempts to address that problem by publishing its code and a machine-readable policy endpoint and by claiming that the production code matches the public repository.

An independent security audit would still be valuable.

SparrowMap Is Already Expanding Beyond License Plates

Calling SparrowMap an ALPR project may soon be too narrow.

Its current site and documentation describe or preview systems involving:

  • Flock and other ALPR-camera locations;
  • volunteer road cameras;
  • radio-frequency detection of surveillance equipment;
  • radar or speed-trap detections;
  • police or government aircraft;
  • drone Remote ID;
  • police-radio activity;
  • patrol hotspots;
  • Tor access to the map.

Some of these features are beta, staged or dependent on local hardware. Their presence in documentation should not be confused with proof of nationwide operational coverage.

But the trajectory is clear.

SparrowMap is attempting to combine multiple inexpensive sensors into a public system for observing government activity.

That is technologically important because it demonstrates a broader shift: the same developments that made large-scale surveillance cheaper for institutions are also making counter-surveillance cheaper for individuals.

Computer vision is inexpensive. Consumer cameras are everywhere. Open-source software can perform recognition locally. Aircraft broadcasts, Remote ID and many other signals are already designed to be detectable.

The asymmetry is shrinking.

Why Would Police Be Concerned?

There are obvious legitimate concerns with a public system that aggregates law-enforcement movements.

A sufficiently accurate network could expose patterns in patrol coverage, reveal the presence of unmarked units, help someone infer an active operation or produce false accusations when a civilian vehicle is misclassified.

Public information can also become more sensitive when it is aggregated.

Seeing one marked police cruiser drive down a public road is ordinary observation. Building a searchable history of where that cruiser has appeared is something more powerful, even if every individual observation occurred in public.

That is the exact logic that makes ALPR surveillance controversial when police deploy it against civilians.

The important distinction is between risk and evidence of misuse.

The Massachusetts intelligence product, as reported, identified the risk while simultaneously saying it had no indication of criminal or nefarious intent within the Commonwealth.

Those two facts can coexist.

Authorities do not have to wait for a crime before thinking about officer-safety risks. But treating a capability as potentially useful to criminals is not the same thing as establishing that the people exercising it are criminals.

Why Are Civil-Liberties Advocates Concerned About the Government Response?

Because the category can expand very quickly.

The August fusion-center records obtained by 404 Media show how intelligence reporting about actual camera vandalism can sit alongside monitoring of lawful public meetings, marches and anti-ALPR organizing.

The risk is not imaginary in either direction.

If intelligence analysts ignore explicit plans to destroy equipment because those plans are wrapped in political language, they are not doing their jobs.

If they begin treating opposition to surveillance itself as an indicator of extremism, the intelligence system starts converting protected political activity into a suspicious trait.

That is why the SparrowMap bulletin’s reported caveat matters so much.

The government apparently recognized, at least in Massachusetts, that it did not have evidence of criminal intent.

What happened to the information after that acknowledgment is the question worth investigating.

Is SparrowMap Legal?

There is no evidence in the material reviewed for this article that SparrowMap itself has been declared illegal or that its operators have been charged merely for running the platform.

But saying "tracking police is legal" without qualification would go too far.

The law depends on what is recorded, where it is recorded, how the information is obtained, how it is used, whether someone interferes with official duties and what other conduct accompanies the observation.

In Massachusetts, the U.S. Court of Appeals for the First Circuit held in Glik v. Cunniffe that people have a First Amendment right to record police officers performing public duties in a public place, subject to reasonable restrictions and noninterference.

That is important precedent for ordinary public observation of law enforcement.

It does not directly decide whether every form of persistent automated aggregation by a distributed camera network receives the same constitutional protection under every circumstance.

Likewise, physically taking or destroying a privately or publicly owned ALPR camera raises legal questions entirely separate from viewing a police vehicle on a public road.

That is another reason the stegan0gram hack and SparrowMap should not be collapsed into one activity.

What We Know, What We Do Not Know

Claim Evidence status
SparrowMap publishes police/government-vehicle sightings. Verified. The live site and documentation describe the system and expose public sightings.
A Massachusetts fusion center discussed SparrowMap in an intelligence product. Verified through Reason’s obtained record and reporting.
The product said there was no indication of criminal or nefarious intent in Massachusetts. Reported from the intelligence product by Reason.
DHS headquarters opened a criminal investigation into SparrowMap. Not established.
SparrowMap is built from stolen Flock software. No evidence found.
stegan0gram and SparrowMap are the same group. No evidence found.
SparrowMap immediately destroys every trace of civilian vehicle detections. Incorrect if read literally. Readable plates are not retained, but keyed hashes can temporarily associate repeat private sightings.
SparrowMap’s privacy architecture is independently audited. Not established.
Fusion centers were monitoring anti-Flock activity before this SparrowMap report. Verified. Earlier records obtained by 404 Media document that monitoring.

The Larger Story Is the End of One-Way Surveillance

For most of the modern surveillance debate, the imbalance was obvious.

The state and large companies could afford cameras, databases, analysts, networking infrastructure and software capable of linking thousands or millions of observations. Ordinary people could photograph a police car, but they could not easily reproduce the institutional machinery that turned isolated observations into searchable movement histories.

That barrier is collapsing.

A cheap camera can run computer vision locally. Open-source software can classify objects. Distributed volunteers can contribute observations to one database. Public radio signals and aircraft broadcasts can be processed automatically. Machine learning can reduce the human labor needed to sort the results.

Flock demonstrated what happens when those capabilities are packaged for police departments.

SparrowMap is an early example of what happens when people outside government begin building comparable aggregation systems for watching the government itself.

The symmetry is not perfect. SparrowMap’s developers have intentionally chosen different retention, publication and privacy rules. Flock restricts who may search its database while broadly collecting vehicle observations. SparrowMap attempts to restrict whose identifying information is retained while making selected government records public.

But both systems expose the same underlying reality:

The most consequential part of modern surveillance is no longer the camera. It is the database behind the camera and the rules governing what gets connected, retained, searched and shared.

That principle does not become less important when the camera is pointed at the police.

If anything, SparrowMap makes the principle easier to see.

What Still Needs to Be Answered

Several material questions remain unresolved:

  • Who received the Massachusetts SparrowMap intelligence product?
  • Under what intelligence category was SparrowMap-related information retained?
  • Did DHS, the FBI or another federal agency request the reporting, or did it originate entirely at the state level?
  • Were specific SparrowMap contributors or users individually identified?
  • Has any criminal investigation been opened based on SparrowMap activity?
  • Which of SparrowMap’s beta sensor layers are actually operating at meaningful scale?
  • Does the live deployment always match the privacy configuration published in the repository?
  • Has an independent security researcher audited the system’s handling of civilian images, hashes and reviewer data?
  • Has SparrowMap data ever been shown to interfere with an active law-enforcement operation?
  • Has anyone been harassed or harmed using information obtained from the platform?

Those are answerable questions.

They are also more important than reducing the story to whether one side is entitled to surveil the other.

The infrastructure is moving toward a world in which both sides can.

The harder argument is over the rules that should apply when they do.

References and Further Reading

Government and Legal Sources

Department of Homeland Security — Fusion Centers and Emergency Operations Centers
DHS’s own description of fusion centers, including the important clarification that state and major-urban-area fusion centers are owned and operated by state and local authorities.

Massachusetts State Police — Commonwealth Fusion Center
Official description of the Massachusetts CFC’s structure, responsibilities, intelligence functions and connections with federal, state and local partners.

Massachusetts Executive Order 476 — Designating the Commonwealth Fusion Center
Establishes the CFC as Massachusetts’ central fusion hub and primary interface with the federal government for information collection, analysis and dissemination.

28 C.F.R. § 23.20 — Operating Principles for Criminal Intelligence Systems
Federal rule governing covered criminal-intelligence systems, including reasonable-suspicion requirements and restrictions concerning lawful political, religious and social activity.

Glik v. Cunniffe — U.S. Court of Appeals for the First Circuit
Leading First Circuit decision recognizing a protected right to record police carrying out public duties in public spaces, subject to reasonable restrictions.

SparrowMap Primary Sources

SparrowMap — How It Works
The project’s own explanation of its camera architecture, human-review process, public/private data tiers and privacy promises.

SparrowMap — Current Guides
Current documentation covering camera contribution and beta sensor functions including radar, aircraft, drones and police-radio activity.

SparrowMap — Public Source Code
Open-source repository used to examine how private-tier plate hashing, retention and other privacy controls are implemented.

SparrowMap privacy.py
Primary source for the project’s keyed civilian-plate hashing, retention logic and hash-key rotation design.

Independent Reporting

Reason — Homeland Security Is Monitoring Activists Building Anti-Flock Tech
The September 23 report based on the Massachusetts intelligence product that brought the SparrowMap monitoring story into public view.

404 Media — The Government Is Monitoring Anti-Flock TikTok and Instagram Accounts
Public-record reporting showing that fusion-center monitoring of anti-Flock activity and DeFlock-related organizing predates the SparrowMap disclosure.

WIRED — Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works
Joint forensic reporting on the stegan0gram Flock-camera teardown, including recovered images, short video clips and on-device computer-vision models.

Flock Safety’s Current Policies

Flock Safety — Law Enforcement Data Access
Flock’s current description of user restrictions, required investigative purposes, search logging and supervisory review.

Flock Safety — License Plate Reader Policy
Current company policy describing LPR data, retention and customer controls, including the company’s seven-day default retention language.

Related sherafy.com Research

Can Flock Cameras Track You? What the Nationwide Network Can—and Can’t—Actually Do
Our broader investigation into how individual Flock observations become searchable vehicle-location histories, how network sharing works, documented misuse and the unresolved constitutional questions.

Inside the Flock Camera Hack: What 1.6 Million Images Reveal About How the Cameras Actually Work
Our technical breakdown of the compromised Flock camera and what the recovered software and data do and do not establish.

Editorial currency note: SparrowMap is actively changing, several of its advertised sensor functions are beta or staged, and Flock’s retention and access policies have also changed during 2026. This article reflects public information and code reviewed through September 24, 2026. Material changes to the SparrowMap deployment, fusion-center records or Flock policy should be incorporated when verified.

Cite this article

Published September 24, 2026

Think something here is wrong, incomplete, outdated, or insufficiently supported? You can challenge a factual claim, source, interpretation, missing context, or privacy issue.

Learn How the challenge process works


More to think on...