The Pentagon Flocked Itself. Should Big Brother Be Worried?
Authored by Brett Heinz via Responsible Statecraft,
As the headquarters to the U.S. military, the Pentagon is surrounded by billions of dollars worth of surveillance and security technology.
These systems provide multiple layers of protection for the building but they also carry a risk of backfiring: any surveillance system that is vulnerable to intruders could potentially provide unauthorized users with details about the activities of the Defense Department (DOD) and its employees. This risk is higher than usual right now because of the decision to install a controversial piece of equipment all over the Pentagon grounds: Flock cameras.
There are at least nine Flock automated license plate readers (ALPRs) currently monitoring the traffic lanes used by drivers entering the Pentagon's parking lots, including many of the DOD's own employees. The purpose of these cameras is to give the Pentagon's security forces the ability to automatically record information about incoming vehicles that may pose a security risk. But if the alleged vulnerabilities of Flock cameras are as serious as the company's critics allege, then this equipment could be exploited to obtain a detailed list of the national security officials seen entering the Pentagon each day. In this way, the Pentagon's rush to obtain security equipment from private contractors may pose a national security risk of its own.
Concerns about the ability of Flock products to track people alongside cars has produced backlash from privacy-minded citizens, resulting in both protests and contract cancellations. Others have criticized Flock's devices for security vulnerabilities that expose them to unauthorized users, flaws which could be especially dangerous in the context of military facilities. Flock Safety has sought to downplay these issues, insisting that they have "never been hacked." Critics dispute this claim, pointing to multiple different ways that Flock's devices can be accessed by unauthorized users.
These concerns prompted two members of Congress' Intelligence committees - Senator Ron Wyden (D-Ore.) and Rep. Raja Krishnamoorthi (D-Ill.) - to write a letter last year asking for an investigation into Flock's "negligent cybersecurity practices." The duo alleged that the company "needlessly exposes Americans to the threat of hackers and foreign spies tapping this data." When asked about the Pentagon's Flock cameras, Sen. Wyden said that "Installing internet-connected cameras in the Pentagon parking lot is obviously a dumb idea. In particular, given Flock's troubling cybersecurity track record, the Pentagon might as well send the data from those cameras directly to China, Russia and Iran."
Under the radar
In late 2021, the Defense Department issued a contract to the Virginia-based company M.C. Dean Inc. to improve the Pentagon's "electronic and physical security systems." This agreement is an "Indefinite Delivery / Indefinite Quantity" contract, which allows the DOD to issue mini-contracts known as "delivery orders" directly to their chosen contractor whenever new needs arise. While the DOD has no direct relationship with Flock Safety, it acquired the company's products through these delivery orders.
The desire for additional security is understandable. The Pentagon has been subject to numerous attempted attacks in the years since the tragic destruction of September 11, 2001. Almost a year into M.C. Dean's contract, a Virginia man tried to drive his vehicle through the Pentagon's multiple checkpoints before being stopped by officers from the building's dedicated security force, the Pentagon Force Protection Agency (PFPA). The culprit later admitted that he was "trying to kill people." Sure enough, installing an "active vehicle barrier and traffic arm" was one of the many tasks that M.C. Dean had been assigned to work on in the coming years. Yet other parts of the contract raise doubts about the idea that more spending necessarily produces more security.
In May 2023, the DOD issued a delivery order to M.C. Dean indicating its interest in a "license plate recognition system." A later update specified that it was "for the entire Pentagon reservation parking facilities." The PFPA already operates several license plate readers on the Pentagon grounds, but applying such a system to the parking lot entrances expanded their reach to capture most of the vehicles that drive within a certain distance of the building. In September, a new order was issued to "procure Flock perimeter license plate reader systems." Because this decision came through the order of a pre-existing contract, neither Flock Safety nor its resellers had to participate in a competitive bidding process to prove that their products were the best prepared to meet the Pentagon's needs - or that they had the most secure system available.
This was not the first time that Flock benefited from government contracts without full competition. Last year, the U.S. Park Police issued a non-competitive contract for "a Flock safety... system in the greater Washington, DC Metropolitan area." Many local police departments use similarly non-competitive agreements to acquire their own Flock equipment.
It is unclear who decided that the Pentagon should acquire its system from Flock. The Defense Department requested Flock products in its September order, but it may have done so under advisement from M.C. Dean or the various subcontractors that it worked with. Neither the DOD, M.C. Dean, nor any of the subcontractors involved in this process responded to a request for comment. Once the decision to go with Flock had been made, M.C. Dean installed its devices with the help of ThunderCat Technology, a subcontractor described by the Brennan Center as "an intermediary selling technology or software produced by other companies." ThunderCat was recently named alongside Flock in a Maryland legal complaint alleging that these and other companies have sold data to third-party customers, including Immigration and Customs Enforcement. Contract information and Google Maps Street View imagery suggest that most of the devices were installed in late 2024 and early 2025.
It is unclear exactly how much the Pentagon spent on this system. The two delivery orders executed by ThunderCat are worth a total of $112,000, while the earlier order that first mentioned the idea is worth an additional $404,000. Several other orders in M.C. Dean's contract discussed license plate readers, though some dealt with systems purchased from other companies.
The Flock spreads
Flock Safety's license plate readers have come under fire from multiple cybersecurity experts. One such critic, hacker and researcher Jon Gaines, has argued that some of the company's technology can be breached in "about 30 seconds." Reached for comment, Gaines said that he "absolutely" considers the Pentagon's Flock cameras to be a potential security risk. Asked whether it was possible for the DOD to have modified the devices to address their security flaws, he replied: "No, by design the customer, in this case the Pentagon, have no control or insight into the security posture or control of the physical devices deployed by Flock."
The DOD distributes parking permits to employees working at the Pentagon, meaning that it already knows who uses its parking lots. The real value of the ALPR system is its ability to document unknown drivers, which could be helpful in identifying threats like the attacker that tried to ram the Pentagon's checkpoints. But if this data were accessed by an authorized user, they could use it to compile a list of active DOD employees and their daily schedules. The PFPA considers it a priority to prevent the public from accessing this type of information. Photography of the Pentagon is illegal, and the building is surrounded by warning signs reminding visitors of this "No Photography" rule. A PFPA spokesperson once stated that preventing someone from taking "pictures of certain people entering the building" was one of the reasons why this rule exists. Yet by engaging in this exact behavior with cameras that allegedly suffer from serious vulnerabilities, the Pentagon's security force could potentially be creating one of their own worst-case scenarios.
Data-sharing poses yet another risk to the security of the data captured by the Pentagon's Flock devices. Technically, the Flock system would not even need to be "hacked" for its data to be dangerous: all it would take is for one person with access to the system to misuse it or share it with others in an unauthorized way. The Institute for Justice, a libertarian public interest law firm which is critical of Flock cameras, maintains a growing database of more than 200 incidents in which they have been used for reasons other than their intended purpose.
The DOD has not disclosed everyone who has access to the data gathered by its license plate readers. Many local law enforcement agencies that share their data with other agencies provide the public with a list of those agencies, but the Pentagon provides no such list. It is even possible that Flock Safety itself has some level of access to the Pentagon's data: previous versions of the company's standard Terms of Service stated that it reserved the right to collect "anonymized and/or aggregated data" from its users that could be used for anything from technical improvements to marketing. Flock Safety did not respond to a request for comment.

