https://footnote4a.org/news/bishop-fox-3
Flock now says it got hacked mere weeks before Bishop Fox arrived
Flock promised a Bishop Fox report in September. It published a summary saying no customer data was accessed. Three days later, its lawyers said confidential customer data had been taken.
Oct 3, 2026, 2:30 PM EDT
by H.C. van Pelt
*** begin quote ***
According to Michael’s blog post, he told Flock about the vulnerability on November 13, 2025, and it was still unpatched on January 7, 2026. Flock says it closed the issue in December.[4] Both accounts leave the hole open for weeks after the report, long enough for data Flock itself calls “accurate as of December 2025” to leave. In February, Flock wrote, “We do not wait for third parties to surface issues.”
*** and ***
Flock did not notice any data had been taken. It hired Bishop Fox. If Bishop Fox noticed, Flock’s summary does not say so. Flock tells its customers nothing sensitive was exposed, while its lawyers tell Michael he took “proprietary and confidential information belonging to Flock and its customers.”
There are no advisories on Flock’s security advisories page. There are no new CVEs. There are no updates to old CVEs. There are blog posts and emails saying everything is fine, and demand letters and police referrals saying it is not.
Flock wants all of this to “reinforce confidence in Flock’s strong security posture.”
I don’t think it will.
*** end quote ***
Well here’s YET ANOTHER example of an intrusive privacy-invading “service” marketed to Gooferment actors doing something that the Gooferment can’t do on its own, that can’t keep their “proverbial pants zipped”. And all the time deliberately lying to mislead their “Customers” and the general public.
This deserves the “corporate version of the death penalty”. Shut them down and possibly sanction the founders and senior executives. Everyone, Flock’s insurers and their investors as well, should take a haircut”.
— 30 —
Posted by reinkefj 









You must be logged in to post a comment.