Despite Flock’s public promise that findings would be “communicated transparently to reinforce confidence in Flock’s strong security posture,” the company does not publish them alongside the blog post. More worryingly, Flock now says it experienced a data breach weeks before Bishop Fox began testing its systems. Flock missed it. If Bishop Fox caught it, Flock’s summary does not say so.
Flock’s lawyers wrote in a demand letter dated September 25, 2026, that Flock determined an exposed access key was used to “unlawfully access Flock’s system, obtain confidential data, retain that data, and later publish it.” The information “includes proprietary and confidential information belonging to Flock and its customers.” Three days earlier, the blog post about Bishop Fox’s testing said:
- “No customer data or systems were ever accessed by anyone outside of Flock as a result of this testing.”
- “None of these findings resulted in any customer data or systems being accessed by anyone outside Flock.”

Open your Funk & Wagnalls to “surveillance without warrant OR probable cause with lax security measures.”
Leave a comment