600 LPR Lookups: Legal Fallout from Rogue Police Use of Flock Network
A police chief stalked his ex-girlfriend by querying Flock's ALPR system 600 times. The case triggers legal questions about agency oversight, vendor liability, and constitutional privacy protections.
Key Takeaways
- A police chief stalked his ex-girlfriend by querying Flock's ALPR system 600 times.
- The case triggers legal questions about agency oversight, vendor liability, and constitutional privacy protections.
Mentioned
Key Intelligence
Key Facts
- 1Former Braselton Police Chief Michael Steffman queried Marci Bakely’s and her daughter’s license plates roughly 600 times over an extended period using the Flock ALPR system.
- 2Steffman was arrested in November on charges of stalking, harassment, and misuse of license plate reader data.
- 3Before trial, Steffman was found dead in his home in April; officials ruled it a suicide.
- 4Flock Safety’s network includes AI-powered roadside cameras recording license plates into a searchable database accessible to thousands of law enforcement agencies.
- 5The website Have I Been Flocked aggregates police search logs from public records, exposing the extent of the abuse.
- 6Bakely took counter-surveillance measures including installing home cameras, buying a hidden-camera detector, and checking her car for trackers before learning about Flock.
Analysis
- Vast ALPR network aids in tracking stolen vehicles and missing persons across jurisdictions
- Provides actionable data that speeds up criminal investigations and deters vehicle-based crime
- Lax access controls enable stalking and personal surveillance without oversight
- Vendor and agency liability unclear under current privacy laws like DPPA and state wiretap statutes
- Potential Fourth Amendment violations when license plate data is queried without probable cause or warrant
Analysis
For legal professionals, this case highlights the urgent need for robust access controls and auditing in law enforcement surveillance tools, as well as potential liability for technology vendors under privacy laws and civil rights statutes. The outcome could shape litigation strategies and fuel a push for new regulations governing ALPR usage nationwide.
The case of Marci Bakely and former Braselton Police Chief Michael Steffman lays bare the dark side of the widespread deployment of automated license plate reader (ALPR) networks, specifically the Flock Safety system, which now covers thousands of law enforcement agencies across the United States. Steffman exploited his privileged access to Flock’s mappable database of vehicle locations to stalk Bakely and her teenage daughter, querying their license plates approximately 600 times over an extended period. The abuse went undetected by Flock’s systems and his own department, only coming to light when Bakely pressed Steffman for answers and he admitted to using Flock, later corroborated by public record aggregator 'Have I Been Flocked.' Steffman’s arrest in November on charges of stalking, harassment, and license-plate-reader misuse, followed by his suicide in April before trial, underscores the profound human cost of insufficient oversight in surveillance infrastructure.
For Flock Safety, the reputational damage is substantial.
The Flock system, like many ALPR networks, is marketed as a force multiplier for law enforcement, capable of solving crimes by tracking vehicles in real time and storing historical data. However, the system’s access controls appear surprisingly lax: a single user could conduct hundreds of searches on a private individual’s vehicles without triggering internal alarms or mandatory audits. This case illustrates a fundamental design flaw present in many law enforcement databases: once an officer is granted access, the only barrier to misuse is personal ethics and the threat of post hoc detection—often long after the damage is done. The absence of real-time anomaly detection, such as flagging when a user repeatedly queries a small set of plates unconnected to active cases, is a critical vulnerability that turns a public safety tool into a stalking weapon.
For Flock Safety, the reputational damage is substantial. The company, which positions itself as a privacy-conscious provider by not using facial recognition and keeping data for only 30 days by default, now faces a public relations crisis and potential civil liability. Victims of such abuse may bring lawsuits alleging negligence, invasion of privacy, and possibly violations of the Driver's Privacy Protection Act or state wiretapping laws, arguing that Flock failed to implement reasonable safeguards. Meanwhile, the thousands of police departments using Flock must reckon with the fact that their own officers could be similarly surveilling ex-partners, journalists, or activists without detection—eroding public trust in policing and surveillance technology.
What to Watch
The broader implications extend to the entire ALPR industry, from competitors like Motorola Solutions’ Vigilant to emerging startups. The incident will almost certainly fuel legislative efforts to regulate ALPR use, including mandatory audit logs, warrant requirements, and enhanced transparency mandates. At the federal level, the Fourth Amendment Is Not For Sale Act and various state bills could gain renewed momentum, potentially imposing strict limits on the sharing and retention of location data. The Federal Trade Commission could also look into whether Flock’s security representations constitute deceptive practices if the system lacked reasonable safeguards against insider abuse.
Looking forward, the Bakely-Steffman case will serve as a touchstone for debates on law enforcement technology governance. Police agencies will be forced to implement stricter internal controls, such as requiring supervisor approval for non-case-related plate searches and conducting random audits. Technology vendors will need to integrate user behavior analytics, hard limits on query frequency, and automatic notifications to agency heads when anomalous patterns emerge. The incident also reinforces the importance of independent oversight: without 'Have I Been Flocked' and public records laws, the scale of Steffman’s abuse might never have been known. Ultimately, the tragedy demonstrates that in the age of networked surveillance, privacy protections cannot be an afterthought—they must be engineered into the core of the technology, backed by legal accountability for both the abuser and the system’s operator.
Timeline
Timeline
Stalking via Flock ALPR begins
Michael Steffman uses his access to Flock’s ALPR database to track Marci Bakely and her daughter, searching their plates approximately 600 times over months.
Steffman arrested
Steffman is arrested on charges of stalking, harassment, and misuse of license plate reader data.
Steffman found dead
Before trial, Steffman is found dead in his home; officials rule it a suicide.
Cite This Page
"600 LPR Lookups: Legal Fallout from Rogue Police Use of Flock Network." Legal & RegTech Intelligence Brief, August 8, 2026. https://getlegalbrief.com/story/600-lpr-lookups-legal-fallout
How we covered this story
Every story in our legal coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the legal space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled legal-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |