San Jose’s police department fired an officer this year for misusing the city’s Flock automated license plate reader network, then waited until September 11, 2026 to say so publicly. The officer used the database on his personal phone to track a woman who had accused his cousin of domestic violence, then passed her location to the cousin, according to The Mercury News. Neither man has been criminally charged. The case lands amid a broader reckoning with Flock license plate reader misuse, a pattern that has already cost at least 18 officers their jobs or their freedom in cases nationwide, per CNN’s ongoing tracking of the issue.

The story matters beyond one department. Flock Safety cameras now sit in more than 6,000 communities across 49 states, feeding a searchable database that thousands of agencies share. San Jose’s admission shows what happens when that access control model meets a personal grudge, and it’s forcing the vendor and its customers to rethink who gets to search, and how anyone would know if they didn’t.

What Happened in San Jose

According to San Jose Police Chief Paul Joseph, an officer with about two years on the force used his personal phone to search the department’s Flock license plate reader database and located a vehicle belonging to a woman who had accused his cousin of domestic violence. The officer then shared what he found with the cousin, who used it to track her down, Joseph said in comments reported by ABC7 San Francisco. “The officer accessed license plate reader data and provided that to a suspect in a domestic violence situation, which enabled that suspect to locate a victim,” Joseph told NBC Bay Area.

The department learned of the misuse in February 2025, after the victim reported that the cousin somehow knew her location and officers ran her plate to figure out how. That inquiry surfaced the officer’s search history inside the Flock system. He was placed on administrative leave, investigated for roughly a year, and terminated in April 2026. San Jose only disclosed the case publicly on September 11, 2026, alongside a new department policy barring officers from accessing law enforcement databases on personal devices.

The Audit Trail That Caught Him

What actually exposed the misuse wasn’t a whistleblower or an internal review sweep. It was routine police work: officers ran the victim’s own plate after she reported being tracked, and that search turned up the earlier unauthorized query tied to the officer’s account. Flock’s platform logs every search by user, timestamp and stated reason, which is precisely the audit trail that let San Jose reconstruct what happened months later. Without that log, the case might never have surfaced at all.

How Flock’s License Plate Reader Network Works

Flock Safety sells camera hardware and a shared cloud database to cities, homeowners associations, and police departments. Cameras mounted on streetlights and intersections photograph every passing vehicle’s plate, make, color and other identifying details, then upload that data to a searchable network. Officers query the system by plate number, and in many deployments they can also search across neighboring agencies’ camera feeds, which is the feature that turned a local vendor into a national surveillance backbone in just a few years.

That cross-agency reach is also the source of most complaints. A search run in San Jose can return hits from cameras hundreds of miles away if the host agency has opted into data sharing, and until this year there was no standard requirement that a supervisor review flagged searches before an officer acted on the results. The Flock license plate reader misuse pattern that’s now drawing scrutiny grew directly out of that permissive design: broad access, thin real-time oversight, and audit logs that mostly get checked after something has already gone wrong.

Timeline: From a February 2025 Report to a September 2026 Disclosure

DateEvent
February 2025Victim reports that the cousin knows her location; officers run her plate and discover the officer’s unauthorized Flock search
February 2025Officer placed on administrative leave; internal and criminal investigations opened
2025–early 2026Roughly year-long internal investigation into the officer’s conduct
April 2026Officer terminated from the San Jose Police Department
Week of September 7, 2026SJPD issues directive barring database access from personal devices
September 11, 2026Chief Paul Joseph publicly discloses the case; officer referred to POST for decertification review

That seven-month gap between disclosure and termination isn’t unusual for police misconduct cases, which typically move through internal affairs, a Peace Officer Bill of Rights review, and sometimes a district attorney referral before an agency can finalize a firing. What’s notable here is the further five-month gap between the April termination and the September public disclosure, a lag Joseph didn’t fully explain in his public remarks.

Chief Paul Joseph’s Response and the POST Referral

Joseph framed the firing as a matter of institutional trust rather than a one-off technical violation. “What we have here is a betrayal of the public’s trust. Plain and simple,” he said, according to The Mercury News. He went further in a separate statement carried by ABC7: “When an officer violates the public’s trust this severely, my responsibility is clear: that person cannot remain in a position of police authority, and they cannot wear the San Jose badge. This technology is new; the standard is not.”

Joseph also laid out the department’s internal process once the misuse came to light: “When we learned about this, we immediately placed this officer on administrative leave. We launched a criminal investigation into his conduct. We referred that investigation to the district attorney’s office and we ultimately terminated that police officer,” he told NBC Bay Area. And on accountability more broadly, he said the department wants the public to know “an officer who violates their trust in that way will be dealt with accordingly. They will be held accountable up to and including termination.”

Beyond the firing, San Jose referred the officer to California’s Commission on Peace Officer Standards and Training, the state body that can strip an officer’s certification and bar him from working in law enforcement anywhere in California. A POST referral doesn’t guarantee decertification, but it puts the officer’s career, not just his job at SJPD, on the line.

Why No Criminal Charges Were Filed

The absence of criminal charges against either the officer or his cousin has drawn its own scrutiny, and it points to a gap in how most states write their computer-access laws. The officer had legitimate, standing authorization to query the Flock database as part of his job. He misused that access for a personal purpose, but he didn’t break in, spoof credentials, or exceed a technical permission boundary in a way that current unauthorized-access statutes are built to catch.

That’s the same fact pattern that has let other insider-misuse cases, from DMV clerks pulling records for exes to hospital staff browsing patient files, slide past criminal prosecution and land instead in employment and licensing proceedings. It’s a structural weak point security teams have flagged for years: audit logging tells you who looked at what, but authorization systems rarely distinguish between a legitimate business reason and a personal one at the moment of the query.

Not an Isolated Incident: A Pattern of ALPR Misuse in 2026

San Jose’s case is part of a documented wave. Investigators nationwide have confirmed at least 18 cases in 2026 in which officers were arrested, fired, or placed under investigation for misusing Flock’s automated license plate reader system, including several involving officers tracking exes or romantic interests, according to CNN’s reporting on the pattern. The overlap between domestic-relationship misuse and law-enforcement database access has become common enough that it now shows up as a recurring category in incident write-ups rather than a one-off anomaly.

The pattern has consequences beyond individual firings. More than 50 agencies or communities have canceled, suspended, or rejected a Flock contract, or deactivated cameras outright, since the start of 2026, according to DeFlock, the grassroots group that tracks license plate reader deployments and cited by CNN. That’s a meaningful dent in a company that built its growth pitch around near-frictionless municipal adoption.

Flock Safety’s Audit Assistance Tool and New Retention Rules

Flock has responded with product changes rather than just public statements. The company is requiring all customers to adopt its “Audit Assistance” tool by the end of 2026, a feature that flags abnormal search behavior for an individual officer and can lock a user out of the system pending administrator review, per Flock’s own announcement reported by CNN. The company also said it will recommend agencies cut license plate reader data retention from 30 days to seven, while adding controls meant to restrict how easily one agency’s data flows into another’s searches.

SafeguardBefore 2026 rolloutAfter 2026 rollout
Data retention (recommended)Up to 30 days7 days
Abnormal search detectionManual post-hoc audit onlyAutomated flagging via Audit Assistance
Suspicious account responseNo automatic lockoutAccount lockout pending admin review
Cross-agency data sharingBroad, opt-in network sharingAdditional restriction tools for agencies
Customer adoption of audit toolingOptionalMandatory by end of 2026

These changes track closely with what happened in San Jose: a search that should have triggered a real-time flag instead sat undiscovered for months, and only came to light because the victim independently reported suspicious behavior. Automated anomaly detection is meant to close exactly that gap, though it still depends on agencies actually enabling and acting on the alerts, which Flock can require contractually but can’t fully control operationally.

Market Impact: A Trust Problem for a Public Safety Vendor

Flock Safety built its business on being the easy, fast-growing alternative to legacy license plate reader vendors, landing thousands of city and HOA contracts by pitching a shared network effect: the more agencies join, the more useful every camera becomes. That same network effect is now the company’s biggest liability. Every misuse story, whether it’s a stalking case or a domestic violence tip-off like San Jose’s, reads as evidence that Flock’s growth outpaced its access controls.

Flock’s Position Against Rivals as Contracts Wobble

Flock still dominates small-to-mid-size city deployments, typically in the $25,000 to $90,000 contract range, but competitors are picking off specific segments as scrutiny grows. Motorola Solutions, which acquired Vigilant Solutions for $445 million in 2021, remains the default choice for agencies wanting deep integration with existing Motorola radio and records systems, according to industry comparisons of ALPR vendors. Rekor Systems takes a camera-agnostic approach, layering cloud analytics onto hardware a city already owns, with its Rekor Scout product starting at roughly $12 per camera per month, a fraction of Flock’s typical per-camera cost. Axon and Verkada round out the field, with Axon increasingly winning larger citywide contracts and Verkada positioning itself as the low-infrastructure option for smaller municipalities.

None of that has translated into an obvious mass migration away from Flock yet. Switching ALPR vendors means ripping out hardware, renegotiating data-sharing agreements, and retraining officers, which is exactly the kind of friction that made Flock’s network sticky in the first place. But the more than 50 contract cancellations and suspensions tracked since January are the clearest sign yet that the friction isn’t infinite.

The Backlash: Agencies Pulling Back on Flock Contracts

The pullback isn’t limited to privacy advocacy groups. City councils in multiple states have cited misuse cases directly when voting to pause or end Flock contracts, and some agencies have gone further than Flock’s own recommendations, cutting retention windows below the new seven-day guidance or barring personal-device access entirely, mirroring the policy San Jose adopted the week of September 7. The common thread across these local decisions is that elected officials, not just police chiefs, are now treating ALPR governance as a political liability rather than a purely operational one.

Historical Context: From Bulk Data Collection to Neighborhood ALPR Networks

Concerns about government location tracking aren’t new, but the shape of the problem has changed. A decade ago, the dominant privacy fight was over bulk telephone metadata collection by federal agencies, a debate fought largely in courts and congressional hearings over programs most citizens never directly saw. Flock’s model inverts that: the cameras are visible on street corners, the contracts are approved in public city council meetings, and the misuse cases involve named police chiefs answering to local reporters within days of an incident becoming public.

That visibility is arguably why the backlash has moved faster this time. Where metadata collection took years of litigation to surface publicly, a single department’s press conference, like Joseph’s on September 11, can trigger contract reviews in other cities within the same news cycle. The tradeoff is that ALPR oversight is being built ad hoc, city by city and vendor policy by vendor policy, rather than through a single federal standard, which is exactly the gap that lets a case like San Jose’s happen without triggering an automatic criminal charge.

What This Means for Security and Privacy Teams

For security engineers who don’t work in law enforcement, the San Jose case is still a useful case study in access control design. It’s a textbook example of an authorization model that answers “can this account touch this data” without ever asking “is there a legitimate reason for this specific query right now.” That’s the same failure mode that shows up in insider-threat cases across healthcare, finance, and government IT, and it’s why anomaly-based detection, not just role-based permissions, is becoming a baseline expectation rather than an add-on.

A generic audit record for a system like Flock’s typically captures enough fields to reconstruct a case after the fact, which is exactly what let San Jose piece together what happened months later:

{
  "user_id": "officer_account_id",
  "query_type": "plate_search",
  "timestamp": "2025-02-XXT00:00:00Z",
  "stated_reason": "investigation_case_number",
  "device_type": "personal_mobile",
  "result_count": 1,
  "flagged_for_review": false
}

The “flagged_for_review: false” field is the design gap Flock’s Audit Assistance tool is meant to close, turning a passive log entry into an active alert when the stated reason, device type, or search pattern looks off. Security teams evaluating any shared-access database, not just license plate readers, should treat that same question, does an anomaly get flagged in real time or only discovered during a post-incident audit, as a baseline procurement requirement.

Predictions: Where ALPR Oversight Goes From Here

  • More departments will follow San Jose’s lead and formally bar law enforcement database access from personal devices, since it’s the single cheapest policy change available and directly closes the exact gap this case exposed.
  • Flock’s mandatory Audit Assistance rollout will likely become the industry baseline, with rivals like Motorola Vigilant and Axon rushing out comparable anomaly-detection features to avoid ceding a procurement talking point.
  • Expect at least one state legislature to introduce a bill in 2027 explicitly criminalizing personal-use misuse of law enforcement databases by authorized users, closing the same charging gap that let the San Jose officer avoid prosecution.
  • The pace of contract cancellations tracked by DeFlock will keep climbing through the rest of 2026, though total deployments will likely still grow overall as new cities sign on even as others exit.
  • POST-style decertification bodies in other states will see a rise in ALPR-misuse referrals, since it’s emerging as the primary accountability mechanism when criminal charges aren’t available.

Competitive Landscape: Flock vs. Motorola Vigilant vs. Rekor

Buyers evaluating ALPR vendors after a case like this are weighing more than camera specs. Flock’s pitch remains the shared-network effect and low upfront cost for small and mid-size departments. Motorola Vigilant leans on deep integration with existing dispatch and records systems that many larger agencies already run. Rekor’s camera-agnostic, subscription-priced model appeals to cities that want analytics without committing to Flock’s proprietary hardware and data-sharing network. None of the three has published a misuse-prevention track record long enough to call one demonstrably safer than another, but Flock’s mandatory audit tooling, forced by public pressure rather than volunteered early, gives competitors an opening to market oversight features as a built-in differentiator rather than a bolt-on response.

Frequently Asked Questions

What did the San Jose police officer actually do?

He used his personal phone to search the department’s Flock license plate reader database for a woman who had accused his cousin of domestic violence, then shared her location with the cousin, according to Chief Paul Joseph’s public statements reported by The Mercury News and NBC Bay Area.

Was the officer criminally charged?

No. Neither the officer nor his cousin has been criminally charged. The officer had authorized access to the database, which limits which unauthorized-access statutes apply even though the search was for a personal, unauthorized purpose.

When was the officer fired?

He was terminated in April 2026 after a roughly year-long internal investigation that began when the department learned of the misuse in February 2025. San Jose publicly disclosed the case on September 11, 2026.

What is Flock Safety’s license plate reader system?

Flock Safety sells automated license plate reader cameras and a shared cloud database used by police departments, cities, and homeowners associations in more than 6,000 communities across 49 states, according to the company’s own figures cited in CNN’s reporting.

Is San Jose’s case an isolated incident?

No. CNN has tracked at least 18 cases nationwide in 2026 in which officers were arrested, fired, or investigated for misusing Flock’s ALPR system, several involving searches tied to personal relationships rather than official investigations.

What is Flock doing to prevent future misuse?

Flock is requiring all customers to adopt its Audit Assistance tool, which flags abnormal search behavior and can lock out suspicious accounts, by the end of 2026. The company is also recommending agencies cut data retention from 30 days to seven and adding controls on cross-agency data sharing.

What happens to the officer’s career now?

San Jose referred the officer to California’s Commission on Peace Officer Standards and Training for a possible decertification review, which could bar him from working as a police officer anywhere in the state, separate from his termination from SJPD.

How many agencies have dropped Flock contracts in 2026?

More than 50 agencies or communities have canceled, suspended, or rejected a Flock contract, or deactivated cameras, since the start of 2026, according to DeFlock, a grassroots group that tracks license plate reader deployments.