Whenever Marci Bakely left home — a run to the grocery store, an evening out on a date — her phone would buzz within minutes. Her ex-boyfriend appeared to know her movements almost as they happened. A Washington Post investigation later documented how: Braselton Police Chief Michael Steffman, her former partner, had queried her license plate and that of her teenage daughter roughly 600 times through Flock Safety, a company that builds and operates networks of automated license plate readers, commonly known as ALPRs.
The Georgia Bureau of Investigation arrested Steffman in November 2025 on charges of stalking, harassment, and misuse of an ALPR system. He was found dead before the case could reach trial. For Bakely, the matter ended without a courtroom reckoning or a public accounting of how one official account could be pointed at a private citizen so many times.
Not an Outlier: The Scale of the Misuse
Bakely's experience is far from a one-off. The Post's investigation identified at least 50 law enforcement officers accused of misusing ALPR networks. Of those, 26 allegedly used Flock's cameras to monitor current or former romantic partners — or people they hoped to pursue romantically. Since that initial reporting, the paper says it has identified at least 100 police department employees who have been charged with or accused of misuse.
In Bakely's case, the queries reached beyond a single target: Steffman also searched plates belonging to her teenage daughter, according to the investigation. That detail illustrates how one authorized account can expose an entire household's daily patterns, from school runs to medical appointments, without the subject ever knowing a search occurred.
This pattern reframes the debate. The question is no longer only whether a handful of officers behaved criminally. It is whether the systems they used made that behavior easy, quiet, and repeatable.
Flock's Response — and Its Limits
Flock Safety contests the framing. The company notes that the individuals implicated represent a very small proportion of its more than 140,000 monthly users, and it points to permanent audit logs as a tool that helps surface misconduct after the fact.
Both claims carry weight. A platform with a user base that large will inevitably include bad actors, and searchable logs are genuinely better than nothing — they are how several of these cases came to light in the first place.
But audit trails are a detection mechanism, not a prevention mechanism. They document abuse after someone's location history has already been exposed. For a person being tracked by an ex-partner, a log entry that surfaces months later offers little protection during the months of surveillance itself.
The Front Door Was Wide Open
What makes the ALPR cases distinctive is the absence of any technical break-in. No hacker cracked a database. No credential was phished. No insider smuggled out a hard drive. According to the reporting, each of these users simply logged in through the front door, using authorized access for an unauthorized purpose.
That distinction separates this episode from a conventional cybersecurity story. Firewalls, encryption, and penetration testing do almost nothing to stop a legitimate account holder from typing a plate number into a search box for personal reasons. The vulnerability is not in the software's defenses; it lives in the permissions model wrapped around the data.
Why This Is an Architecture Problem
A scholar of criminal procedure who directs a school devoted to forensics has argued that the ALPR controversy points to a defect baked into the surveillance system's design, not merely the criminality of certain users. That framing is useful because it shifts attention from individual misconduct toward structural choices that can be re-engineered.
Purpose Limitation and Least Privilege
Two long-standing principles from data protection practice are relevant here. Purpose limitation holds that information gathered for one stated reason should not be repurposed for another. Least privilege holds that people should receive the minimum access necessary to perform their jobs.
An architecture that lets thousands of individual officers run unrestricted, free-text plate searches — with no case number, no stated reason, and no supervisory gate — runs against both principles at once. In that design, the only thing standing between a plate and a person's location history is the user's own restraint. Policy manuals and training modules assume that restraint generally holds. The pattern documented by the Post suggests it does not always.
What a Better Design Would Look Like
None of this means plate readers must be abandoned, or that agencies should lose a tool that can genuinely help solve crimes. It means the access layer deserves the same scrutiny as the camera layer.
- Require a documented, case-linked justification before any query returns results, rather than a log entry written afterward.
- Restrict search permissions by role, so a small number of vetted personnel can run broad queries instead of every account holder.
- Flag and lock searches involving plates tied to officers' own addresses, relatives, or known personal contacts.
- Notify the subject of a search, or an independent oversight body, when queries fall outside declared casework.
- Give civilians a meaningful role in reviewing aggregate audit data, rather than leaving oversight entirely inside the agency.
Each measure raises costs: administrative friction, slower investigations, more complex software. Those costs are real and worth weighing honestly. But they are the price of moving from detection after harm to prevention before it.
The Broader Stakes
License plate readers are only one node in a widening web of automated observation. The same design questions recur with facial recognition, drone footage, and aggregated location data drawn from vehicles and phones. As these networks expand, the gap between an "authorized user" and a trustworthy one becomes a systemic risk rather than a human resources problem.
The Bakely case ended without a trial, and the officer accused of tracking her is no longer alive to answer the charges. But the architecture that made hundreds of lookups possible is still running in departments across the country. Until access is redesigned around purpose, privilege, and outside oversight, the next person to be tracked is likely to be tracked by someone who never had to defeat the software's defenses — only the limits of their own job description.
This article is based on reporting by Fast Company. Read the original article.
Originally published on fastcompany.com








