iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
Home ›› Technology ›› Cybersecurity ›› A Leak of San Francisco Police Drone Footage Exposes the New Reality of Urban Surveillance

A Leak of San Francisco Police Drone Footage Exposes the New Reality of Urban Surveillance

Security researchers Sam Curry and Maik Robert found that San Francisco Police Department drone footage was accidentally livestreamed on the open internet via Skydio's website, exposing real-time video, thermal imaging, location metadata, and pilot details. The leak highlights critical cybersecurity and privacy concerns for organizations using surveillance technology.

iG
iGEN Editorial
July 13, 2026
A Leak of San Francisco Police Drone Footage Exposes the New Reality of Urban Surveillance

Just after noon on a Saturday last month, a Skydio X10 quadcopter hovered about 200 feet over a San Francisco apartment complex, watching police chase a man hiding behind a parked car. This glimpse of modern drone-enabled police surveillance wasn't voluntarily released by the San Francisco Police Department (SFPD)—it was accidentally livestreamed onto the open internet via Skydio's website. Two security researchers, Sam Curry and Maik Robert, discovered that the SFPD was leaking real-time footage from five of its surveillance drones, including color and thermal imaging, accompanying location metadata, and the drone pilots' names and email addresses, to anyone who found the public web address where the videos were hosted.

How the Leak Occurred

According to WIRED, the leak was discovered when Curry and Robert found that the SFPD's drone feeds were accessible at a fully public web address. They reported their discovery to Skydio around two days after discovering it, and the feed was quickly taken offline. By then, the researchers had watched police carry out multiple arrests and searches, as well as tracking cars and individuals from the sky. The archive they captured includes 60 videos from 20 separate flights over about 48 hours in mid-June, with each mission recorded from three feeds: a color camera, a thermal camera, and a third view from the drone's rooftop dock.

What the Drone Footage Captured

Curry and Robert later shared the results with WIRED, which analyzed all 20 color videos with software that detects people, vehicles, and other objects. The review found that the cameras had filmed hundreds of people and vehicles across the 20 flights. The leaked feed captured two forced detentions, a police visit to an apartment in a high-rise building, and an apparent search of an alley populated with homeless people, as well as numerous instances where police used drones to surveil individuals, vehicles, or buildings. In one example, a drone followed a man across the city, zooming in on his black SUV's license plate, and kept the vehicle locked at the center of its video frame until he pulled over. The manhunt stemmed from an alleged "auto boost/strip" incident—the suspected theft of car parts or another object from a vehicle.

Privacy and Security Implications

"There's a certain trust given to the police to use these things correctly," says Sam Curry. "When you're watching a drone feed live, you can look into dozens of different apartments, you can see police zooming in on people, you can see arrests. The fact that all of this was exposed feels like a really big issue from a privacy perspective." For enterprise technology leaders, this incident underscores the critical importance of securing IoT and surveillance infrastructure. The inadvertent exposure of pilot names, email addresses, and real-time geolocation data poses not only privacy risks but also operational security threats. Organizations deploying similar drone or camera systems must ensure that streams are not publicly accessible, authentication mechanisms are robust, and access controls are strictly enforced.

Response and Lessons

Curry and Robert's responsible disclosure to Skydio led to a quick takedown. However, the incident serves as a case study in the vulnerabilities of connected surveillance technology. The SFPD did not voluntarily release the footage; it was a data breach. For companies in logistics, supply chain, and security, the lesson is clear: any device that captures and streams data can be an entry point for leaks. Regular security audits, encryption of video feeds, and strict access logging are essential. As urban surveillance expands, so does the attack surface—Skydio's platform, used by many police departments, must now face scrutiny over its default security configurations.


Sources: WIRED – Top Stories

Keep Reading

Recommended Stories

The Cop Who Took On Flock: Inside a Secret License-Plate Camera Deployment Technology

The Cop Who Took On Flock: Inside a Secret License-Plate Camera Deployment

Pawtucket, Rhode Island police officer Noel Pichardo discovered that Flock Safety license-plate readers were live on city streets after the city signed a $128,000, two-year contract without prior public notice. WIRED reports on the ACLU complaint, the chief's apology, and the chain of events that Pichardo says ended his law-enforcement career.

August 18, 2026
Stockton's Flock Drone Deal Sparks Privacy Concerns Technology

Stockton's Flock Drone Deal Sparks Privacy Concerns

Stockton's recent approval of a $3.15 million investment in Flock drones has sparked significant privacy concerns among residents. The drones, intended as airborne first responders, have been criticized for potential surveillance and data privacy issues.

June 14, 2026
Face-Recognition Tool Failure Leads to Wrongful Arrest Technology

Face-Recognition Tool Failure Leads to Wrongful Arrest

A Florida man's wrongful arrest due to a faulty face-recognition match exposes significant flaws in one of the oldest police face-recognition systems in the US. The incident raises concerns about the reliability and oversight of such technologies in law enforcement.

June 10, 2026
Reverse-Lookup Service Exposed Millions of Photos of People's Faces Technology

Reverse-Lookup Service Exposed Millions of Photos of People's Faces

Independent security researcher Jeremiah Fowler found that the people-search service ClarityCheck left more than 9 million image files, including photos of faces, publicly accessible in an unsecured Amazon S3 bucket. A second misconfiguration exposed email addresses and phone numbers. The company secured the data after WIRED reached out but disputed that the data was publicly exposed.

August 19, 2026