A security vulnerability in San Francisco Police Department software accidentally exposed live, unencrypted drone surveillance feeds to the public, allowing anyone to view real-time police operations for months.
Key Points
- Security researchers Sam Curry and Maik Robert discovered a public URL providing unrestricted access to live video, thermal imaging, and GPS telemetry from five SFPD drones.
- The exposed data included sensitive footage of police detentions, searches, and high-rise apartment interiors, as well as the names and email addresses of drone pilots.
- The breach occurred because an SFPD user generated a "ReadyLink" for the Skydio X10 drones without authentication, which was then indexed on an open-source threat intelligence platform.
- The SFPD fleet has grown to 98 drones since 2024, with officers logging over 1,400 launches between May 2024 and March 2026.
- Following the discovery, the SFPD disabled the link and implemented more restrictive sharing protocols, though the department claims the footage was improperly accessed.