Somewhere in Columbia, Maryland, a few miles from Fort Meade, a company most Americans have never heard of just finished moving into a building. It didn't come from Silicon Valley. It came from Tel Aviv, founded by a former Prime Minister of Israel. Its business is finding cameras that already belong to somebody else, breaking into them, and changing what they show. Not watching. Changing. While you've been staring at the pole camera on your street corner arguing about Flock, this company spent two years quietly walking through the front door of the American security state, and it just told the public it already has customers here. It won't say who.
“What’s that?” I asked one of my clients back in 2023.
I worked in finance, and he had pulled into our offices with what appeared to be cameras strapped to his car. His company “secured collateral” for ours. In other words, he was a repo guy. He told me, “That’s how we do what we do,” he told me, before explaining that finance companies, skip-tracers, private detectives, buy-here/pay-here car dealers, and anyone else who wants to can place license plate numbers in a database, pinging anyone with one of those cameras when they scan it, and they are always scanning, all the time. He told me he made extra cash between repos by laying warranty alerts on cars for manufacturers when they couldn't reach the owner by mail (proving they were notified of the warranty to decrease their liability concerns). The money he made from placing warranty fliers paid for the cameras. But the big money was repos. It didn’t matter if the lienholder was in Alaska; if the car is spotted in Atlanta, anyone driving by with such a camera would be dinged, and the car would be legally repossessed at the next stop.
This, of course, horrified me. My further questions revealed that the local police don’t use it, but they call him, and he uses it for them. But the company he used also stored the data, and most believe it’s being compiled. What that means is that, with the volume of cameras out there, they likely know which doughnut shop you're at on Tuesday mornings and the route you take home from work.
I’ve followed a watered-down, civilian-level “pattern of life” deterrence rules for years - taking different routes home to be unpredictable, or taking unnecessary turns when being followed, etc.- because paranoia has always been a hobby. I spent weeks researching ways around these new devices; chemical sprays for the license plate (illegal), magnetic obstructions (illegal), invisible flashing license plate holders, you name it. None work. If they want you, they will find you. And the “they” in this hypothetical is absolutely anyone with the cash to pay, and it comes cheap.
FLOCK
Three years later, and the technology has grown exponentially. If you have spent any time on social media lately, you’ve probably learned what a Flock camera is. The automated license-plate readers have been quietly multiplying alongside American roads for years, perched on poles at intersections, entrances to subdivisions and parking lots, photographing passing vehicles and turning those photographs into searchable records of where cars have been and when they were there. Suddenly, everybody seems to be looking up and noticing them. Roughly 120,000 Flock cameras now operate across 49 states, generating an estimated 20 billion scans every month. More than 50 jurisdictions have ended their relationships with Flock after the outrage - largely thanks to Tucker and many others who’ve sounded the alarm - while other jurisdictions are reconsidering, and the backlash has become so intense that the company announced sweeping new “safeguards” this week.
The outrage is not difficult to understand. A Flock camera does more than photograph the license plate of a car suspected in a crime. It photographs everybody’s car, builds a database from the resulting images, and lets authorized users search that accumulated history when they want to know where a particular vehicle has been. A tool sold as a way to find stolen cars and murder suspects therefore creates something much larger as a byproduct: an enormous privately operated network capable of reconstructing portions of the movements of ordinary Americans who were never suspected of doing anything wrong. The problem is that a machine capable of finding a kidnapped child is also capable of finding your ex-wife. Some police officers apparently figured that out.
More than 50 officers have now reportedly been accused of misusing automated license-plate-reader systems, with Flock involved in most of the tracked cases. Officers have been accused of using the network to follow spouses, girlfriends, and other people for reasons unrelated to legitimate police work. In Georgia alone, multiple officers were fired and arrested this summer following investigations into their use of Flock. This week, the Harris County Sheriff’s Office suspended three deputies’ access while investigating possible misuse (just their access to the software, not their jobs). CEO Garrett Langley has effectively conceded that relying on police departments to police themselves was not enough.
Another problem is receiving considerably less attention. Researchers say Flock can be hacked. Flock says it never has been. Some experts disagree. After confirmed police misuse of Flock, it’s bad enough that cops have access to it. It would appear that the giant spy network could be vulnerable to people even less scrupulous than they.
The Flock controversy therefore contains three separate problems that tend to get mashed together. There is surveillance, because an enormous network continuously records vehicles belonging overwhelmingly to innocent people. There is access, because thousands of law-enforcement users can search portions of that network and some have allegedly abused that privilege. And there is security, because every internet-connected device presents some attack surface, and researchers have demonstrated it’s possible. No matter how secure that system allegedly is, America has planted tens of thousands of networked cameras along its roads, and a security state is in place. The nightmare of a dystopian, Orwellian existence imagined in practically every sci-fi or futuristic book and movie is now reality.
That should bother you. It bothers people on the political left who spent twenty years warning about the surveillance state, and it bothers people on the political right who have recently discovered that the surveillance state occasionally considers them worthy of surveillance, too. The backlash has become remarkably bipartisan. Flock cameras have been vandalized, covered, and turned into a national symbol of a government that seems increasingly incapable of encountering a new technology without asking how efficiently it can be used to monitor us. There are now 120,000 cameras, and 20 billion monthly vehicle scans, keeping tabs on people who never broke the law.
YOU’VE SEEN NOTHING YET
But suppose, just for a moment, we’ve seen nothing yet. Suppose it gets much, much worse. Suppose the frightening development is not merely a company building its own nationwide surveillance network, but technology designed to locate existing cameras, penetrate them remotely, take control of their feeds, and watch through them. Suppose that tech could reach beyond purpose-built police cameras to ordinary internet-connected surveillance devices, like Ring cams, dash cams, web cams, and phone cams. Suppose the operator could manipulate what a camera was showing in real time, reach backward into recorded video and alter that too. The nightmare would no longer require somebody to install a government camera outside your house. The cameras already surrounding us would constitute the raw material.
Such technology does not belong to a dystopian novel, and I am not describing some hypothetical capability that might exist twenty years from now. Internal company documents obtained by Haaretz have already described the existence of this class of spy tech. A former Israeli prime minister and one of Israel’s highest-ranking military cyber officials founded the company behind it. One of the same venture-capital firms behind Flock also backs it. Brought to you, in other words, by some of the same people who brought you Flock.
The company’s name is Toka.
And so while Flock cameras are now trending on social media and Americans are waking up to the fact they’ve all been staring in a real-world version of Big Brother, Toka has been quietly moving its headquarters to the United States, openly recruiting intelligence personnel to sell its technology to the Pentagon and American intelligence agencies, and now says it already has customers here. And its customers, supposedly, only include the government.
THE FASCINATING SOURCES USED TO WRITE THIS ARTICLE, AND MORE FOR YOUR OWN ADDED RESEARCH, ARE LINKED BELOW.
ISRAELI SPY TECH
Toka was founded in Israel in 2018 by former Israeli Prime Minister and Defense Minister Ehud Barak and retired IDF Brigadier General Yaron Rosen, who had served as chief of the Israeli military’s Cyber Staff. Joining them were Alon Kantor, a former Check Point executive, and Kfir Waldman, a veteran of Cisco and Israel’s technology sector. From its beginning, Toka was aimed not at consumers or ordinary businesses but at governments, intelligence agencies, militaries and law enforcement. The company’s messaging is careful and antiseptic, describing technology for “targeted intelligence,” “forensic investigations” and “covert operations.”
But according to documents obtained by Haaretz, an operator could designate a geographic area and identify vulnerable security cameras within it. Toka’s technology would then exploit those cameras, allowing its customer to watch their feeds without the camera owner's cooperation. The target could be an ordinary internet-connected camera made by anyone - like your Ring cam. Those cams could become intelligence assets simply because somebody had found a way inside them. Toka described the idea in its own marketing materials as transforming “untapped IoT sensors into intelligence sources.”
Haaretz reported that Toka’s technology could manipulate video feeds and previously recorded footage. A technical expert who reviewed the materials for the newspaper said the manipulation could be performed without leaving evidence that the camera had been compromised. Secretly watching through somebody else’s camera is surveillance. But secretly changing what the camera recorded attacks the reliability of the record itself. A camera that supposedly provides objective evidence of what happened can instead become a tool for changing what everyone subsequently believes happened. It’s a framing tool. Why would governments want to plant false video?
Ordinarily, the argument is about whether authorities had the right to obtain the footage. But once technology capable of covertly altering stored recordings exists, the question is: how do you establish that the video being presented today is real?
Toka has pushed back against claims it’s a hacking company. Rosen has described its position as “something in the middle” between offensive and defensive cyber operations, and the company presents its products as “lawful tools restricted to vetted government customers.” Its technology has also been subject to Israeli Defense Ministry oversight. They advertise that to help people sleep better at night, knowing it couldn’t possibly be used for ulterior motives.
I’m not saying that Toka has hacked a Flock camera. But what has been demonstrated independently is that Flock’s physical cameras are not invulnerable. Security researcher Jon Gaines demonstrated a method of hacking into a Flock camera in roughly thirty seconds with physical access to the device. GainSec researchers subsequently documented more than 50 vulnerabilities, including outdated Android components with hundreds of known vulnerabilities, while another incident exposed more than 60 live camera feeds online. Flock is bad enough. Now, imagine the government - or your enemies - has access to all of Flock. And every other camera in your home. That tech exists.
America has spent billions of dollars covering itself in networked cameras while an Israeli cyber company has simultaneously spent years developing tools for turning other people’s networked cameras into intelligence sources. And both companies have some of the same investors. One of the companies is also overseen by the Israeli Ministry of Defense.
Right now, we Americans are presently arguing about whether police should be allowed to install 120,000 cameras, and which agencies should be permitted to search them. Toka eliminates the first requirement altogether. The camera could have been installed by a business owner, a city, another police department or somebody who thought he was purchasing a security system to protect himself. The useful intelligence asset is no longer merely the surveillance network somebody deliberately constructed. It is the universe of vulnerable cameras already connected to the internet.
And if Toka were merely an obscure Israeli cybersecurity company selling exotic tools on the other side of the world, that would already make for an interesting story. It isn’t. The people behind Toka lead directly back into an intelligence and surveillance ecosystem I’ve brought to you at I2I before. Including a former Israeli prime minister whose name appeared repeatedly in our investigation of Jeffrey Epstein, Unit 8200 and the commercialization of Israeli surveillance technology.
Yes, Ehud Barak is back. This time, as far as I can tell, Epstein isn’t.
PREVIOUS I2I INTEL REPORT
I2I subscribers may remember Ehud Barak from an investigation I published in February into Jeffrey Epstein’s involvement in the Israeli surveillance-technology industry. That article followed a trail stretching back to the PROMIS software scandal of the 1980s, through Israel’s extraordinary investment in military cyber capabilities, into the modern ecosystem of former Israeli intelligence personnel who leave government service and build enormously valuable commercial technology companies. One recurring figure was Barak, who developed an extensive relationship with Epstein and later became involved in an Israeli emergency-communications startup eventually renamed Carbyne.
Carbyne offered emergency dispatchers dramatically improved location information, video communications and other data that could help police, firefighters and paramedics respond faster. Behind that perfectly legitimate application, however, sat an unusual collection of people from the Israeli national-security world. One of Carbyne’s early directors was Pinchas Buchris, the former commander of Unit 8200, Israel’s signals-intelligence unit. Co-founder Alex Dizengof had worked in cybersecurity for the Israeli Prime Minister’s Office. Former Homeland Security Secretary Michael Chertoff joined the board. And sitting among them was former Israeli Prime Minister and Defense Minister Ehud Barak.
Epstein’s role made that story considerably stranger. Barak acknowledged that Epstein helped finance the company through an investment arrangement in which Barak was also involved, and reporting later established that Epstein’s participation was intentionally kept out of public view. Epstein was simultaneously cultivating relationships across the technology and intelligence worlds, corresponding extensively with Barak and taking a particular interest in Israeli cyber companies. That was the part of the Epstein story that fascinated us because it was so different from the story everyone else was telling. While the public stared at the cameras in Epstein’s bedrooms, his money and relationships were intersecting with people building considerably more sophisticated surveillance technology. My February article argued that the cameras on Little St. James were only one part of a much larger story about information, access and the commercialization of intelligence capabilities.
Toka brings us back to Barak through a different door. Epstein does not appear in the company’s publicly documented founding or financing history. Barak himself co-founded Toka in 2018 with Alon Kantor, Kfir Waldman and retired IDF Brigadier General Yaron Rosen. This was not simply Barak buying shares in an interesting cybersecurity startup after somebody else built it. Toka announced him as one of its founders from the beginning. Eight years later, the same company is openly advertising technology for covert government operations and says it has customers in the United States.
Rosen may be even more relevant to understanding what Toka actually is. He served as an Israeli Air Force pilot before rising to brigadier general and becoming chief of the IDF Cyber Staff, where he helped coordinate the Israeli military’s cyber activities. That puts one of the men responsible for building Israel’s military cyber capabilities beside a former prime minister and defense minister in a private company commercializing cyber capabilities for foreign governments. Toka did not emerge from a Silicon Valley garage populated by four college kids trying to build a better doorbell camera. Its pedigree runs straight through the Israeli national-security establishment.
If you recall from that article, Israel has spent decades developing an unusually sophisticated cyber workforce through its military and intelligence institutions, especially Unit 8200 and adjacent cyber commands. Veterans routinely leave government service for the private technology sector, taking with them skills acquired while working on real intelligence and military problems. Many have built successful cybersecurity companies, and have made the Israelis billions. Most are invasive tech that spies on Americans, including Cellebrite’s phone-forensics technology and the Pegasus spyware. Much of that tech, experts believe, was created through U.S. public-sector research and development by the CIA’s InQTel or DARPA, shared with Israeli Intelligence (for free), given to a freshly “retired” Unit 8200 CyberCommando, and sold back to Americans through an Israeli Silicon Valley start-up. We know the money is going back to Israel. But many suspect our intelligence data is, too. The Waze GPS app is one example that has raised these suspicions. If you’ve used it, there’s a good chance Israeli intelligence knows the route you take to church.
That was the central historical lesson I drew from PROMIS in February. The cleverest way into another country’s information infrastructure is not necessarily to break through the window. Sometimes you build something the target desperately wants, convince him to purchase it, and let him open the front door himself.
Toka is now opening that door in the United States. But before I get to Washington, another connection makes the sudden national fixation on Flock cameras almost perfectly timed. Toka and Flock do not merely inhabit the same world of surveillance technology. They share a major investor, and one of the men behind that investment firm personally tried to put both technologies into the hands of the same American police department. That man is Ben Horowitz.
If you appreciate my work, please grab a premium subscription to access exclusive content (like the rest of this article) and get a fantastic 20% discount if you act now.

















