One bad apple. That was all it took to shut down Flock automatic license plate readers across a Florida county.
It wasn’t a systemic failure. No massive data breach. Just one detective. Brandy Almany.
She worked for the Sumter County Sheriff’s Office. She’d been on the job since 2019. But an internal audit caught her red-handed.
The incident highlights why law enforcement agencies are reconsidering ALPR system access controls and how fragile trust in these tools really is.
Here is what happened. And why it matters.
How a Detective Misused Florida Law Enforcement Databases
On July 23, something looked wrong in the logs.
An internal audit flagged unusual activity. The pattern didn’t fit legitimate criminal investigations. It looked personal.
Investigators dug deeper. They found that Almany had accessed three powerful systems:
- Comprehensive Case Information System (CCIS )
- Florida’s Driver and Vehicle Information Database (DAVID )
- Flock’s automated license plate recognition (ALPR ) network
Why? To track her husband’s ex-wife.
Almany allegedly fabricated investigative justifications. She used unrelated Sheriff’s Office case numbers to mask her searches. The goal was to make the surveillance look official.
It worked, for a while. Until the audit caught up.
Now she faces charges. One count of official misconduct. Three counts of offenses against computer use.
She allegedly exceeded her authorized access. She falsified electronic records. She hid unauthorized searches behind false paperwork.
“The alleged actions violated the department’s standards of professionality and integrity.” — Sheriff Pat Breeden
This isn’t an isolated case. Police and public employees have misused ALPR tech before. But this one triggered immediate action.
Why the Sumter County Sheriff Disabled Flock Cameras Immediately
Sheriff Pat Breeden didn’t wait. He suspended the Flock ALPR system entirely.
The department is now conducting a comprehensive audit. Every database. Every access point.
Almany could face more charges. It depends on what the audit reveals.
But the move sends a signal. Accountability isn’t just about punishing the individual. It’s about questioning the system that allowed the breach.
Some victims of ALPR misuse never know they’re being tracked. They only find out later through public records requests.
Recently, Flock changed how data is labeled in its records. That makes independent scrutiny harder.
In Almany’s case, Flock’s own audit system flagged the abuse. But should we rely on post-hoc detection?
Is it enough to catch misuse after the damage is done? Or should safeguards prevent it from happening in the first place?
When emotions run high, temptation is real. Access is powerful. Restraint isn’t always guaranteed.
The current model assumes audits are enough. Cases like this suggest otherwise.
Which Law Enforcement Database Access Rules Are Failing Now?
We assume audits will catch bad actors. But they don’t always.
Flock’s system did here. But it wasn’t perfect. The data labeling changes made outside checks harder.
This raises a critical question.
Who monitors the monitors?
If only internal audits or vendor systems can detect misuse, are we relying too much on self-regulation?
Victims shouldn’t have to dig through records to know they were stalked. Systems shouldn’t require external pressure to improve.
Almany’s case is a symptom. Not the disease.
The disease is unchecked access. Lack of real-time safeguards. A culture where “I know a guy with access” still exists.
Sheriff Breeden pulled the plug. Good start.
But will other counties follow? Or wait until their own detective crosses the line?
That remains to be seen.
The cameras are off in Sumter County. For now.
But the questions linger. How do we trust these tools when the people using them aren’t fully trusted?
No neat answers. Just open doors.


















