Admin
Lake City Magazine
Sign In
09:52

Officer charged after allegedly using Flock to track woman’s vehicles more than 2,000 times

1 views
August 27, 2026
Reading Time: 09:52

LOUISVILLE, Ky. — In an alarming case that highlights the growing vulnerabilities surrounding law enforcement data access, a Kentucky police officer has been arrested and charged following a months-long internal investigation. Authorities allege that the officer systematically abused his official privileges, leveraging a sophisticated network of automated license plate-reading cameras to stalk and monitor the movements of a woman across multiple states.

Asad Zahir, a 40-year-old law enforcement officer with the Shively Police Department, now faces a battery of criminal charges after investigators uncovered a staggering digital footprint of unauthorized database queries. According to court records and arrest citations filed by his own department, Zahir’s alleged campaign of digital surveillance spanned nearly half a year, piercing the privacy of a citizen and turning advanced public safety infrastructure into a personal tracking tool.

The arrest has ignited renewed scrutiny over the safeguards governing access to law enforcement surveillance technologies, particularly automated license plate reader (ALPR) systems like those manufactured by Flock Safety. As communities nationwide grapple with the balance between public safety and individual privacy, this case serves as a stark reminder of the potential for technological overreach and the severe consequences when the guardians of the law breach public trust.


Executive Overview

The investigation into Officer Asad Zahir culminated in late August, revealing a troubling breach of institutional authority. According to the Shively Police Department, Zahir utilized his credentials to access the Flock safety system—a widespread network of stationary, automated cameras that capture and log vehicle license plates, make, model, color, and directional travel in real time.

Between January 1 and May 2, Zahir allegedly executed an astonishing 2,048 searches within the database. Investigators determined that these queries were not conducted in the course of legitimate police work or active criminal investigations. Instead, they were laser-focused on two specific vehicle registrations in Kentucky belonging to the mother of his child.

The fallout from Zahir’s alleged digital tracking extends far beyond professional misconduct. Court documents outline a broader pattern of alleged harassment and intimidation directed at the victim during the exact five-month timeframe of the searches. The victim, feeling increasingly unsafe and monitored across state lines in both Kentucky and Indiana, ultimately sought and secured a temporary protective order against the officer in a neighboring Indiana court.

Zahir has been formally charged with five counts of first-degree official misconduct and five counts of fourth-degree unlawful access to a computer. Following his arrest, he was released on personal recognizance and is scheduled to face formal arraignment in Jefferson District Court.


Detailed Chronology of the Investigation

The unfolding of the case against Asad Zahir reveals a calculated misuse of police databases that persisted for months before setting off internal alarms. Law enforcement and judicial records provide a clear timeline of the events leading up to his arrest.

The Five-Month Surveillance Window (January 1 – May 2)

According to the arrest citation, the illicit tracking began on New Year’s Day and continued unabated through early May. During this 121-day window, Zahir allegedly treated the Flock camera network as his personal tracking system.

Investigators analyzing system logs discovered that Zahir entered specific license plate numbers associated with the victim over two thousand times. The network’s architecture—designed to help law enforcement locate stolen vehicles, Amber Alert suspects, and wanted fugitives—effectively tracked the victim’s daily routines, work commutes, personal visits, and interstate travels between Kentucky and Indiana. Because Flock cameras timestamp and geolocate every vehicle capture, Zahir was purportedly able to piece together a real-time mosaic of the victim’s whereabouts without ever needing to physically follow her.

Escalation and the Protective Order

As the digital monitoring intensified, the interpersonal dynamic deteriorated. Court records indicate that Zahir’s behavior extended beyond passive digital surveillance into active harassment. The victim reported receiving threatening comments and experiencing escalating intimidation from the officer.

Recognizing the gravity of the situation and the inherent danger posed by an individual with law enforcement training, access to sensitive databases, and a firearm, the victim pursued legal intervention. She successfully petitioned an Indiana court for a temporary protective order against Zahir, legally barring him from contact and underscoring the severity of the alleged harassment.

Discovery, Internal Investigation, and Arrest

While specific details regarding how the internal audit was triggered remain restricted as the judicial process unfolds, modern ALPR platforms typically feature administrative tracking tools designed to log every search query back to an individual user’s credentials. Such audits are frequently initiated following internal complaints, red flags raised by system anomalies, or reports filed by citizens experiencing unusual patterns of harassment.

Upon reviewing the query logs, the Shively Police Department launched a swift internal inquiry. Confronted with the overwhelming digital evidence—specifically the 2,048 unauthorized searches tied directly to his login credentials—investigators moved forward with criminal charges. Zahir was booked into the Louisville Metropolitan Department of Corrections (LMDC) before being released on personal recognizance pending his upcoming court appearance in Jefferson District Court.


Supporting Context and Metrics: The Scale of ALPR Misuse

To fully grasp the magnitude of the allegations against Officer Zahir, it is necessary to examine the technology at the center of the controversy: Automated License Plate Reader systems, colloquially referred to in this case by the dominant private vendor, Flock Safety.

Understanding Flock Safety Networks

Flock cameras have rapidly become ubiquitous fixtures across American municipalities, suburban neighborhoods, and law enforcement jurisdictions. Mounted on utility poles, traffic lights, and entranceways to residential communities, these solar- or AC-powered cameras capture high-resolution images of passing vehicles. Using optical character recognition (OCR) software, the system instantly reads license plates and logs metadata—including vehicle make, body style, color, unique vehicle features (such as bumper stickers or roof racks), and the precise GPS coordinates and timestamp of the capture.

This data is uploaded to a centralized cloud database. Law enforcement agencies subscribe to these networks, granting officers the ability to set "hot lists" that alert authorities when a specific vehicle of interest passes a camera anywhere within the interconnected network. While proponents praise ALPRs for solving crimes, recovering stolen vehicles, and assisting in missing persons cases, civil liberties advocates have long warned about the immense potential for abuse, mass surveillance, and stalking.

By the Numbers: Analyzing Zahir’s Digital Footprint

The quantitative data compiled by investigators paints a vivid picture of obsessive monitoring:

  • 121 Days: The duration of the alleged tracking period, stretching from January 1 to May 2.
  • 2,048 Searches: The total number of unauthorized database queries executed by Zahir.
  • 2 Vehicle Registrations: The specific targets of the queries, both linked to the mother of his child.
  • 2 States: The geographic scope of the surveillance, covering movements across Kentucky and Indiana.
  • 10 Criminal Counts: The total charges filed against the officer, split evenly between official misconduct and unlawful computer access.

Averaging out the data, Zahir’s alleged activity involved querying the database roughly 17 times per day every single day for five months. This sustained, high-volume interaction with a law enforcement database intended for criminal interdiction highlights a systemic vulnerability: credentialed access, when left unmonitored or unchecked by automated supervisory filters, can be easily weaponized by bad actors within an agency.


Legal Charges and Statutory Framework

The charges filed against Asad Zahir carry significant legal weight, reflecting both the abuse of public office and the unauthorized exploitation of protected digital infrastructure.

First-Degree Official Misconduct

Under Kentucky law, a public servant commits first-degree official misconduct when, with intent to obtain or confer a benefit or to injure another person, they knowingly refrain from performing a duty imposed upon them by law or clearly inherent in the nature of their office, or commit an unauthorized act which they purport to act by virtue of their office.

In Zahir’s case, prosecutors argue that using police-issued credentials to stalk an individual for personal, non-law enforcement purposes represents a textbook abuse of public office and a direct violation of the oath sworn by law enforcement personnel. This charge is classified as a Class A misdemeanor in the Commonwealth of Kentucky, carrying potential penalties including jail time, fines, and the permanent forfeiture of law enforcement certification.

Fourth-Degree Unlawful Access to a Computer

The companion charges of fourth-degree unlawful access to a computer address the digital breach itself. Under Kentucky revised statutes, this offense occurs when a person knowingly and without authorization accesses, alters, destroys, or obtains data from a computer, computer system, or computer network.

Law enforcement databases—including state criminal justice information systems and private vendor networks contracted by police departments—are legally classified as secure restricted environments. Officers are granted access solely for official duties governed by department policy, state law, and federal regulations. Bypassing these guardrails for personal vendertas, domestic disputes, or stalking constitutes a direct digital trespass.


Official Statements and Institutional Response

The arrest of a sworn officer for digital stalking has placed the Shively Police Department under a microscope, prompting conversations regarding departmental accountability and technological oversight.

Law enforcement leadership in Shively acted decisively once the internal audit uncovered the scope of Zahir’s searches. By compiling the arrest citation and moving forward with criminal charges rather than seeking internal administrative concealment, the department signaled a commitment to accountability. However, the incident has also invited broader critique from privacy advocates who question how an officer could execute over two thousand unauthorized searches over a five-month period without immediate red flags halting the activity.

Civil rights organizations, including the American Civil Liberties Union (ACLU) of Kentucky, have frequently raised concerns regarding the expansion of ALPR networks without robust legislative guardrails. While officials from private vendors like Flock Safety maintain that their systems include audit trails and security protocols, cases of individual officer malfeasance underscore the reality that technology is only as secure as the human gatekeepers permitted to use it.

Legal analysts point out that police departments utilizing third-party surveillance networks face mounting pressures to implement real-time anomaly detection software. If an officer’s query volume regarding a specific private citizen exceeds normal investigative thresholds—or involves individuals with whom the officer shares personal domestic relationships—automated alerts could theoretically notify internal affairs before months of stalking can occur.


Future Outlook and Judicial Proceedings

As the legal process moves forward, several critical milestones and broader societal questions loom on the horizon.

Immediate Judicial Timeline

Asad Zahir is scheduled for his formal arraignment in Jefferson District Court. Given that he was released on personal recognizance following his initial booking, the upcoming court dates will determine the pre-trial conditions, potential suspension or revocation of his police powers, and the discovery schedule as prosecutors share evidence with the defense.

Legal experts anticipate that the defense will scrutinize the precise extraction of database logs, while the prosecution will rely heavily on the digital trail of 2,048 distinct queries to demonstrate intent and pattern. Furthermore, the existence of the Indiana protective order secured by the victim will likely play a prominent role in establishing the context of harassment and fear.

Long-Term Implications for Law Enforcement Technology

Beyond the courtroom drama surrounding Zahir individually, this case serves as a watershed moment for police agencies across Kentucky and the broader United States regarding the integration of private surveillance tech.

Key questions facing police administrators include:

  1. Audit Frequency: How often do departments audit ALPR and database queries to ensure compliance with privacy laws?
  2. Algorithmic Oversight: Can tech vendors and police IT departments implement automated tripwires that flag domestic or personal searches based on shared last names, addresses, or prior relationships?
  3. Victim Protection: How can agencies better protect victims of domestic violence when the alleged perpetrator possesses the technological tools of the state?

The case of Asad Zahir demonstrates that the digital transformation of policing, while offering unprecedented investigative capabilities, simultaneously expands the potential harm inflicted by rogue actors within the badge. As the legal proceedings unfold in Jefferson District Court, the outcome will resonate far beyond Shively, setting a vital precedent for accountability in the age of automated public surveillance.

Tags:

0 Comments