A security lapse at prison pay phone service Pay Tel publicly exposed over 300K callers’ driver’s licenses

A security lapse at prison pay phone service Pay Tel publicly exposed over 300K callers’ driver’s licenses

Pay Tel, a service that facilitates phone calls for inmates, has inadvertently exposed a significant security vulnerability, leading to the public accessibility of a cloud server containing sensitive personal data. Cybersecurity firm UpGuard uncovered the issue, revealing that a Microsoft Azure-hosted server held at least 300,000 scans of driver’s licenses and other government-issued identification documents used by Pay Tel customers. The server was found to be unsecured, lacking a password, which allowed anyone with internet access to locate and view the stored data. Pay Tel provides communication devices, such as tablets, to prisons across the United States, requiring customers to submit identification documents and profile photos for service activation. Unfortunately, this sensitive information was among the data that became exposed. In addition to personal identification, researchers from UpGuard indicated that various inmate communications—including text messages, handwritten notes, and financial records—were also compromised due to this security breach. UpGuard notified Pay Tel about the vulnerability on May 7, and despite follow-ups, it appears the server remained unsecured for several days. As of now, Pay Tel has not publicly acknowledged this security incident. This leak adds to a worrying trend where technology companies fail to adequately protect sensitive user information, often due to misconfigurations or inadequate cybersecurity practices. UpGuard highlighted that many of the uploaded images contained geolocation data, which could potentially reveal the home addresses of the individuals involved. This incident marks Pay Tel's second known security issue in just two years, following a ransomware attack in June 2025. The company's president, Vincent Townsend, has not responded to inquiries regarding this latest breach, and it remains uncertain whether affected individuals will be notified or if any legal obligations under state data breach laws will be fulfilled. The accountability for cybersecurity practices at Pay Tel remains unclear.

Sources : TechCrunch

Published On : May 28, 2026, 18:35

Mobile
Unleashing the Power of AI: The 5 Smartphones Redefining Mobile Photography

Artificial Intelligence (AI) is transforming our daily experiences, permeating various aspects of technology, including ...

Business Today | Jul 26, 2026, 07:05
Unleashing the Power of AI: The 5 Smartphones Redefining Mobile Photography
Science
Vision Breakthrough: US Startup Launches Groundbreaking Retina Chip in Europe

Science Corp is poised to introduce a revolutionary retina chip in Europe, designed to restore partial vision for indivi...

Business Today | Jul 25, 2026, 01:00
Vision Breakthrough: US Startup Launches Groundbreaking Retina Chip in Europe
Computing
Reclaiming Control: Librarians Host Workshops to Help People Navigate AI Tools

In a lively library setting in South Philadelphia, Charlie Bailey, a local librarian, humorously noted, "Everybody’s on ...

TechCrunch | Jul 25, 2026, 16:20
Reclaiming Control: Librarians Host Workshops to Help People Navigate AI Tools
Cybersecurity
The Aluminum Foil Trend: A DIY Shield Against Wireless Identity Theft

Have you noticed an unusual trend where people are wrapping their wallets in aluminum foil? This peculiar practice has e...

Business Today | Jul 25, 2026, 02:45
The Aluminum Foil Trend: A DIY Shield Against Wireless Identity Theft
Startups
The Boring Company Eyes $4 Billion Funding Boost Amid Expanding Tunnel Ventures

Elon Musk's tunneling enterprise, The Boring Company, is reportedly negotiating a substantial funding round of $4 billio...

TechCrunch | Jul 25, 2026, 19:50
The Boring Company Eyes $4 Billion Funding Boost Amid Expanding Tunnel Ventures
View All News