A security lapse at prison pay phone service Pay Tel publicly exposed over 300K callers’ driver’s licenses

A security lapse at prison pay phone service Pay Tel publicly exposed over 300K callers’ driver’s licenses

Pay Tel, a service that facilitates phone calls for inmates, has inadvertently exposed a significant security vulnerability, leading to the public accessibility of a cloud server containing sensitive personal data. Cybersecurity firm UpGuard uncovered the issue, revealing that a Microsoft Azure-hosted server held at least 300,000 scans of driver’s licenses and other government-issued identification documents used by Pay Tel customers. The server was found to be unsecured, lacking a password, which allowed anyone with internet access to locate and view the stored data. Pay Tel provides communication devices, such as tablets, to prisons across the United States, requiring customers to submit identification documents and profile photos for service activation. Unfortunately, this sensitive information was among the data that became exposed. In addition to personal identification, researchers from UpGuard indicated that various inmate communications—including text messages, handwritten notes, and financial records—were also compromised due to this security breach. UpGuard notified Pay Tel about the vulnerability on May 7, and despite follow-ups, it appears the server remained unsecured for several days. As of now, Pay Tel has not publicly acknowledged this security incident. This leak adds to a worrying trend where technology companies fail to adequately protect sensitive user information, often due to misconfigurations or inadequate cybersecurity practices. UpGuard highlighted that many of the uploaded images contained geolocation data, which could potentially reveal the home addresses of the individuals involved. This incident marks Pay Tel's second known security issue in just two years, following a ransomware attack in June 2025. The company's president, Vincent Townsend, has not responded to inquiries regarding this latest breach, and it remains uncertain whether affected individuals will be notified or if any legal obligations under state data breach laws will be fulfilled. The accountability for cybersecurity practices at Pay Tel remains unclear.

Sources : TechCrunch

Published On : May 28, 2026, 18:35

Startups
SpaceX Completes Acquisition of AI Startup Cursor

In a significant move within the tech industry, SpaceX has officially integrated AI coding startup Cursor into its opera...

TechCrunch | Aug 15, 2026, 16:55
SpaceX Completes Acquisition of AI Startup Cursor
Automotive
Battle of the Bots: Comparing Rivian's Autonomy+ with Tesla's FSD

In the quest for the ultimate advanced driver-assistance system (ADAS), Rivian Automotive is making bold claims about th...

CNBC | Aug 15, 2026, 12:20
Battle of the Bots: Comparing Rivian's Autonomy+ with Tesla's FSD
Cybersecurity
Protect Your AI Accounts: A Guide to Identifying Unwanted Access

As with any online service, your accounts on popular AI platforms like ChatGPT, Claude, and Perplexity can become target...

TechCrunch | Aug 15, 2026, 16:40
Protect Your AI Accounts: A Guide to Identifying Unwanted Access
AI
AI Trust Crisis: Anthropic's Dario Amodei Calls for a Balanced Perspective

Dario Amodei, the CEO of Anthropic, has recently addressed concerns regarding his portrayal of artificial intelligence a...

TechCrunch | Aug 16, 2026, 17:15
AI Trust Crisis: Anthropic's Dario Amodei Calls for a Balanced Perspective
AI
Tech Giants Propel AI Investments Amid Easing Inflation

Recent market trends indicate a notable easing in inflation, largely driven by the influential performances of tech gian...

CNBC | Aug 15, 2026, 14:35
Tech Giants Propel AI Investments Amid Easing Inflation
View All News