Skip to main content
Back to overview
High

Prison Communication Service Pay Tel Exposed Hundreds of Thousands of Driver's Licenses

Prison communication service Pay Tel exposed hundreds of thousands of driver’s licenses As reported by TechCrunch, prison calling service Pay Tel has experienced a significant data security lapse, exposing sensitive…

Key points

  • Approximately 300,000 driver's license scans and other government-issued IDs exposed.
  • Inmate communications, including text messages, handwritten notes, and financial records, were also compromised.
  • Caused by an unsecured Microsoft Azure cloud server (misconfiguration).

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Threat source not confirmed

03

Potential impact

Potential operational disruption

Confidentiality, Availability

Published
May 29, 2026
Updated
Jul 22, 2026
Confidence
High
Evidence
3 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch ransomware, endpoint compromise and business interruption exposure.

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data, Server or cloud data store

Mentioned entities

PaytelData DisclosurePrison Communication Service Pay TelExposed Hundreds of Thousands ofDriverLicenses PrisonPay TelTechCrunchCybersecurityUpGuard

Quick context

Questions about this signal

What happened in this signal?

Prison communication service Pay Tel exposed hundreds of thousands of driver’s licenses As reported by TechCrunch, prison calling service Pay Tel has experienced a significant data security lapse, exposing sensitive information of its users due to a publicly accessible cloud server. Cybersecurity firm UpGuard discovered an unprotected Microsoft Azure server managed by Pay Tel containing at least 300,000 driver's license scans and other government-issued identification documents. The server, left without a password, also exposed inmate communications, including text messages, handwritten notes, and financial records. Users signing up for Pay Tel's services are required to submit identification documents and profile photos, which were among the compromised data. Some uploaded photos contained precise location data, potentially revealing home addresses. This marks Pay Tel's second security incident in two years, following a ransomware attack in June 2025. The company has not yet publicly acknowledged the breach or stated whether it will notify affected individuals or state attorneys general as required by data breach notification laws. A security lapse at prison pay phone service Pay Tel publicly exposed over 300K callers’ driver’s licenses Pay Tel, a service that facilitates phone calls for inmates, has inadvertently exposed a significant security vulnerability, leading to the public accessibility of a cloud server containing sensitive personal data. Cybersecurity firm UpGuard uncovered the issue, revealing that a Microsoft Azure-hosted server held at least 300,000 scans of driver’s licenses and other government-issued identification documents used by Pay Tel customers. The server was found to be unsecured, lacking a password, which allowed anyone with internet access to locate and view the stored data. Pay Tel provides communication devices, such as tablets, to prisons across the United States, requiring customers to submit identification documents and profile photos for service activation. Unfortunately, this sensitive information was among the data that became exposed. In addition to personal identification, researchers from UpGuard indicated that various inmate communications—including text messages, handwritten notes, and financial records—were also compromised due to this security breach. UpGuard notified Pay Tel about the vulnerability on May 7, and despite follow-ups, it appears the server remained unsecured for several days. As of now, Pay Tel has not publicly acknowledged this security incident. This leak adds to a worrying trend where technology companies fail to adequately protect sensitive user information, often due to misconfigurations or inadequate cybersecurity practices. UpGuard highlighted that many of the uploaded images contained geolocation data, which could potentially reveal the home addresses of the individuals involved. This incident marks Pay Tel's second known security issue in just two years, following a ransomware attack in June 2025. The company's president, Vincent Townsend, has not responded to inquiries regarding this latest breach, and it remains uncertain whether affected individuals will be notified or if any legal obligations under state data breach laws will be fulfilled. The accountability for cybersecurity practices at Pay Tel remains unclear. Startup Founder Secures $31 Million to Revolutionize AI Cooling Solutions As artificial intelligence technology continues to advance, the need for effective cooling systems for data centers has ... Google Employees Rally for Enhanced Layoff Protections Amid AI Restructuring In the face of widespread layoffs fueled by ongoing AI-driven transformations, anxiety is palpable among Google’s workfo ... Revolutionizing Training: Synthesia Launches AI-Powered Roleplay Sessions Synthesia, a pioneering British startup, is taking a bold step beyond its traditional focus on creating interactive trai ... Apple Set to Introduce Flexible Upgrade Program for Devices Apple is on the verge of launching an innovative program called the 'Apple Upgrade,' developed in collaboration with Kla ... Rumors of Anthropic's Acquisition of Robotics Firm Ignite AI Community This year has been monumental for AI acquisitions, with companies like Anthropic and OpenAI aggressively expanding their ... We’re excited to explore how we can turn your ideas into impactful solutions.

When was this signal reported?

Shadow Tier lists May 29, 2026 as the signal date.

Which organization is connected to this signal?

Paytel is the organization connected to this public signal.

Explore Paytel
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents