OTHER

Security Breach at Pay Tel: Over 300,000 Drivers’ Licenses Exposed from Prison Pay Phone Service Users

The prison communication provider Pay Tel has disclosed a publicly accessible cloud server that contains hundreds of thousands of driver’s licenses and other sensitive user data, according to a cybersecurity firm that alerted the company about the breach.

UpGuard, a team of security researchers, announced in a blog post that they found a Microsoft Azure-hosted storage server containing at least 300,000 scans of driver’s licenses alongside other government-issued identity documents linked to Pay Tel.

The server was unprotected by a password, allowing the data to be easily accessed over the internet.

Pay Tel provides tablets and communication devices in prisons throughout much of the U.S., allowing inmates to make phone calls. To access the service, customers must provide identification documents and a profile picture, both of which UpGuard confirmed were compromised. Furthermore, the researchers uncovered that communications between inmates, including text messages, handwritten notes, and financial records, were also at risk due to this security lapse.

UpGuard informed Pay Tel on May 7 after verifying the company’s ownership of the server and followed up shortly after to confirm its security. Currently, Pay Tel has not acknowledged the security incident.

The data exposure at Pay Tel underscores a worrying trend of technology companies inadvertently leaving sensitive information open on the internet. TechCrunch has reported similar cases where companies misconfigure their systems or fail to follow cybersecurity best practices, exposing personal data to anyone online.

According to UpGuard, many of the user-uploaded images contained geolocation data that could identify the precise location where the pictures were taken, potentially exposing individuals’ home addresses.

This incident represents Pay Tel’s second known security breach in two years, following a ransomware attack in June 2025.

Vincent Townsend, the president of Pay Tel, did not respond to TechCrunch’s questions regarding the breach. It remains unclear if the company intends to notify affected individuals or inform state attorneys general in compliance with U.S. data breach notification laws.

TechCrunch has been unable to ascertain who, if anyone, is responsible for cybersecurity at Pay Tel.

When you make purchases through links in our articles, we may earn a small commission. This does not impact our editorial independence.