Pay Tel, a prison communications provider serving facilities across much of the United States, secured a publicly accessible Microsoft Azure storage server after researchers found it exposed without password protection. The exposed data included at least 300,000 scans of driver’s licenses and other government-issued IDs, as well as profile photos, inmate communications, handwritten notes, text messages, and financial records tied to customers using the service to contact incarcerated people.
Researchers said many uploaded photos also contained precise geolocation metadata that in some cases could reveal users’ home addresses, increasing the sensitivity of the leak. UpGuard reported notifying Pay Tel on May 7 and following up before the server was secured, but the company had not publicly acknowledged the exposure or said whether affected individuals or state attorneys general would be notified under breach disclosure laws. The incident marks Pay Tel’s second known security event in two years, following a ransomware attack in 2025.

Map this exposure pattern across your cloud, code, and identities.
3 events from the most recent confirmed update back to the earliest known activity.
After UpGuard's notification and follow-up, Pay Tel secured the publicly exposed Azure storage server. Reporting said the company had not publicly acknowledged the incident at the time of publication.
Pay Tel experienced a ransomware attack in June 2025, marking the company's earlier known security incident referenced in later reporting about the data exposure.
UpGuard discovered that a Microsoft Azure storage server belonging to Pay Tel was publicly accessible without a password and notified the company on May 7. Researchers said the exposed data included at least 300,000 driver's license scans and other sensitive customer and inmate-related records.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.