
AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.
UpGuard found a public Azure bucket with ID scans and inmate documents at prison calling firm Pay Tel. Pay Tel says it was secured and no one else accessed it.
What happened
Security firm UpGuard says that on 4 May 2026 it found a publicly accessible Microsoft Azure storage bucket belonging to Pay Tel Communications, which supplies tablets and calling services to jails, mainly in the south-eastern US. The bucket held about 3.4 million images (1.1 TB), including an estimated 300,000 unique driver's licences of people who signed up to call inmates, plus inmate legal and financial documents and personal messages. It needed no password. UpGuard says it notified Pay Tel and later confirmed the bucket was secured. TechCrunch reported the findings on 28 May.
Confirmed vs. claimed
Confirmed by Pay Tel: in a website statement, the company acknowledges a cloud storage setting that allowed public access to files from customer account setup, including ID images. It says it was contacted on 11 May, disabled public access the same day and finished fixes by 14 May. UpGuard gives an earlier first notice date of 7 May.
Disputed / unknown: Pay Tel says there is no sign anyone other than the researchers accessed the files and no evidence of misuse, and that it currently sees no risk of harm. That means it may not send notices. The figures on volume come from UpGuard, not Pay Tel. Pay Tel also says it is still evaluating a separate June 2025 incident.
Who is affected
People who created Pay Tel accounts to contact incarcerated relatives or friends, largely in Georgia and North Carolina, and inmates whose documents were stored.
What to do
- If you used Pay Tel, assume your licence image may have been exposed and watch for identity misuse.
- US residents can place a free credit freeze with the three bureaus.
- Be wary of calls or messages that claim to be about an inmate's account and ask for payment.
- Contact Pay Tel through its official website to ask whether your files were in the bucket.
- See our guide on what to do after a data breach notice.
Sources
- UpGuard — Breaking Confinement: how a corrections vendor exposed inmate communications (May 2026) Primary
- Pay Tel Communications — Security statement (May 2026) Primary
- TechCrunch — A security lapse at prison pay phone service Pay Tel publicly exposed over 300K callers' driver's licenses (28 May 2026) Secondary
More breaches in United States
- IDScan.net — 01 Sep 2026
- Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) — 27 Aug 2026
- Boston Scientific — 26 Aug 2026
- Aesto Health — 14 Aug 2026
- DentaQuest — 17 Jul 2026