Breach tracker

Breach report

Researchers found open Pay Tel storage holding 300,000 callers' ID scans

ConfirmedDisclosed United StatesTelecomBy Vivek Kumar
Records UnknownCause Misconfiguration
Conceptual illustration: A generic institutional payphone handset connected to an open cloud-storage sculpture containing blank identity cards. Headline: PAY TEL DATA EXPOSURE.

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.

UpGuard found a public Azure bucket with ID scans and inmate documents at prison calling firm Pay Tel. Pay Tel says it was secured and no one else accessed it.

What happened

Security firm UpGuard says that on 4 May 2026 it found a publicly accessible Microsoft Azure storage bucket belonging to Pay Tel Communications, which supplies tablets and calling services to jails, mainly in the south-eastern US. The bucket held about 3.4 million images (1.1 TB), including an estimated 300,000 unique driver's licences of people who signed up to call inmates, plus inmate legal and financial documents and personal messages. It needed no password. UpGuard says it notified Pay Tel and later confirmed the bucket was secured. TechCrunch reported the findings on 28 May.

Confirmed vs. claimed

Confirmed by Pay Tel: in a website statement, the company acknowledges a cloud storage setting that allowed public access to files from customer account setup, including ID images. It says it was contacted on 11 May, disabled public access the same day and finished fixes by 14 May. UpGuard gives an earlier first notice date of 7 May.

Disputed / unknown: Pay Tel says there is no sign anyone other than the researchers accessed the files and no evidence of misuse, and that it currently sees no risk of harm. That means it may not send notices. The figures on volume come from UpGuard, not Pay Tel. Pay Tel also says it is still evaluating a separate June 2025 incident.

Who is affected

People who created Pay Tel accounts to contact incarcerated relatives or friends, largely in Georgia and North Carolina, and inmates whose documents were stored.

What to do

  • If you used Pay Tel, assume your licence image may have been exposed and watch for identity misuse.
  • US residents can place a free credit freeze with the three bureaus.
  • Be wary of calls or messages that claim to be about an inmate's account and ask for payment.
  • Contact Pay Tel through its official website to ask whether your files were in the bucket.
  • See our guide on what to do after a data breach notice.

Sources

More breaches in United States