Pay Tel security lapse exposes 300k caller IDs – Claril Noticias

US-based prison communications provider Pay Tel has secured an unprotected cloud server that exposed over 300,000 driver’s licences and sensitive personal data of its users, cybersecurity firm UpGuard revealed on May 7.

Unprotected Azure Server Left Data Exposed

Security researchers at UpGuard disclosed in a blog post that they identified an open Microsoft Azure-hosted storage server managed by Pay Tel. The database lacked basic password protection, leaving highly sensitive government-issued identity documents accessible to anyone on the public web.

What Information Was Compromised?

Pay Tel distributes tablets and other communication technologies to correctional facilities across the United States, enabling inmates to receive calls. To use the service, external customers must register by uploading a profile photo and a copy of their official identification. UpGuard confirmed that these registration documents were entirely exposed, alongside inmate communications such as text messages, handwritten notes, and financial transactions.

Geotagged Photos Reveal Home Addresses

Beyond identity documents, the security lapse exposed metadata embedded within the user-uploaded images. UpGuard noted that many of these photos contained precise GPS coordinates indicating exactly where they were taken. In several instances, this metadata was granular enough to pinpoint the users’ home addresses, posing an additional physical security risk.

A History of Cybersecurity Failures

This incident represents Pay Tel’s second major security failure in recent years, following a ransomware attack in June 2025. The recurring vulnerability highlights an ongoing industry-wide issue where technology firms misconfigure cloud storage systems, failing to meet basic cybersecurity standards and leaving consumer data vulnerable.

UpGuard alerted Pay Tel to the leak on May 7, following up days later before the server was finally secured. Despite the gravity of the exposure, Pay Tel has yet to publicly acknowledge the incident. The company’s president, Vincent Townsend, did not respond to inquiries regarding the breach, and it remains unclear whether the firm intends to notify the affected individuals or report the exposure to state attorneys general as required by US data breach notification laws. Furthermore, it is currently unknown who manages cybersecurity operations at Pay Tel.

By Claril

Leave a Reply

Your email address will not be published. Required fields are marked *