2026 Pay Tel — Azure storage exposed 300K+ caller IDs and inmate communications (UpGuard)
Data compromised
Driver’s license scans, government IDs, profile photos, inmate text messages and financial records per UpGuard
Technical writeup
UpGuard researchers identified a publicly exposed Microsoft Azure storage server managed by U.S. prison communications vendor Pay Tel storing at least 300,000 driver’s license scans and other government-issued identity documents from callers signing up for inmate calling services, plus inmate communications including text messages and financial records. UpGuard alerted Pay Tel on May 7, 2026; the bucket was secured days later. Pay Tel had not issued a formal customer notice at TechCrunch reporting time; BreachHistory uses UpGuard’s verified exposure count.
Root cause
Publicly exposed Microsoft Azure storage server (misconfiguration)