An exposed Azure storage bucket contained millions of documents sent through a jail messaging app, including driver's licenses used for identity verification.
On May 4th UpGuard researchers discovered a publicly exposed Azure storage bucket belonging to Pay Tel Communications, a corrections vendor who supplies tablets and communications services to jail inmates, especially in the American Southeast. The bucket held 3.4 million documents in 1.1TB, all images. These images contained sensitive data, including an estimated 300,000 unique driver’s licenses, inmate legal and financial documents, and personal/intimate communications. After notifying Pay Tel of the exposure, the bucket was secured.
ScopeAffected entities:
Affected Individuals:
To understand why this data was collected in the first place, it helps to understand the history of jail telecommunications that led from payphones to tablets.
Privatized communications in the American prison system have evolved from heavily monitored public payphones into a multibillion dollar industry. This evolution was driven by rapid technological transformation, massive profit margins, deregulation and a literally captive market. Up until the 1980s, prisons used payphones, the same as on a street corner, usually established by AT&T prior to their ant-trust breakup.
Pay Tel Communications was founded in 1986. Initially, they serviced public payphones across the American southeast. But as telecommunications were deregulated, Pay Tel shifted entirely to inmate telecom services in 1989, seeing massive growth potential in the specialized contracts. By the 1990s, prison communications had been fully privatized. Providers began offering specialized "Inmate Telephone Systems" (ITS) that included automated operators, voice-recognition, and the ability to block specific phone numbers. Increased “security” allowed further surveillance and logging of inmate communications.
This era gave rise to the “site commission” contract model. To win exclusive contracts from sheriffs and state departments of corrections, private phone companies promised to return a massive percentage of their phone revenue (sometimes 60–80%) back to the facility or the county's general fund. Collect calls from jails and prisons regularly cost upwards of $1.00 per minute, with mandatory "connection fees" adding $3.00 to $5.00 the moment a call was accepted.
The Video Call EraEventually, the public and regulatory bodies such as the FCC began targeting the exorbitant cost of voice calls. Regulations such as the Martha Wright-Reed Just and Reasonable Communications Act authorized the FCC to regulate prison phones and cap the rate of calls made from state and local prisons.
Private vendors pivoted to video visitation to maintain revenue. Today, the industry is defined by the widespread rollout of specialized, "detention-grade" tablets. Companies like Pay Tel provide these tablets to incarcerated individuals for "free" or for low monthly lease rates. While the hardware is cheap, the software ecosystem is highly monetized. Instead of just phone calls, modern tablet programs charge micro-fees for almost every action:
Pay Tel has transitioned into a multimedia and software-as-a-service (SaaS) provider. Their modern suites feature secure tablets equipped with messaging apps, educational portals, and entertainment hubs. While communication between inmates and the outside world could once be facilitated by a payphone, it is now routed through the internet and entails a digital supply chain including cloud storage.
Data AnalysisBucket DetailsStorage Provider: Microsoft Azure
Permissions: Publicly Readable
Total Size: 1.1TB
Total Number of Files: 3.4M
UpGuard Analysis Sample Size: 314GB, 500K files (~15%)
File dates: From 2018-May 2026 (Active and with files being added)
Just over a terabyte of exposed files resided on a Microsoft Azure cloud storage bucket configured to be publicly accessible, without any authentication or identification. The bucket name contained “cdn” (content delivery network) and was having more files uploaded to it in real time, suggesting an active production server.
Content TypesThe image files could be classified into four categories:
Researchers discovered unredacted images of identification cards, largely driver’s licenses, though passports, Social Security cards and other forms of identification were also present in smaller numbers. These IDs, as well as a profile picture, are required as part of Pay Tel’s process for those who wish to communicate with inmates in their contracted facilities. Thus while the use of the Pay Tel app is predicated on one of the parties being in jail, the drivers licenses most likely belonged to those who were not incarcerated.

Using local OCR on a sample of 500k documents, we found that just over 10% of all pictures were some form of identification card. Extrapolating that out to the full dataset, over 300,000 id cards for unique individuals are likely present. The geographic distribution of the licenses in the analysis sample reflects quite closely the layout of facilities using Pay Tel, as does what EXIF GPS data was present.
Legal and Financial FormsThousands of documents related to inmates’ legal situations were included in the data. Case dockets and records, court filings and motions, warrants and bonds, conviction records and even attorney communication were all found among the pictures. Many of these include details and strategies regarding ongoing cases and appeals.
Thousands of financial documents were also discovered, mostly inmate deposit receipts, money received from friends and family by an inmate and used for prison services. Itemised commissary orders were also present, as well as a small number of bank screenshots, money orders and P2P payments.

About 10% of the data set were personal communications, including text messages and chatting application screenshots, including prison messaging systems such as Pay Tel’s InteleMessage. A lesser number of email screenshots and even hand written personal letters were also detected. These range from children’s report cards and letters to incarcerated parents, to very intimate discussions between partners. Despite the surveilled nature of prison communications, there appeared to be a high expectation of privacy for the transmitted contents.

PhotographsThe remainder of the dataset consists of the photos of children, pets, friends and family that were transmitted to inmates using the Pay Tel system. These serve the crucial role of keeping incarcerated people connected to their outside world. Many studies have shown that connection to friends and family while incarcerated leads to improved outcomes.
RamificationsWhen a correctional facility awards an exclusive contract to a single telecom provider, any communication between inmates in that facility and the outside world must be done within their platform and according to their rules and prices. For nearly 40 years now, the friends and family of incarcerated people have battled the exorbitant fees and costs for inmate communication services. But in addition to the financial aspect, they have also battled the technology itself, with long delays and non functioning services having become expected, despite the premium price being paid for them.
This data exposure reveals yet another burden placed on those seeking contact with incarcerated loved ones: the risk of data exposure. However specialized Pay Tel’s operations are on the frontend in order to serve prisons, on the backend they use cloud storage and hosting like everyone else, in this case Microsoft Azure. By misconfiguring the Azure bucket to be publicly readable, hundreds of thousands of the IDs and selfies required by Pay Tel, and millions of privately communicated photos handled by them, were exposed.
This may not be the first time such information has been at risk. In 2025, the Dragonforce ransomware group claimed to have exfiltrated Pay Tel data, including tens of thousands of voice and video call recordings, scans of physical mail and other documents. Ironical
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Social Insecurity: Billions of Social Security Number and Passwords | UpGuard | 0 | 7.48 | 19-02-2026 |
| 2 | Read Receipts: How Mail Server Logs Put Corporate Clients at Risk | UpGuard | 0 | 8.21 | 30-04-2026 |
| 3 | "Яндекс.Практикум" проверяет утечку данных пользователей | 0 | 0 | 14-06-2022 |
| 4 | Shared Enemy: Inside a Chinese Dark Web Monitoring Database | UpGuard | 0 | 9.07 | 01-04-2026 |
| 5 | Open House: How an Unauthenticated MCP Server Exposed India's Largest Real Estate Platform | UpGuard | 0 | 5.85 | 21-07-2026 |
| 6 | Adult Supervision: How OnlyFans Takedowns Quietly Police Compromised Domains | UpGuard | 0 | 11.82 | 28-07-2026 |
| 7 | ICE shared Medicaid data it wasn't supposed to have with Palantir | 0 | 7.35 | 17-07-2026 |
| 8 | FISA Section 702 Isn’t the Only Way the Government Spies on Our Communications | 0 | 12.65 | 01-08-2026 |
| 9 | "Ъ": копии паспортов оказались в открытом доступе на компьютерах в московских МФЦ | 0 | 0 | 16-11-2018 |
| 10 | 3 accused of 'prison break-in' at Tennessee corrections facility | 0 | 5 | 27-06-2026 |