惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
小众软件
小众软件
MongoDB | Blog
MongoDB | Blog
Hugging Face - Blog
Hugging Face - Blog
Jina AI
Jina AI
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Stack Overflow Blog
Stack Overflow Blog
L
LangChain Blog
大猫的无限游戏
大猫的无限游戏
量子位
A
About on SuperTechFans
G
Google Developers Blog
雷峰网
雷峰网
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
IT之家
IT之家
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园_首页
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Vercel News
Vercel News
V
Visual Studio Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 聂微东
U
Unit 42
Apple Machine Learning Research
Apple Machine Learning Research

TechCrunch

Robots beat human records at Beijing half-marathon Palantir posts mini-manifesto denouncing inclusivity and ‘regressive’ cultures TechCrunch Mobility: Uber enters its assetmaxxing era Cracks are starting to form on fusion energy’s funding boom Blue Origin successfully re-uses a New Glenn rocket for the first time ever Tesla brings its robotaxi service to Dallas and Houston VC Ron Conway says he has a ‘rare form of cancer’ AI chip startup Cerebras files for IPO Anthropic’s relationship with the Trump administration seems to be thawing The App Store is booming again, and AI may be why “Tokenmaxxing” is making developers less productive than they think Hackers are abusing unpatched Windows security flaws to hack into organizations Zoom teams up with World to verify humans in meetings Gigs turns your concert history into a personal live music archive Chef Robotics escaped the robot cooking graveyard and says it’s thriving — here’s why Uber will now pick up your returns from your doorstep Anthropic launches Claude Design, a new product for creating quick visuals Google’s AI Mode can now help you find products in stock nearby Bluesky confirms DDoS attack is cause of continued app outages Bluesky confirms DDoS attack is cause of continued app outages Netflix plans to add a vertical video feed, use AI for recommendations SaySo is a new short-form video app that aims to restore users’ trust in news Loop raises $95M to build supply chain AI that predicts disruptions Are we tokenmaxxing our way to nowhere? New leaders, new fund: Sequoia has raised $7B to expand its AI bets Netflix co-founder and chair Reed Hastings to leave board Upscale AI in talks to raise at $2B valuation, says report Physical Intelligence, a hot robotics startup, says its new robot brain can figure out tasks it was never taught From the Startup Battlefield stage to the International Space Station: geCKo Materials built a sticky product Slash, a Ramp competitor founded by teenagers, raises $100M at $1.4B valuation
A security lapse at prison pay phone service Pay Tel publ...
Zack Whittaker · 2026-05-29 · via TechCrunch
Image Credits:Bryce Durbin / TechCrunch

Prison calling service Pay Tel has secured a publicly exposed cloud server storing hundreds of thousands of driver’s licenses and other sensitive information about people who used its services, according to a cybersecurity firm that alerted the company to the security lapse. 

Security researchers with UpGuard said in a blog post that they identified a Microsoft Azure-hosted storage server storing at least 300,000 driver’s license scans and other government-issued identity documents belonging to Pay Tel. 

The server was unprotected without a password, allowing the data inside to be accessible from the web.

Pay Tel provides tablets and other communication devices to prisons across much of the United States for inmates to receive calls. Customers signing up to Pay Tel have to provide a copy of their identification documents and a profile photo before they can use the service, which UpGuard said were exposed. The security researchers said inmate communications, including text messages, handwritten notes, and financial records, were also exposed as a result of the security lapse.

UpGuard said it alerted Pay Tel on May 7 after determining that the company managed the server and followed up days later before it was secured. Pay Tel has not yet acknowledged the security incident.

The data exposure at Pay Tel is the latest example in recent months of tech companies leaving people’s highly sensitive documents on the open web for anyone to find. TechCrunch has reported on this recurring problem of companies often misconfiguring their systems or falling below cybersecurity best practices, and as a result, allowing anyone on the internet to view their customers’ personal information.

UpGuard said many of the user-uploaded photos also contained the precise real-world location of where the images were taken; in some cases, granular enough to identify someone’s home address.

This is Pay Tel’s second known security lapse in as many years, following a ransomware attack in June 2025.

Pay Tel president Vincent Townsend did not respond to an email from TechCrunch with questions about the security lapse. It’s unclear if the company plans to notify the individuals whose data was exposed or if the company will alert attorneys general under U.S. state data breach notification laws.

TechCrunch could not ascertain who, if anyone, is responsible for cybersecurity at Pay Tel.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security.

He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com.

View Bio