AZURE
Pay Tel Left Family IDs on a Public Azure Bucket
Pay Tel left family driver’s licenses on a public Azure container serving 387 jails, a vendor vault counties do not control and still keep filling.
Pay Tel Communications left over 300,000 family driver’s licenses on a public Microsoft Azure storage container that anyone could open. UpGuard researchers found the bucket on May 4, 2026, tied it to the jail-tablet vendor, and watched new files land while they worked.
The IDs were not a side pile of inmate mugshots. They belonged to people outside the walls who had to upload a license and a profile photo before they could talk to someone in jail.
What Pay Tel Stored on the Open Azure Container
Greg Pollock’s UpGuard team described 3.4 million images and 1.1TB of files on a Microsoft Azure container that needed no password. The bucket name contained “cdn,” the usual label for a content delivery network, and it was still taking uploads, which is how a production store behaves rather than an old archive.
Researchers copied a 314GB slice of 500,000 files, about 15 percent of the set, and ran local OCR. Just over 10 percent of the pictures were identification cards, mostly driver’s licenses, with passports and Social Security cards in smaller numbers. Extrapolated across the full dump, that pointed to over 300,000 unique ID cards. File timestamps ran from 2018 through May 2026.
WHAT THE OPEN BUCKET HELD
| Category | What UpGuard measured | Who it identified |
|---|---|---|
| Driver’s licenses and other IDs | Just over 10% of images; over 300,000 unique cards | Non-inmate users of the calling platform |
| Personal communications | About 10% of the set | Inmates and the people they messaged |
| Legal and financial forms | Thousands of dockets, warrants, bonds, deposit receipts | Inmates, and in some files their lawyers |
| Personal photographs | The remainder of the dataset | Children, pets, friends, and family |
The same container held screenshots from Pay Tel’s InteleMessage app, handwritten letters, children’s report cards, commissary orders, and a smaller run of bank screenshots and money orders. Many photos still carried EXIF GPS tags. Some pins were tight enough to mark a home address.
The Licenses Belonged to Families, Not Inmates
UpGuard’s affected-individuals line is easy to miss if you only read “inmate data leak.” The firm estimated over 300,000 unique, non-inmate users, clustered in the American Southeast, notably Georgia and North Carolina. Pay Tel requires those people to hand over an ID card and a profile picture before they can use the service. The licenses in the bucket followed that rule, not a booking desk inside the jail.
The remainder of the dataset consists of the photos of children, pets, friends and family that were transmitted to inmates using the Pay Tel system.
Greg Pollock, UpGuard research report
About 10 percent of the files were personal communications, including text-message screenshots and letters. Pollock wrote that the messages ran from kids’ report cards sent to an incarcerated parent to intimate talks between partners, and that the people sending them still seemed to expect privacy even on a monitored jail platform.
Those families did not pick Pay Tel in any market sense. When a county signs an exclusive tablet contract, every call, e-message, and scanned letter goes through that vendor. Switching would mean not talking. That is why an open Azure store of licenses is not the same event as a retailer leaking customer scans. The people in this dump had already been told the upload was the price of contact.
Azure Public Access Takes Two Deliberate Switches
Microsoft does not ship Blob Storage as a public website. For Azure Resource Manager accounts, anonymous reads are prohibited unless someone turns them on at the account and then again on the container. A CDN-named bucket that served 1.1TB of ID scans without a login means both of those switches were open.
THE TWO SWITCHES THAT OPEN A BLOB
- Account flag: AllowBlobPublicAccess must be enabled before any container in that account can serve anonymous reads.
- Container flag: The container itself must be set to Blob or Container public access; the default is Private, which still demands an authorized request.
- Account override: Setting AllowBlobPublicAccess to False blocks anonymous reads even if a container was left public, which is the control Microsoft tells operators to use.
Microsoft’s own remediation guide says anonymous access “presents a potential security risk,” and it tells operators to disallow anonymous access for the storage account unless a workload truly needs public reads. Static website images might. Driver’s licenses, commissary receipts, and kids’ photos do not.
The fix is not exotic. In the Azure portal it lives under Configuration as “Allow Blob anonymous access.” A built-in Azure Policy can deny new accounts that leave public access on. Shared Access Signatures and Microsoft Entra ID exist for the cases that need time-boxed reads. None of that requires Microsoft to change the product. It requires the account owner to leave the defaults in place on a store that holds government IDs.
County Jails Do Not Control the Storage Account
UpGuard listed Pay Tel Communications, Pay Tel’s clients with 387 unique jails referenced, and inmates as the affected entities. The Azure account was the vendor’s. Sheriffs who bought tablets and call routing did not get a portal into that CDN bucket, and they could not flip AllowBlobPublicAccess from a county admin screen.
Pay Tel Communications, which shifted its focus to inmate telephone services in 1989 after starting as a southeastern payphone firm in 1986, now sells InteleTABLET devices, the Centurion ITS call platform, inteleVISIT video, and InteleSCAN mail scanning. President and founder Vincent Townsend still runs the company. UpGuard emailed privacy@paytel.com on May 7, got no reply, and on the morning of May 11 wrote support addresses plus the president and the vice president of business development. The bucket was locked around 1 p.m. Pacific that day, seven days after discovery and four days after the first notice.
Pay Tel has issued no public statement about the incident. There is no posted notice on its site for the people who uploaded licenses, and no visible letter to attorneys general. State breach laws generally treat driver’s license images as personal information that triggers notice. Whether those statutes get used depends on the company filing, or on a regulator opening a file without one.
Site-commission contracts help explain why counties stay in that position. UpGuard’s background on the industry describes vendors promising to return sometimes 60 to 80 percent of phone revenue to a facility or a county general fund, while collect calls once ran above $1.00 a minute with $3.00 to $5.00 connection fees. After the Martha Wright-Reed Just and Reasonable Communications Act let the FCC cap voice rates, vendors moved fees into tablets, video, and e-message “stamps” that UpGuard put at $0.25 to $0.50 each. The county still gets a vendor. The family still pays. The ID scans still sit in the vendor’s cloud.
DragonForce Already Listed Pay Tel in June
The open Azure container was not Pay Tel’s first public data event. A DragonForce leak-site record logged on June 26, 2025, with an estimated attack date of June 25, 2025, already treated the company as a victim and described call recordings and scanned mail from county jails, many of them in North Carolina and Georgia, the same belt UpGuard later mapped from EXIF and license geography.
PAY TEL’S TWO PUBLIC DATA EVENTS
- June 25, 2025: Estimated date of the DragonForce attack on Pay Tel Communications, per the leak-site record.
- June 26, 2025: DragonForce listing appears, describing 10,000-plus video call recordings, 10,000-plus audio recordings, 20,000-plus scans of physical mail, and 70,000-plus work documents, plus a long roster of county jails.
- May 4, 2026: UpGuard finds the unsecured Azure bucket, still receiving files, with timestamps back to 2018.
- May 7, 2026: First notice goes to privacy@paytel.com.
- May 11, 2026: Follow-up emails go to executives; the bucket is confirmed secured around 1 p.m. Pacific.
- May 28, 2026: UpGuard publishes the research report. Pay Tel still has no public notice up for families.
The 2025 listing named county jails and a juvenile center. The 2026 Azure dump then put family licenses, kids’ photos, and GPS-tagged snapshots on the open internet. Different paths, same pile of people: relatives who needed the vendor to reach someone inside, and county shops that could not audit the store.
Public posts about the May leak never turned into a real argument. That quiet matches the market. There is no rival app to install, and the surnames on those North Carolina and Georgia licenses are not a consumer brand with a reply guy. The dump was large. The noise was not.
New Jersey Now Wants the Same ID Uploads
On September 3, 2026, New Jersey prisons began requiring a driver’s license or passport upload from anyone who wanted to send an electronic message to someone inside. Chris Greeder, a Department of Corrections spokesman, called the rule “an important public safety measure designed to protect victims, the public, and incarcerated individuals from fraud, extortion, harassment, and criminal coordination.” He said phone calls from incarcerated people can still land without a photo ID, and that “NJDOC works with its vendors to ensure personal data collected for verification is handled securely.”
The vendor in that rollout is ViaPath, which replaced JPay. ViaPath is the current name of Global Tel*Link, a firm the Federal Trade Commission already said failed to secure cloud-stored user data and failed to tell every affected person, then ordered into tighter retention and notice rules in 2024. Wanda Bertram of the Prison Policy Initiative said identification checks of this kind are spreading, and that “families are now effectively paying for their own monitoring.” Federal and state figures cited in that debate show more than half of Americans have no passport and about 30 percent of New Jersey adults have no driver’s license.
WHAT WE KNOW
- Bucket status: UpGuard confirmed the Azure container was secured around 1 p.m. Pacific on May 11, 2026.
- Who was in it: Over 300,000 unique non-inmate users, plus inmate legal files, messages, and family photos, across 387 jails.
- Prior incident: DragonForce listed Pay Tel in June 2025 with call recordings and scanned mail.
WHAT IS UNCONFIRMED
- Other downloads: UpGuard has not said whether anyone else copied the bucket before May 11.
- Family notice: Pay Tel has not said whether it will notify the people on those licenses or state attorneys general.
- How long it was public: Files dated to 2018, but the public window before May 4, 2026 is unknown.
Pay Tel’s May bucket is a finished event with published counts. The ID-upload rule that filled it is not finished. New Jersey is now collecting the same class of document through a different vendor, and Greeder’s security sentence is the same promise families already heard when they scanned a license for a jail tablet.
Frequently Asked Questions
How did researchers tie the open Azure bucket to Pay Tel?
UpGuard found a second Azure bucket with a similar name that held assets carrying Pay Tel branding, then matched EXIF GPS clusters to the company’s southeastern jail map, read device metadata that fit Pay Tel’s detention-grade tablets, and saw ID-card collection plus inmate receipts that followed Pay Tel’s signup process. That mix, not a company press release, is what sent the first email to privacy@paytel.com.
Is Azure Blob Storage public by default?
No. On Azure Resource Manager accounts, anonymous reads are prohibited until an admin allows them at the account and then sets a container to Blob or Container public access. Microsoft also documents that remediating the account flag needs Azure Storage resource provider version 2019-04-01 or later, after which a False value for AllowBlobPublicAccess overrides every container in that account.
What products does Pay Tel sell to jails besides phone calls?
The company’s public product list includes InteleTABLET multi-function tablets, the Centurion ITS call-control platform, inteleVISIT on-site and remote video, InteleSCAN off-site mail scanning, and Pathway to Achieve, a tablet education app Pay Tel says detainees can use to earn entertainment time. InteleMessage is the messaging channel named in the leaked screenshots.
What did the 2025 DragonForce listing say about Pay Tel’s jails?
Besides the call recordings and mail scans, the listing named county jails across North Carolina, Georgia, South Carolina, Florida, and Virginia, and also listed sites in Utah, New Mexico, Tennessee, Ohio, Washington, California, Kansas, and Missouri, including Guilford County Juvenile Center in North Carolina. That roster is a leak-site claim, not a court finding.
Why do prison vendors collect driver’s licenses from families?
Pay Tel treats an ID image and a profile photo as the signup gate for its calling and messaging apps. New Jersey’s Chris Greeder later described a similar upload rule as a public-safety check against fraud and gang coordination on electronic messages. After federal rate caps hit voice minutes, vendors moved more traffic onto tablets and stamped e-messages, which is how a family license ended up in object storage next to a kid’s photograph.
UpGuard published the report on May 28, 2026. Pay Tel’s public site still does not mention the bucket, the licenses, or the 387 jails that had been sending families through that signup gate.
-
NEWS4 months agoWarzone Leaves Xbox One and PS4 After Season 06
-
NEWS4 months agoMicrosoft AI Was Set Free to Build Its Own Frontier
-
MICROSOFT 3654 months agoMicrosoft IQ Turns Workplace Data Into a Metered Agent Brain
-
NEWS4 months agoXbox Games Showcase 2026 Split the Catalog in Two
-
MICROSOFT 3654 months agoNadella Banned Addiction Talk While Scout Kept Heartbeat
-
NEWS4 months agoModern Warfare 4 Splits Its Audience Before the October Launch
-
NEWS4 months agoInfinity Ward Bets Modern Warfare 4 on a Paid DMZ
-
NEWS4 months agoDragonwilds Hits Xbox, but Steam Saves Stay Put
