PRISON PAY PHONE SERVICE EXPOSED 300K DRIVER'S LICENSES
SECURITY DESK■ 1 MIN READ
FRI, MAY 29, 2026■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE
Security researchers discovered a public data leak at Pay Tel, a prison telephone service provider, exposing over 300,000 callers' driver's licenses and inmate communications. The company secured the data after the vulnerability was identified.
Pay Tel, which operates pay phone systems in correctional facilities, left sensitive caller information accessible online without proper security protections. The exposed dataset included driver's license numbers and images, along with records of calls between inmates and their contacts.
Security researchers notified Pay Tel of the vulnerability, prompting the company to secure the exposed information. The incident highlights persistent security gaps in services handling personal identification data.
The breach affected hundreds of thousands of individuals who used prison pay phones to communicate with inmates. Details regarding the duration of the exposure and whether the data was accessed by unauthorized parties remain unclear. Pay Tel has not released a formal statement addressing the scope of the incident or remediation steps beyond securing the database.
The exposure underscores broader concerns about data protection practices across third-party services managing sensitive personal information in institutional settings.
■ SOURCES
► TechCrunch■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE
■ MORE FROM THE SECURITY DESK
Cybercriminals have transformed DDoS attacks into a polished, commercialized service complete with pricing tiers, customer support, and reseller programs. The DDoS-as-a-Service market has evolved from basic tools into sophisticated attack platforms.
9H AGO— Industry Desk
Microsoft faced backlash after threatening a security researcher with criminal investigation, reigniting debate over software vulnerability disclosure practices and corporate responsibility.
9H AGO— Security Desk
Google is deploying Device Bound Session Credentials (DBSC) to all Chrome users, a security feature designed to prevent account takeovers by protecting session cookies from theft.
9H AGO— Industry Desk
Dutch authorities have dismantled a major botnet comprising 17 million infected devices and seized over 200 servers hosting the operation at a local provider.
9H AGO— Security Desk