Correctional technology vendors maintain vast repositories of sensitive records, yet their defensive measures historically trail commercial standards. While CorrLinks has managed to avoid a confirmed monolithic database exfiltration, the broader ecosystem of prison technology vendors has faced severe security failures over the past decade.
| Vendor & System | Year Range | Scope of Compromise | Underlying Cause |
|---|---|---|---|
| Securus Technologies | 2015, 2018 | Over 70 million call records and attorney-client recordings leaked | Server misconfiguration and an anonymous insider leak provided to The Intercept |
| Telmate (GettingOut) | 2020, 2021 | Millions of personal logs, inmate locations, and family chat logs exposed | Unprotected database left accessible on the public internet without password protection |
| CorrLinks / ATG (Public Rumor) | 2024, 2026 | Localized message disclosures; high-profile detainee emails published online | Credential stuffing against outside accounts combined with court records and FOIA releases |
The distinction between an infrastructure hack and an account-level compromise matters. When Securus left millions of attorney-client calls open to download, it represented a catastrophic infrastructural failure. The recent CorrLinks incidents, by contrast, expose how weak user-side authentication and public record requests intersect to lay private communications bare.