BridgePay Payment Gateway Hit by Ransomware, Causing Nationwide Outages - CyberSecurityNews
CyberSecurityNewsArchived Mar 19, 2026✓ Full text saved
BridgePay Payment Gateway Hit by Ransomware, Causing Nationwide Outages CyberSecurityNews
Full text archived locally
✦ AI Summary· Claude Sonnet
Home Cyber Attack News BridgePay Payment Gateway Hit by Ransomware, Causing Nationwide Outages
BridgePay Ransomware Attack
BridgePay Network Solutions, a major U.S. payment gateway provider, confirmed a ransomware attack caused a widespread outage, disrupting card processing for merchants nationwide.
The outage began early on February 6, 2026, around 3:29 a.m. EST with degraded performance in systems like the Gateway.Itstgate.com virtual terminal, reporting, and API. By 5:48 a.m. EST, BridgePay posted its first status update, noting systems were down with an unknown resolution time.
An hour later, at 6:34 a.m., the company identified a cybersecurity incident and began investigating with internal teams, external specialists, and the FBI, without an estimated restoration timeframe.
At noon EST, BridgePay reported that systems remained unavailable, emphasizing collaboration with the U.S. Secret Service forensic team and cybersecurity professionals to conduct assessments and clearances.
By 7:08 p.m. EST, about 12 hours ago, as of February 7, the firm confirmed ransomware as the cause. Initial forensics showed no payment card data was compromised, with the accessed files encrypted and no evidence of any usable data exposure.
The attack crippled core services, including the BridgePay Gateway API (BridgeComm), PayGuardian Cloud API, MyBridgePay virtual terminal and reporting, hosted payment pages, and PathwayLink gateway and boarding portals.
Merchants quickly resorted to cash-only operations; one restaurant cited a nationwide cybersecurity breach in its card processor. Florida’s City of Palm Bay announced its online billing portal was down due to BridgePay, urging in-person cash, card, or check payments.
Other impacts hit Lightspeed Commerce, ThriftTrac, and the City of Frisco, Texas. BridgePay stated no immediate threat to integrators but prioritized secure restoration.
BridgePay engaged federal authorities like the FBI and Secret Service, plus forensic, recovery, and leading cybersecurity teams. The firm acknowledged a potentially lengthy recovery, focusing on customer protection without naming the ransomware group.
As of the latest update, operations restoration proceeds urgently but responsibly, with more details promised.
This incident underscores the rising threat of ransomware to payment infrastructure, where disruptions can halt real-world commerce. Unlike some attacks with data exfiltration, BridgePay reports encryption-only access so far. No full recovery ETA exists, heightening uncertainty for reliant businesses.
Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.
RELATED ARTICLESMORE FROM AUTHOR
Cyber Security
Cisco Firewall 0-day Vulnerability Exploited in the Wild to Deploy Interlock Ransomware
Cyber Attack News
New iOS Exploit With Advanced iPhone Hacking Tools Attacking Users to Steal Personal Data
ANY.RUN
The High Cost of Slow Triage: How to Make Tier 1 the Fastest Layer in Your SOC
Top 10
Essential E-Signature Solutions for Cybersecurity in 2026
January 31, 2026
Top 10 Best Data Removal Services In 2026
January 29, 2026
Best VPN Services of 2026: Fast, Secure & Affordable
January 26, 2026
Top 10 Best Data Security Companies in 2026
January 23, 2026
Top 15 Best Ethical Hacking Tools – 2026
January 15, 2026