A major ransomware has hit BridgePay Network Solutions, a leading provider of payment gateways and transaction processing solutions in the United States, causing widespread service disruptions nationwide. The incident, which began on Friday, has quickly become a crisis for merchants, organizations and public entities that rely on the platform for card payments.

The outage was not limited to individual operations, but affected core BridgePay systems , leading to the inability to process transactions and a temporary transition of many businesses to cash-only payments
See also: How Samsung Knox firewall helps prevent network breaches
Confirmation of the incident and the involvement of the authorities
BridgePay confirmed late Friday that the cause of the disruption was a ransomware. According to an update published on February 6, the company has already been in contact with federal law enforcement agencies, including the FBI and the U.S. Secret Service. It is also working with external digital forensics teams and data recovery.
The company said initial findings indicate no payment card data was compromised. The files that may have been compromised were encrypted, and so far there is no indication of any exploitable information being leaked.
It remains unknown which ransomware group is behind the attack.
Businesses in a state of emergency: "Cash only"
On the same day that the incident became known, many merchants and organizations in the US informed their customers that they could only accept cash, due to the inability to process card payments
See also: Flickr: Possible data breach via third-party provider
A typical example was a restaurant that announced that its credit card processing company had suffered a cybersecurity breach, resulting in card payments being unavailable nationwide.

Similarly, the city of Palm Bay in Florida issued an official statement, informing that the online bill payment portal is temporarily down, with no estimated time of restoration. Citizens were asked to pay utility bills with cash or check.
Which services were most affected?
BridgePay's status page recorded severe outages in critical production infrastructure. Among the systems affected were:
- BridgeRay Gateway API (BridgeComm)
- PayGuardian Cloud API
- MyBridgeRay virtual terminal and reporting
- Hosted payment pages
- PathwayLink gateway and boarding portals
The first signs appeared at approximately 3:29 a.m., when degraded performance was detected across multiple services. The situation escalated from intermittent glitches to a complete outage within a few hours.
See also: La Sapienza University suffered a cyberattack

The Bigger Picture: Ransomware and Payment Infrastructure in the Crosshairs
The BridgePay incident joins a growing wave of ransomware attacks targeting critical financial infrastructure. Unlike other industries, attacks on payment systems have a direct impact on real commerce: when transaction pipelines are frozen, markets, services and daily economic activity come to a halt.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
BridgePay warned that restoration will take time, as recovery is being done in a "safe and responsible manner" and the investigation is ongoing.
The event highlights once again how critical cybersecurity is in the digital payments sector, as a single attack can cause ripple effects on businesses, public organizations and consumers across the country.
Source: www.bleepingcomputer.com
