BridgePay Network Solutions, a U.S. payment gateway and solutions provider, confirmed a ransomware attack forced it to take key systems offline, triggering a nationwide outage that disrupted card processing and related services for merchants and public-sector customers. The incident began on a Friday with degraded performance that escalated into a broad platform disruption, with monitoring first flagging issues around Gateway.Itstgate.com before cascading into a full outage.
BridgePay reported it engaged federal law enforcement, including the FBI and U.S. Secret Service, alongside external forensic and recovery teams. The company stated that initial forensic findings found no compromise of payment card data, and that any accessed files were encrypted, with “no evidence of usable data exposure,” while it continued restoration efforts across impacted services including BridgePay Gateway API (BridgeComm), PayGuardian Cloud API, MyBridgePay virtual terminal/reporting, hosted payment pages, and PathwayLink gateway/boarding portals; the responsible ransomware group was not publicly named in the reporting.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
As of Monday, BridgePay said it was still securely restoring operations while the forensic investigation continued, and it had not provided an estimated time for full recovery. No ransomware group had publicly claimed responsibility at that time.
By the weekend and as of Monday reporting, outages tied to BridgePay had taken offline online payment portals for customers including the City of Palm Bay, Florida and the City of Frisco, Texas, while some merchants were forced to accept cash only.
In its initial forensic assessment, BridgePay said it found no evidence that payment card data was stolen or exposed, adding that any accessed files were encrypted and that integrators were not believed to face an active threat or vulnerability.
Late Friday, BridgePay confirmed that ransomware caused the outage and said it had engaged the FBI, the U.S. Secret Service, and external forensic and recovery teams to investigate and restore systems.
The incident developed into a widespread outage that disrupted card processing and related services for merchants and public-sector customers across the United States. Impacted services included BridgePay Gateway API, PayGuardian Cloud API, MyBridgePay, hosted payment pages, and PathwayLink portals.
On Friday, BridgePay began seeing degraded performance around 3:29 a.m. and took key systems offline as the disruption escalated into a broader outage affecting its payment platform.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourceteiss.co.uk
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.