Skip to content

BridgePay ransomware payment-processing outage

Summary

BridgePay Network Solutions logo

A ransomware attack disrupted BridgePay payment services beginning Feb. 6, 2026, affecting merchants and municipal billing. BridgePay said gateway instances were restored by Feb. 28, though partner connections took longer; Lightspeed reported one connection still unavailable March 4 and restored March 10.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

Data impacts

  • Data encryption

    Data was rendered inaccessible through unauthorized encryption, including ransomware-related encryption.

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Complete service outage

    A primary service, system, platform, or operational capability became entirely unavailable.

  • Online portal unavailable

    A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.

  • Payment processing disruption

    The organization could not process, receive, issue, reconcile, or record payments normally.

  • Third-party service disruption

    The incident materially affected services delivered by or through a vendor, managed service provider, contractor, partner, or other third party.

Extortion indicators

  • Unknown extortion indicators

    The incident may involve extortion, but available evidence does not establish which extortion indicators were present.

Incident narrative

Analyst assessment

BridgePay’s incident updates confirm a ransomware attack that disrupted its payment gateway and transaction processing beginning Feb. 6, 2026. The company did not name an attacker. The available record establishes a ransomware-related service outage but does not identify specific encrypted systems.

Operational significance

The outage interrupted gateway APIs and payment portals used by merchants and public agencies. Palm Bay, Florida, reported that its online utility-billing portal could not accept payments Feb. 9; credit-card payments resumed Feb. 11, while phone payments remained unavailable. Frisco, Texas, reported disruption to its municipal billing portal. Coppell, Texas, reported card and online payment disruptions across several city service areas; Clackamas County Water Environment Services in Oregon reported unavailable online and automated phone/text utility payments; and Wilson, North Carolina, reported disrupted MyWilson payments and autopay before restoration Feb. 26. Grand Traverse County, Michigan, reported that in-person credit card payments for many county services were unavailable. Reporting on merchants also described cash-only workarounds; the public record does not establish a complete count of affected businesses or public agencies. BridgePay said all TPI, TGateway and BridgePay gateway instances were restored by Feb. 28, though some processing-partner approvals remained pending. Lightspeed’s status record shows its BridgePay connection to Elavon remained unavailable March 4 and all of its third-party processor connections were restored March 10. Gateway restoration therefore did not mean every partner connection had recovered.

BridgePay is based in Maitland, Florida. Palm Bay and Frisco are documented downstream municipal impacts; their location links do not imply an outage across each city. The other named jurisdictions refer to specific affected payment services, not outages of all local government operations.

Confidence and uncertainty

BridgePay’s own updates establish ransomware and the payment-processing outage with high confidence. The public record does not identify a ransomware group, confirm payment-card data exposure, or specify which systems were encrypted. The municipal and Lightspeed reports establish discrete downstream effects, not a complete count of affected customers.

Disclosure posture

BridgePay confirmed cyber involvement and service effects, supporting organization-confirmed cyber and disruption transparency.

Current status

Lightspeed marked all of its third-party processor connections restored March 10. BridgePay marked its incident resolved April 27. The latest dated evidence of an active downstream connection problem found in this review was March 4; a final restoration date for every BridgePay customer is not established.

Analytic gaps

The public record does not establish initial access, the attacker, a ransom demand or payment, full customer count, encrypted systems, or whether non-card data was accessed.

Organizations involved

Impacted locations

  • Maitland, Florida

    BridgePay's documented Maitland base is a physical organization anchor; no Maitland facility-specific outage is established.

  • Palm Bay, Florida

    Geographic service overlay for the documented BridgePay-dependent payment disruption; no jurisdiction-wide outage is asserted.

    Palm Bay's city utility-billing portal lost online payment capability as a downstream effect; this does not assert a citywide outage.

  • Marietta, Georgia

    Geographic service overlay for the documented BridgePay-dependent payment disruption; no jurisdiction-wide outage is asserted.

    Physical jurisdiction anchor for the affected organization's payment service; no facility-wide outage is asserted.

  • Bloomington, Illinois

    Geographic service overlay for the documented BridgePay-dependent payment disruption; no jurisdiction-wide outage is asserted.

    Physical jurisdiction anchor for the affected organization's payment service; no facility-wide outage is asserted.

  • Wichita, Kansas

    Physical jurisdiction anchor for the affected organization's payment service; no facility-wide outage is asserted.

    Geographic service overlay for the documented BridgePay-dependent payment disruption; no jurisdiction-wide outage is asserted.

  • Wilson, North Carolina

    Geographic service overlay for the documented BridgePay-dependent payment disruption; no jurisdiction-wide outage is asserted.

    Physical jurisdiction anchor for the affected organization's payment service; no facility-wide outage is asserted.

  • Clackamas County, Oregon

    Geographic service overlay for the documented BridgePay-dependent payment disruption; no jurisdiction-wide outage is asserted.

    Physical jurisdiction anchor for the affected organization's payment service; no facility-wide outage is asserted.

  • Bryan, Texas

    Geographic service overlay for the documented BridgePay-dependent payment disruption; no jurisdiction-wide outage is asserted.

    Physical jurisdiction anchor for the affected organization's payment service; no facility-wide outage is asserted.

  • Coppell, Texas

    Geographic service overlay for the documented BridgePay-dependent payment disruption; no jurisdiction-wide outage is asserted.

    Physical jurisdiction anchor for the affected organization's payment service; no facility-wide outage is asserted.

  • Denton, Texas

    Geographic service overlay for the documented BridgePay-dependent payment disruption; no jurisdiction-wide outage is asserted.

    Physical jurisdiction anchor for the affected organization's payment service; no facility-wide outage is asserted.

  • Frisco, Texas

    Frisco's utility payment portal was unavailable as a downstream effect; the city said online payments resumed March 5, 2026. This does not assert a citywide outage.

    Frisco's online utility billing portal was affected by the BridgePay outage. This area overlay does not assert that all city operations or residents were disrupted.

  • San Angelo, Texas

    Geographic service overlay for the documented BridgePay-dependent payment disruption; no jurisdiction-wide outage is asserted.

    Physical jurisdiction anchor for the affected organization's payment service; no facility-wide outage is asserted.

  • Kennewick, Washington

    Physical jurisdiction anchor for the affected organization's payment service; no facility-wide outage is asserted.

    Geographic service overlay for the documented BridgePay-dependent payment disruption; no jurisdiction-wide outage is asserted.

Sources

BridgePay ransomware outage disrupts payment processing

DysruptionHub reported BridgePay’s ransomware confirmation and broad payment gateway disruption, including municipal billing portals.

BridgePay payment gateway incident

BridgePay confirmed ransomware, reported gateway instances restored by Feb. 28 while processor approvals were pending, and marked the incident resolved April 27.

Temporary Service Disruption for Payments

WES said its online and automated phone/text utility payments were unavailable starting Feb. 6, 2026, because of the BridgePay cyber incident.

Temporary Service Disruption: Credit Card & Online Payments

Coppell said BridgePay’s disruption affected credit card and online payments for utility billing, the Public Works Annex, Police and Animal Services, and Rolling Oaks Memorial Cemetery.

Third Party Water Payment Vendor Experiencing Outage

Wichita said card payments through its water portal and water autopay were not processing because of BridgePay.

Update on online water service card payments

San Angelo said online water card payments were disrupted beginning Feb. 6 because of its third-party processor’s outage.

Utility payment options affected by payment processor outage

Palm Bay reported its online utility-billing payment portal unavailable Feb. 9 because of the BridgePay outage; credit-card payments resumed Feb. 11 while phone payments remained unavailable.

BridgePay confirms ransomware attack behind outage

BridgePay confirmed ransomware caused the nationwide payment processing outage.

BridgePay Service Interruption

The county said BridgePay’s outage made in-person credit card transactions for many county services unavailable beginning Feb. 10, 2026.

Online Utility Payment Issues Impacting Credit and Debit Cards

Denton said online utility card payments, including Pay As You Go, could not be processed after BridgePay’s cyber incident.

Card Payment Notice

BTU said its card payments were unavailable because of BridgePay’s ransomware incident and restored Feb. 12.

Notice of Temporary Online Business License Payment Disruption

Marietta said it could not process certain online business license card payments because of BridgePay’s ransomware outage.

MyWilson Payment Updates

Wilson said its BridgePay-dependent MyWilson portal could not process payments, autopay was delayed, and service was restored Feb. 26, 2026.

BridgePay processor connection status

Lightspeed said its BridgePay/Elavon connection remained unavailable March 4 and all third-party processor connections were restored March 10.

See something that needs correction?

Signed-in members can report an error, update, or missing source.