ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

RansomHouse claims major ransomware attack on US payments giant AvidXchange

AvidXchange, one of the largest payment software providers in the US, suffered a significant cyber attack that affected some of its systems and clients’ data.AvidXchange is one of the leading providers of accounts payable automation software and payment solutions for middle-market businesses and their suppliers. The company says it processed over 70 million transactions worth $215 billion in 2022 and its AvidPay Network was used by over 965,000 suppliers in the past five years.In a recent incident notification posted on its website, AvidXchange said that it recently detected suspicious activity in its internal systems, following which it launched an investigation with assistance from third-party cyber security experts to understand the nature and scope of the intrusion.“Our investigation, which is ongoing, has revealed that the incident affected some of our systems and data. We are aware that a threat actor has published files they claim to have taken from our systems. We are reviewing these files to validate and understand the nature of this data,” it said.The infamous RansomHouse ransomware gang has claimed responsibility for the cyber attack on AvidXchange and listed the company on its data leak site. “Dear AvidXchange, we strongly recommend you to contact us to prevent your confidential data, and documents from being leaked,” reads a message on RansomHouse’s leak site.The group is believed to have leaked a trove of data stolen from the company. According to TechCrunch, the leaked data includes non-disclosure agreements, employee payroll information, corporate bank account numbers, usernames, passwords, and, in some cases, answers to security questions for a variety of the company’s systems, including cloud accounts and security software, through to smart door locks and surveillance cameras.Acknowledging the data leak, AvidXchange said that once the investigation concludes and the company identifies whose data has been compromised, it will contact all affected individuals and provide measures to safeguard themselves.“We continue to take actions to implement additional safeguards. Our solutions are operational and we are processing customer invoices and payments. However, our efforts to respond to the incident and enhance our security may result in temporary disruptions to certain features or products,” AvidXchange added.This is the second cyber attack the company has suffered in 2023. A month ago, AvidXchange confirmed that it was among the 130 organisations that were affected by the exploitation of the zero-day vulnerability in Fortra’s GoAnywhere MFT file transfer application.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543