← TSYS|Total System Services

2020 TSYS — Conti ransomware hitting legacy Cayan merchant back office; stolen data marketed online (Dec)

2020 Unknown records affected Share on X

Data compromised

Corporate and likely HR/onboarding style files per actor dumps and later notifications—categories vary by population

Technical writeup

TSYS (later part of Global Payments M&A structure) disclosed a December 2020 Conti ransomware incident confined largely to corporate back-office systems supporting the legacy Cayan merchant-acquiring business it had bought in 2018. Krebs on Security, PYMNTS, Digital Transactions, and regional employee-notification coverage described roughly 10 GB of stolen material briefly posted to extortion infrastructure; TSYS maintained card-present / processing networks stayed up and that payment card data were not impacted while acknowledging administrative/HR-class exposure risk for subsets of records. Victimology split across employee vs merchant meta-data in press; no single authoritative person tally.

Root cause

Conti human-operated ransomware with data exfiltration against TSYS/Cayan back-office segment

References