Zellis
| Primary URL | Location | Industry | www[.]zellis[.]com |
Country
United Kingdom
|
Financial Services
|
|---|
Profile
Zellis is a United Kingdom‑based organisation that specialises in providing payroll processing and related workforce management services to large employers. Its core offering includes the calculation of salaries, deduction of taxes and statutory contributions, generation of payslips and submission of regulatory filings on behalf of clients. The platform is designed to handle complex payroll requirements for organisations that employ thousands of staff across multiple pay frequencies and jurisdictions. Zellis serves a diverse range of sectors, as evidenced by its client list that includes major names in media, aviation, retail and air transport, indicating a broad market footprint within the UK. The company positions itself as a specialist provider focused exclusively on payroll, distinguishing itself from broader human‑resources outsourcing firms by concentrating on compliance, accuracy and scalability in salary administration. Its services are typically integrated with clients’ existing HR and finance systems to automate the end‑to‑end payroll cycle and reduce manual intervention. By maintaining a dedicated payroll expertise, Zellis aims to deliver reliable, timely and regulation‑compliant compensation processing for its corporate customers.
In May 2023 Zellis suffered a cyber security incident that exploited a zero‑day vulnerability in the MOVEit file transfer tool used by the organisation for exchanging data with clients and partners. The breach resulted in the unauthorized access to personal data belonging to employees of several high‑profile UK organisations, including the British Broadcasting Corporation, British Airways, Boots and Aer Lingus. The exposed information comprised names, residential addresses, national insurance numbers and, for a subset of individuals, bank account details. Investigations attributed the attack to the Clop ransomware gang, although the group publicly asserted that it did not retain the data stolen from Zellis’s clients. The incident underscored the supply‑chain risk associated with third‑party service providers, demonstrating how a vulnerability in a vendor’s file‑transfer infrastructure can propagate to the personal data of numerous downstream organisations. Media coverage of the event highlighted the breach’s scale and the sensitivity of the data involved, prompting discussions about organisational resilience and vendor management practices. No explicit details regarding Zellis’s ownership, parent company or subsidiary structure are available in the supplied sources, so those aspects remain unspecified in this profile.
