Nayax said it detected unusual activity in a cloud account tied to one of its subsidiaries, blocked and contained the activity, and launched an investigation with external experts and law enforcement in Israel and the United States. In a Form 6-K filing, the payments firm said its production environment, core systems, and business operations were not affected and that it does not currently believe material information was exposed.
The disclosure followed claims by threat actor TheSyndicate, which alleged a far broader compromise lasting nearly a year and involving more than 100 TB of stolen data, including over 1 billion payment-card records, KYC data, transaction histories, API keys, credentials, source code, and internal infrastructure details. Those claims remain unverified, no proof or sample data had been released at the time of reporting, and Nayax had not confirmed the actor’s assertions about the scale or sensitivity of any data allegedly taken.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
TheSyndicate said the allegedly stolen Nayax data would be released through a portal on July 21, 2026, with card-data query capability and raw file downloads, and promised a Telegram update beforehand. This was presented as part of the actor's unverified extortion or leak threat.
Nayax disclosed in a Form 6-K filing that it detected unusual activity involving one of its subsidiaries in one of the company's cloud accounts and said the activity was immediately blocked and contained. The company said it was investigating with external experts and law enforcement in Israel and the United States, while stating its production environment and core systems were not affected.
A threat actor using the alias TheSyndicate claimed to have fully compromised Nayax, remained in its systems for nearly a year, and exfiltrated more than 100 TB of data including over 1 billion card-data records. At the time of reporting, the claim was unverified and no proof or sample data had been released.
A threat actor using the alias derm0nix allegedly breached the Portal de Salud de Culiacán and claimed to have leaked 4,045 patient records from 2018 to 2026, including minors' and patients' sensitive medical data. The report stated the claim was unverified and that local authorities had not publicly addressed it.
A threat actor using the alias Saturne advertised an alleged sale of data from Follow.fr, claiming a dataset of 2,052,123 patient records in CSV format dated July 2026. The claim was reported as unverified, with samples and negotiable pricing allegedly offered to serious buyers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
databreaches.net
Open sourcedarkwebinformer.com
Open sourcedarkwebinformer.com
Open sourcedarkwebinformer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.