Nayax Allegedly Breached With Payment Card and Customer Data Claimed Stolen

A threat actor claims to have compromised Nayax and stolen more than 100TB of payment card data, customer records, source code, and internal company information, though the claims remain unverified.
Screenshot of a cybercrime forum post alleging a breach of Nayax and claiming the theft of payment card data, customer records, source code, and other internal information.
A forum post alleges that Nayax was compromised and claims more than 100TB of payment card data, customer information, source code, and internal documents were stolen. The claims have not been independently verified by BreachNews.

A threat actor has claimed responsibility for an alleged breach of payment technology provider Nayax, asserting that it exfiltrated more than 100TB of internal company data, including payment card information, customer records, source code, financial documents, and internal credentials.

The claims were published on a cybercrime forum alongside a dedicated leak site threatening to release the purportedly stolen data on July 21. At the time of publication, the claims had not been independently verified, and Nayax had not issued any public statement.

Nayax confirms cloud security incident

Update (July 8, 2026): Nayax has since confirmed a cybersecurity incident in a filing with the U.S. Securities and Exchange Commission (SEC), stating that it detected anomalous activity within a cloud account belonging to one of its subsidiaries.

According to the filing, the affected cloud account was immediately blocked after the activity was discovered. Nayax said its production environment, core systems, payment processing infrastructure, and business operations were not affected by the incident.

The company said it is continuing to investigate the scope of the incident with the assistance of external cybersecurity experts and law enforcement authorities in both Israel and the United States. Nayax added that it is still assessing what data, if any, may have been accessed and stated that it does not currently believe material information has been exposed.

Threat actor claims long-term access

According to the forum post, the threat actor allegedly maintained access to Nayax’s environment for nearly a year before exfiltrating data. However, no evidence has been presented that independently verifies the duration of the alleged compromise or the scale of the claimed data theft.

The actor claims the stolen information includes payment card data, Know Your Customer (KYC) records, transaction histories, customer identities, internal API keys, infrastructure documentation, database exports, source code repositories, financial records, email communications, and ERP platform data. Similar claims involving source code and cloud credentials have surfaced in other recent alleged breaches, including Accenture’s alleged source code and cloud credential leak, though the circumstances surrounding each incident differ.

The forum post also alleges that more than 1 billion payment card records were obtained. BreachNews has not independently verified that claim.

Release threatened for July 21

The threat actor claims the alleged dataset will be published on July 21 through an online portal that would allow users to search and download portions of the purportedly stolen information.

The actor also claimed it would provide advance notice before the planned publication and made statements encouraging market participants to trade on the anticipated release. There is no evidence that the claimed dataset exists in the form described or that any public release will occur.

Public company faces unverified extortion claim

Nayax develops payment and commerce technology for unattended retail environments, including vending machines, parking systems, laundromats, and self-service kiosks. The Israeli fintech company operates globally and is publicly traded on both the Nasdaq and the Tel Aviv Stock Exchange.

While large-scale breach claims involving payment data can pose significant risks if confirmed, threat actors have previously exaggerated the volume or sensitivity of allegedly stolen information to increase pressure on victims during extortion attempts.

The threat actor’s claims remain unverified. While Nayax has now acknowledged a cybersecurity incident involving a subsidiary’s cloud account, the company has not confirmed that customer payment data, source code, internal documents, or the volume of information described by the threat actor were compromised. The investigation remains ongoing.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site
INTEL.BREACHNEWS.COM

Live Cyber
Threat Map

Explore live cyber activity, recent breach reports, KEV alerts, and public threat feeds from a single interactive dashboard.

Launch Threat Map