A threat actor has claimed responsibility for an alleged breach of payment technology provider Nayax, asserting that it exfiltrated more than 100TB of internal company data, including payment card information, customer records, source code, financial documents, and internal credentials.
The claims were published on a cybercrime forum alongside a dedicated leak site threatening to release the purportedly stolen data on July 21. At the time of publication, the claims had not been independently verified, and Nayax had not issued any public statement.
Nayax confirms cloud security incident
Update (July 8, 2026): Nayax has since confirmed a cybersecurity incident in a filing with the U.S. Securities and Exchange Commission (SEC), stating that it detected anomalous activity within a cloud account belonging to one of its subsidiaries.
According to the filing, the affected cloud account was immediately blocked after the activity was discovered. Nayax said its production environment, core systems, payment processing infrastructure, and business operations were not affected by the incident.
The company said it is continuing to investigate the scope of the incident with the assistance of external cybersecurity experts and law enforcement authorities in both Israel and the United States. Nayax added that it is still assessing what data, if any, may have been accessed and stated that it does not currently believe material information has been exposed.
Threat actor claims long-term access
According to the forum post, the threat actor allegedly maintained access to Nayax’s environment for nearly a year before exfiltrating data. However, no evidence has been presented that independently verifies the duration of the alleged compromise or the scale of the claimed data theft.
The actor claims the stolen information includes payment card data, Know Your Customer (KYC) records, transaction histories, customer identities, internal API keys, infrastructure documentation, database exports, source code repositories, financial records, email communications, and ERP platform data. Similar claims involving source code and cloud credentials have surfaced in other recent alleged breaches, including Accenture’s alleged source code and cloud credential leak, though the circumstances surrounding each incident differ.
The forum post also alleges that more than 1 billion payment card records were obtained. BreachNews has not independently verified that claim.
Release threatened for July 21
The threat actor claims the alleged dataset will be published on July 21 through an online portal that would allow users to search and download portions of the purportedly stolen information.
The actor also claimed it would provide advance notice before the planned publication and made statements encouraging market participants to trade on the anticipated release. There is no evidence that the claimed dataset exists in the form described or that any public release will occur.
Public company faces unverified extortion claim
Nayax develops payment and commerce technology for unattended retail environments, including vending machines, parking systems, laundromats, and self-service kiosks. The Israeli fintech company operates globally and is publicly traded on both the Nasdaq and the Tel Aviv Stock Exchange.
While large-scale breach claims involving payment data can pose significant risks if confirmed, threat actors have previously exaggerated the volume or sensitivity of allegedly stolen information to increase pressure on victims during extortion attempts.
The threat actor’s claims remain unverified. While Nayax has now acknowledged a cybersecurity incident involving a subsidiary’s cloud account, the company has not confirmed that customer payment data, source code, internal documents, or the volume of information described by the threat actor were compromised. The investigation remains ongoing.











