Nayax
Syndicate threat group claims 100+ terabytes from payment solutions provider. Nayax powers transactions for vending machines, EV charging, laundromats, and self-service kiosks globally.
What happened?
Syndicate threat group claimed a breach at Nayax, an Israeli payment solutions provider operating globally. They claim theft of over 100 terabytes—an extraordinary volume suggesting comprehensive systems data, not just database exports.
Nayax provides payment processing for unattended retail: vending machines, self-service kiosks, EV charging stations, laundromats. The invisible payment layer behind machines people interact with daily.
What data was actually inside?
100+ terabytes from a payment processor includes transaction logs, merchant data, payment processing records, and technical infrastructure details. PCI-DSS regulated payment card data. Merchant business information. System architecture documentation.
Nayax operates across 50+ countries. Vending operators, parking companies, laundry businesses, EV charging networks. Each merchant relationship creates data that flows through their systems.
Who gets hurt and how?
Every merchant using Nayax for payment processing. Every consumer who tapped a card at a Nayax-powered machine. Transaction data reveals purchasing patterns. Merchant data reveals business operations. The exposure multiplies across the payment ecosystem.
Payment processor breaches create cascading risk. Merchants depend on the processor's security. Consumers depend on merchants. The payment chain is only as strong as its weakest link.
What did they think they were doing right?
Payment processors operate under PCI-DSS requirements. Regular audits. Security assessments. Compliance is mandatory for handling payment card data.
But 100 terabytes suggests comprehensive access. Not a single database breach—systems-level extraction. The volume indicates attackers had substantial access over time to accumulate that much data.
What did they not know about their own data?
100 terabytes accumulates over time. Transaction logs. System backups. Merchant onboarding records. Technical documentation. The data grows with every transaction processed, every merchant connected, every system documented.
Understanding what exists at that scale requires deliberate inventory. Payment processors generate data continuously. Without active management, the accumulation is unlimited.
If your business runs on databases, you probably have similar records—customer data, credentials, financial information. Do you know what's actually in yours?
What does attribution look like the morning after?
PCI-DSS breach notification requirements. Merchant notifications across 50+ countries. Payment card brand involvement for potential card compromise. The response spans the global payment ecosystem.
Syndicate as a threat actor has targeted fintech. Payment processing remains a high-value target for the density of financial data and the monetization opportunities.
What would have changed the outcome?
Data lifecycle management that limits accumulation—ensuring 100 terabytes doesn't exist to be stolen.
Payment data has limited operational lifespan. Completed transactions don't need indefinite retention. Aggressive data minimization reduces what attackers can take. The organizations that limit breach scope are the ones that don't accumulate data beyond operational necessity.
Nayax found out the hard way.
Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.