← Blog

Nayax Breach: Cloud Theft Confirmed (Updated)

Share on X

July 14, 2026: Israeli payments firm Nayax (NASDAQ: NYAX) finished its investigation into a July cybersecurity incident and told investors it will not pay ransom despite a July 21 deadline from extortionists who claimed a far larger compromise than the company acknowledges.

What Nayax confirmed

Nayax detected anomalous activity in a subsidiary cloud account around July 7–8, blocked it immediately, and filed with the SEC. Two weeks later the board published fuller findings:

  • Data was exfiltrated from that cloud environment
  • Stolen material included scanned-document backups, general business files, and a backup of payment transaction records
  • Production payment systems were never compromised and operations continued normally
  • The company will not comply with extortion demands, calling payment inconsistent with customer and shareholder interests

What was not exposed — according to Nayax

Nayax drew a bright line around cardholder verification data. It said the transaction backup does not include cardholder names, CVV codes, or government ID numbers — fields Nayax says it generally does not store. It also highlighted that many transactions run through Apple Pay and Google Pay tokenization, which replaces the real card number with a one-time token useless for replay fraud.

Forum actors had marketed a vastly bigger story — on the order of a billion card rows and full KYC archives. Nayax treats that scale as extortion theater unless independently proven. No public victim count has been attested.

Why vending operators care

Nayax hardware sits on millions of unattended devices: vending machines, micro-markets, laundry readers, EV chargers. Even a peripheral cloud backup leak can expose merchant contracts, terminal identifiers, or operational documents useful for social engineering against site owners.

Nayax expects incident-response costs but says it does not anticipate material financial impact. Customers should still watch for fraud spikes on machines tied to their Nayax merchant IDs through July and beyond, especially if the July 21 leak deadline passes without a public dump.

Action items

  1. Verify communications only through nayax.com — not Telegram “support” accounts citing the breach.
  2. Review transaction logs on high-value machines for anomalies after the incident window.
  3. Rotate integration credentials if your deployment team shared cloud or API access with Nayax subsidiaries.
  4. Do not download alleged leak archives from criminal forums; files may be unrelated recycled dumps or malware.

Canonical record: Nayax 2026 incident on BreachHistory.