CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

The Syndicate

actor · actor:the-syndicate

Extortion/leak-site group claiming (unverified, as of 2026-07-08) a large-scale data theft from fintech Nayax's cloud infrastructure, 1B+ card records, ~1 year dwell, 100 TB exfiltrated; no proof published and the claim conflicts with Nayax's own 'immediately contained' SEC filing (DataBreaches.net, 2026-07-08).

Coverage
1
first 2026-07-09 → last 2026-07-16
Latest activity
2026-07-16
Nayax SEC 6-K reports a contained cloud-account incident; "The Syndicate" claims 1B card records, no proof…
Peak priority
notable
1 notable
Targets
finance
sectors: finance, retail · regions: europe
Sources cited
5
5 hosts

Action items (2)

Do-now tasks recorded on the entries about The Syndicate, newest first. Check the date before acting on an older one.

Defender insights

What each entry about The Syndicate tells a defender to do, newest first.

2026-07-09NOTABLENayax SEC 6-K reports a contained cloud-account incident; "The Syndicate" claims 1B card records, no proof, conflicts with the filing

Latest update

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

attributed activity

Story timeline

  1. 2026-07-09Nayax (Bank-of-Lithuania-licensed EEA payment institution) discloses a cloud-account incident; "The Syndicate" claims 1B card records, claim unverified and contradicted by the filing
    active-threatsNayax SEC 6-K reports a contained cloud-account incident; "The Syndicate" claims 1B card records, no proof, conflicts with the filing
ATT&CK techniques (1 across 1 tactic)

1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • CollectionData from Cloud Storage

Collection TA0009

T1530Data from Cloud Storage×1

Adversaries may access data from cloud storage.

Evidence: 2026-07-09/nayax-cloud-account-incident-the-syndicate-claim · ATT&CK page ↗

Entries about The Syndicate (1)

2026-07-09 · view entry permalink →

NOTABLEupdatedNATOA3

Nayax (Bank-of-Lithuania-licensed EEA payment institution) discloses a cloud-account incident; "The Syndicate" claims 1B card records, claim unverified and contradicted by the filing

Nayax Ltd. an Israeli-headquartered fintech (Nasdaq/Tel Aviv-listed) providing cashless payment terminals and management platforms, and, through Nayax Europe UAB, a Bank-of-Lithuania-licensed payment institution serving more than 23 million enterprises across the EEA (Nayax, 2018-07-17), filed a Form 6-K with the SEC on 2026-07-08 disclosing that it detected "unusual activity" in a cloud account belonging to one of its subsidiaries, which it "immediately blocked and contained" (Nayax SEC Form 6-K, 2026-07-08). Nayax states its production environment and core payment-processing systems were unaffected and business operations continue normally, with the scope still under investigation alongside Israeli and US law enforcement (DataBreaches.net, 2026-07-08).

Separately, an extortion group calling itself "The Syndicate" posted leak-site claims (surfaced by DataBreaches.net on 2026-07-08) asserting it acquired more than 1 billion card records, had been inside Nayax's infrastructure for "almost a year", and exfiltrated over 100 TB, with a threatened ~11-day countdown to a public data portal. No evidence has been published for any of these figures, and DataBreaches.net notes the claims are internally inconsistent with Nayax's "immediately blocked and contained" characterisation, a familiar extortion pattern of inflating scope for leverage. Nayax's stock reportedly fell after the claims surfaced, but the company has not confirmed the attacker's figures (Calcalistech, 2026-07-08). The filing does not disclose the initial-access vector, the cloud provider, or which subsidiary was involved, a material gap for deriving any concrete detection lever from the disclosure alone.

As part of the company's ongoing monitoring, an unusual activity was detected in relation to one of Nayax's subsidiaries, in one of the company's cloud accounts, which was immediately blocked and contained.

The company's production environment and its core systems have not been affected by the event. The company's business activity continues as normal, without impact to the company's business operations.

Nayax Ltd. SEC Form 6-K 2026-07-08

One claim is that they have acquired over 1 billion card records. Another claim is that they have been inside Nayax's servers for almost a year, and have exfiltrated more than 100 TB of data. That claim appears to conflict with a claim that something was immediately blocked and contained or that it was detected quickly.

DataBreaches.net 2026-07-08

The Company's Board of Directors has resolved not to comply with criminal extortion demands.

The Company's systems have been cleared and based on its investigation to date, confirmed to be free of unauthorized access.

Nayax Ltd.
Updaterun 2026-07-16T0409Z-intelevidencesourcestechniquesbody

Nayax Ltd. whose Nayax Europe UAB subsidiary is a Bank-of-Lithuania-licensed payment institution serving EEA enterprises, issued a 14 July status update on the cloud-account incident The Syndicate claimed. Its board of directors "has resolved not to comply with criminal extortion demands," on the stated grounds that compliance would not serve customers', partners', employees' or shareholders' long-term interests (Nayax Ltd., 2026-07-14). Nayax narrowed the disclosed exfiltrated data to a backup of scanned documents, other business information, and mainly a backup of payment-transaction records that it says excludes sensitive payment-authentication data (cardholder names, CVV, ID information), adding that most affected transactions used digital-wallet single-use tokens it describes as valueless if disclosed. It also states remediation is complete and its systems are confirmed free of unauthorized access (Nayax Ltd., 2026-07-14).

incident09 Jul 04:32Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats1

Source distribution

  • calcalistech.com1 (20%)
  • databreaches.net1 (20%)
  • globenewswire.com1 (20%)
  • nayax.com1 (20%)
  • sec.gov1 (20%)