ctipilot.ch

The Syndicate

actor · actor:the-syndicate single-source-victim

Extortion/leak-site group claiming (unverified, as of 2026-07-08) a large-scale data theft from fintech Nayax's cloud infrastructure — 1B+ card records, ~1 year dwell, 100 TB exfiltrated; no proof published and the claim conflicts with Nayax's own 'immediately contained' SEC filing (DataBreaches.net, 2026-07-08).

Coverage timeline
3
first 2026-07-09 → last 2026-07-16
Peak priority
notable
2 notable · 1 routine
Sources cited
10
9 hosts
Sections touched
3
active-threats, updates, weekly-incidents-recap
Co-occurring entities
1
see Related entities below
ATT&CK techniques
5
pinned v19.2 · see below
2026-07-093 appearances2026-07-16

ATT&CK techniques

5 techniques observed across 2 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-12/weekly-w28-third-party-cloud-account-exposure · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-07-12/weekly-w28-third-party-cloud-account-exposure · ATT&CK page ↗

T1199Trusted Relationship×1

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-07-12/weekly-w28-third-party-cloud-account-exposure · ATT&CK page ↗

Persistence TA0003

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-12/weekly-w28-third-party-cloud-account-exposure · ATT&CK page ↗

Privilege Escalation TA0004

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-12/weekly-w28-third-party-cloud-account-exposure · ATT&CK page ↗

Stealth TA0005

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-12/weekly-w28-third-party-cloud-account-exposure · ATT&CK page ↗

Collection TA0009

T1530Data from Cloud Storage×1

Adversaries may access data from cloud storage.

Evidence: 2026-07-16/nayax-the-syndicate-board-refuses-extortion-scope-narrowed · ATT&CK page ↗

Exfiltration TA0010

T1567Exfiltration Over Web Service×1

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.

Evidence: 2026-07-12/weekly-w28-third-party-cloud-account-exposure · ATT&CK page ↗

Story timeline

  1. 2026-07-16Nayax refuses The Syndicate's extortion demand and narrows its disclosed breach scope
    updatesNayax's board formally rejects The Syndicate's extortion and says the exfiltrated data excludes sensitive payment-authentication details
  2. 2026-07-12This week's disclosures clustered on third-party, cloud-account and vendor exposure — the breach rarely started inside the victim
    weekly-incidents-recapW28 incidents cluster on third-party / cloud-account exposure — Accenture, Deutsche Bank vendor, KDDI, Nayax cloud account, Odido vishing, Nextcloud misconfig
  3. 2026-07-09Nayax (Bank-of-Lithuania-licensed EEA payment institution) discloses a cloud-account incident; "The Syndicate" claims 1B card records — claim unverified and contradicted by the filing
    active-threatsNayax SEC 6-K reports a contained cloud-account incident; "The Syndicate" claims 1B card records — no proof, conflicts with the filing

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

attributed activity

Where this entity is cited

  • active-threats1
  • weekly-incidents-recap1
  • updates1

Source distribution

  • bleepingcomputer.com2 (20%)
  • calcalistech.com1 (10%)
  • computing.co.uk1 (10%)
  • cybernews.com1 (10%)
  • databreaches.net1 (10%)
  • globenewswire.com1 (10%)
  • nayax.com1 (10%)
  • politie.nl1 (10%)
  • other1 (10%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (10)

Entries about The Syndicate (3)

2026-07-16 · view entry permalink →

ROUTINEupdateNATOA2

Nayax refuses The Syndicate's extortion demand and narrows its disclosed breach scope

UPDATE · originally covered Nayax (Bank-of-Lithuania-licensed EEA payment institution) discloses a cloud-account incident; "The Syndicate" claims 1B card records — claim unverified and contradicted by the filing (2026-07-09)

Nayax Ltd. — whose Nayax Europe UAB subsidiary is a Bank-of-Lithuania-licensed payment institution serving EEA enterprises — issued a 14 July status update on the cloud-account incident The Syndicate claimed. Its board of directors "has resolved not to comply with criminal extortion demands," on the stated grounds that compliance would not serve customers', partners', employees' or shareholders' long-term interests (Nayax Ltd., 2026-07-14). Nayax narrowed the disclosed exfiltrated data to a backup of scanned documents, other business information, and mainly a backup of payment-transaction records that it says excludes sensitive payment-authentication data (cardholder names, CVV, ID information), adding that most affected transactions used digital-wallet single-use tokens it describes as valueless if disclosed. It also states remediation is complete and its systems are confirmed free of unauthorized access (Nayax Ltd., 2026-07-14).

The Company's Board of Directors has resolved not to comply with criminal extortion demands.

The Company's systems have been cleared and based on its investigation to date, confirmed to be free of unauthorized access.

Nayax Ltd.
incident16 Jul 04:46Zsingle-source · victim disclosureOpen finding ↗

2026-07-12 · view entry permalink →

NOTABLENATOB1

This week's disclosures clustered on third-party, cloud-account and vendor exposure — the breach rarely started inside the victim

Read as a set, the week's confirmed incidents point away from the classic perimeter-RCE story and toward exposure that lives in someone else's account, platform or supply chain.

The third-party / vendor strand: Accenture confirmed a data-theft incident after the handle "888" advertised roughly 35 GB of internal source code (BleepingComputer, 2026-07-08); Deutsche Bank disclosed a third-party-vendor incident after the "Unsafe" ransomware group posted claims (Computing, 2026-07-09); and KDDI named a zero-day in third-party email-platform software as the root cause of a breach affecting about 12 million people (BleepingComputer, 2026-07-09). The cloud-account strand: Nayax, a Bank-of-Lithuania-licensed EEA payment institution, disclosed a cloud-account incident (claimed by "The Syndicate") in its own SEC Form 6-K (Nayax, 2026-07-09); ShinyHunters' Odido (Netherlands telecom) breach drew a Dutch-national-involvement assessment from police voice analysis (Politie, 2026-07-08); and Nextcloud GmbH's own hosting infrastructure exposed roughly 367,000 internal records through a misconfigured public Elasticsearch (Cybernews, 2026-07-10).

Why the pattern matters for the constituency: several victims are directly relevant classes — an EEA-licensed payment institution, an EU telecom, a European cloud vendor — and the shared root cause is exactly the exposure a Swiss/EU public-sector or CI organisation inherits through its suppliers and cloud tenancy. The transferable lesson is that a mature internal patch posture does not cover a vendor's zero-day, a supplier's compromised account, or a misconfigured datastore in your own cloud footprint.

Builds on: 2026-07-08/accenture-confirms-data-theft-888-azure-devops-claim · 2026-07-09/deutsche-bank-unsafe-ransomware-third-party-vendor-incident · 2026-07-09/kddi-isp-email-breach-zero-day-root-cause-update · 2026-07-09/nayax-cloud-account-incident-the-syndicate-claim · 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · 2026-07-10/nextcloud-gmbh-elasticsearch-exposure-msb-nrw

incident12 Jul 23:34Zmulti-sourceOpen finding ↗

2026-07-09 · view entry permalink →

NOTABLENATOA3

Nayax (Bank-of-Lithuania-licensed EEA payment institution) discloses a cloud-account incident; "The Syndicate" claims 1B card records — claim unverified and contradicted by the filing

Nayax Ltd. — an Israeli-headquartered fintech (Nasdaq/Tel Aviv-listed) providing cashless payment terminals and management platforms, and, through Nayax Europe UAB, a Bank-of-Lithuania-licensed payment institution serving more than 23 million enterprises across the EEA (Nayax, 2018-07-17) — filed a Form 6-K with the SEC on 2026-07-08 disclosing that it detected "unusual activity" in a cloud account belonging to one of its subsidiaries, which it "immediately blocked and contained" (Nayax SEC Form 6-K, 2026-07-08). Nayax states its production environment and core payment-processing systems were unaffected and business operations continue normally, with the scope still under investigation alongside Israeli and US law enforcement (DataBreaches.net, 2026-07-08).

Separately, an extortion group calling itself "The Syndicate" posted leak-site claims — surfaced by DataBreaches.net on 2026-07-08 — asserting it acquired more than 1 billion card records, had been inside Nayax's infrastructure for "almost a year", and exfiltrated over 100 TB, with a threatened ~11-day countdown to a public data portal. No evidence has been published for any of these figures, and DataBreaches.net notes the claims are internally inconsistent with Nayax's "immediately blocked and contained" characterisation — a familiar extortion pattern of inflating scope for leverage. Nayax's stock reportedly fell after the claims surfaced, but the company has not confirmed the attacker's figures (Calcalistech, 2026-07-08). The filing does not disclose the initial-access vector, the cloud provider, or which subsidiary was involved — a material gap for deriving any concrete detection lever from the disclosure alone.

As part of the company's ongoing monitoring, an unusual activity was detected in relation to one of Nayax's subsidiaries, in one of the company's cloud accounts, which was immediately blocked and contained.

The company's production environment and its core systems have not been affected by the event. The company's business activity continues as normal, without impact to the company's business operations.

Nayax Ltd. — SEC Form 6-K 2026-07-08

One claim is that they have acquired over 1 billion card records. Another claim is that they have been inside Nayax's servers for almost a year, and have exfiltrated more than 100 TB of data. That claim appears to conflict with a claim that something was immediately blocked and contained or that it was detected quickly.

DataBreaches.net 2026-07-08
incident09 Jul 04:32Zmulti-sourceOpen finding ↗