Nayax Refuses Ransom After Backup Copy Stolen

Nayax says hackers copied a backup that did not include cardholder names, CVVs or ID documents; customer safeguarded funds were not accessed and the company will not pay a ransom.

Nayax, an Israeli payments and merchant-loyalty firm, disclosed earlier this month that attackers copied a backup of scanned documents and payment transaction records. The company said the files did not include cardholder names, CVV numbers or identity documents, and that customer safeguarded funds were not accessed. The board said it will not comply with extortion demands and will not pay a ransom.

Investigators identified the copied backup as containing scanned documents, some business-related records and primarily a backup of payment transaction logs. Nayax said the copy did not contain primary cardholder data or identity records.

Some of the affected transactions were processed through digital wallets such as Apple Pay and Google Pay. Those services use single-use tokenized credentials that cannot be reused for new payments, the company said.

Nayax completed a system review and carried out remediation work and reports its systems are now free of unauthorized access. The company has engaged law enforcement and is cooperating with ongoing investigations. It did not name the attackers and gave no detailed timeline beyond saying the intrusion was identified earlier this month.

The firm is notifying affected partners as required and continuing to review logs to confirm the full scope of the breach. Nayax did not say whether it will offer identity monitoring to partners or customers, and it gave no estimate of any financial impact.

In a statement, Nayax’s board said, “We will not comply with criminal extortion demands.”

Articles by this author