Nayax Refuses Ransom After Backup of Transactions Stolen

Nayax says hackers copied a backup of payment transaction records this month but did not access cardholder names, CVVs or IDs. The company refused to pay and reports customer funds were untouched.

Nayax, an Israeli payments and loyalty platform for merchants, disclosed a data breach earlier this month after attackers copied a backup containing payment transaction records and other business files. The company refused to pay a ransom demand.

An internal investigation found the backup included scanned documents, additional business-related information and primarily a backup of payment transaction records. The company reported the copy did not contain cardholder names, CVV values or identity documents.

Some transactions recorded in the backup were processed through digital wallets such as Apple Pay and Google Pay. Those services use single-use tokens for payment credentials, which the company noted would have no value if exposed.

Nayax reported that safeguarded customer funds were not accessed and that there was no unauthorized entry into customer accounts.

The firm completed a system review and remediation that removed unauthorized access and carried out a forensic review to determine the scope of the exposure and restore normal operations. The company says its systems are now free of unauthorized access.

Nayax’s board declined to comply with criminal extortion demands and is cooperating with law enforcement. The company did not disclose the number of merchants or transactions affected and gave no timetable for further disclosures.

Articles by this author