Skip to content

The Syndicate

The Syndicate is an extortion-oriented cyber threat actor observed publicly claiming responsibility for an alleged compromise of Nayax, an Israeli fintech and payments company.

Profile source: Mallory opens in a new tab

The Syndicate

Family profile

The Syndicate is an extortion-oriented cyber threat actor observed publicly claiming responsibility for an alleged compromise of Nayax, an Israeli fintech and payments company. The actor has used the aliases TheSyndicate and the_syndicate. Publicly attributed activity in this context consists of coercive breach claims and threatened data release intended to pressure the victim into meeting extortion demands.

The group’s known tradecraft in this reporting centers on post-compromise extortion behavior rather than a well-corroborated intrusion set. It has claimed long-term unauthorized access, large-scale data exfiltration, and possession of sensitive business and customer information, followed by threats to publish or provide searchable access to the purportedly stolen data. This pattern is consistent with data-theft extortion operations that seek leverage through reputational harm, regulatory exposure, and downstream fraud risk.

Claimed targeting in this case focuses on the financial technology and payments sector, specifically an Israeli company. The actor’s public messaging asserted theft of payment-related records, customer identity and KYC information, transaction data, credentials, source code, and internal infrastructure information. However, these specific claims were not substantiated with proof in the available reporting, and the victim publicly stated that suspicious activity involving a subsidiary cloud account was blocked and contained, with no confirmed impact to production or core systems at the time of disclosure.

Based on currently available information, The Syndicate should be characterized as an extortion threat actor associated with unverified but high-impact breach claims against a payments-sector target. There is insufficient high-confidence public evidence in this material to attribute the group to a nation state, to define stable sub-groups, or to establish a broader, corroborated history of operations, malware usage, or intrusion techniques beyond extortion and threatened data exposure.

Operational record

MITRE ATT&CK

The Syndicate in ATT&CK

4 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.