Foreign exchange company Travelex took its websites and systems offline after a ransomware attack on New Year’s Eve. The Sodinokibi (also known as REvil) group was reported to be behind it and to have demanded US$6 million.
What happened
- Travelex staff had to process transactions by hand in branches for weeks.
- Banks and supermarkets that relied on Travelex for travel money, including several major UK high street banks, could not offer online currency orders.
- Researchers said Travelex had been running unpatched Pulse Secure VPN servers, for which fixes had been available since April 2019.
- The Metropolitan Police investigated, and the Wall Street Journal later reported that Travelex had paid a ransom of about US$2.3 million.
Why it mattered
The attack showed how a single supplier’s outage could disrupt many downstream brands and highlighted the risk of leaving known VPN vulnerabilities unpatched.
Lessons for organisations
Patch internet-facing systems such as VPNs as a priority, and map dependencies on critical suppliers so continuity plans cover their failure. Cyber Essentials sets out baseline patching expectations. Test business continuity plans against a prolonged loss of IT, not just a short outage.
Sources: The Register, TechRadar
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.