Don’t do SECURITY. Do business SECURELY.

Travelex taken offline by Sodinokibi ransomware attack

Currency exchange firm Travelex takes its systems offline after a New Year's Eve ransomware attack, disrupting services for UK banks.

Foreign exchange company Travelex took its websites and systems offline after a ransomware attack on New Year’s Eve. The Sodinokibi (also known as REvil) group was reported to be behind it and to have demanded US$6 million.

What happened

  • Travelex staff had to process transactions by hand in branches for weeks.
  • Banks and supermarkets that relied on Travelex for travel money, including several major UK high street banks, could not offer online currency orders.
  • Researchers said Travelex had been running unpatched Pulse Secure VPN servers, for which fixes had been available since April 2019.
  • The Metropolitan Police investigated, and the Wall Street Journal later reported that Travelex had paid a ransom of about US$2.3 million.

Why it mattered

The attack showed how a single supplier’s outage could disrupt many downstream brands and highlighted the risk of leaving known VPN vulnerabilities unpatched.

Lessons for organisations

Patch internet-facing systems such as VPNs as a priority, and map dependencies on critical suppliers so continuity plans cover their failure. Cyber Essentials sets out baseline patching expectations. Test business continuity plans against a prolonged loss of IT, not just a short outage.

Sources: The Register, TechRadar

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights