How the Travelex ransomware attack happened: 7 warned, unpatched VPN servers
Travelex was told in September 2019 that 7 of its remote access servers had a known, fixable security hole, and on New Year's Eve ransomware came in anyway.[1] This case file covers how the attack played out, what it cost the currency exchange giant, and the one control that would have closed the door months earlier.
What happened
Travelex, based in London, was one of the world's best-known foreign currency exchange companies, with airport counters and a large online business. It also supplied travel money services behind the scenes for major UK banks and supermarkets.[2]
On September 13, 2019, a threat intelligence firm that scans the internet for vulnerable systems told Travelex that 7 of its Pulse Secure VPN servers were unpatched against a serious flaw. A VPN server is the gateway staff use to reach the company network from outside. The maker had released fixes months earlier.[1]
On December 31, 2019, attackers using the Sodinokibi ransomware, also called REvil, struck Travelex. The company took its systems offline, and operations were disrupted across some 30 countries.[1] Websites in more than 20 countries went dark, the mobile app stopped working, and branch staff fell back to pen and paper. Banks that relied on Travelex, including Barclays, HSBC, Sainsbury's Bank, Tesco and Virgin Money, could not sell travel money online.[2]
The criminals behind the attack claimed they had been inside the network for 6 months and had taken 5 gigabytes of customer data, and they demanded $6 million.[1] Travelex began bringing some customer-facing services back after about 2 weeks, and its main online services returned roughly a month after the attack.[3][4]
How they got in
A VPN server sits on the edge of the network, facing the open internet, so anyone in the world can reach it. That is its job: it lets employees log in from home or on the road. It also makes it one of the most exposed machines a company owns.
In 2019 a serious flaw was found in Pulse Secure's VPN product, and the vendor published patches in the spring. Security researchers then scanned the internet and found many companies had not installed them; about 1,000 vulnerable servers were still online around the time of the attack.[1] Criminal groups used the unpatched servers as a way in, and the vendor itself warned that attackers were using the flaw to spread this exact ransomware.[1]
Travelex was on the list of companies warned in September, and patches had been available for more than 6 months by the time the attack landed.[1] Once inside, the attackers had time to spread across systems and, by their own account, to copy data before triggering the encryption that locked everything up.
What it cost
In April 2020 the Wall Street Journal reported that Travelex had paid the attackers about $2.3 million in bitcoin to get its systems back.[5] That was on top of weeks of lost sales, manual workarounds and damage to its bank partnerships.[2]
Then the pandemic shut down international travel. In August 2020 Travelex's UK business went into administration as part of a rescue deal, and more than 1,300 UK jobs were cut. The administrators cited both the cyberattack and the collapse in travel caused by COVID-19.[6] The ransomware did not single-handedly sink the company, but it hit at the worst possible time and left it weaker going into the crisis.
The missing control
The missing control: patching internet-facing systems within days, not months. A VPN gateway that the whole internet can reach needs security updates as soon as they are released, especially once the flaw is public and being used by attackers.
Travelex had more than the usual warning. There was a vendor fix, public reporting that criminals were exploiting the flaw, and a direct notice about its own 7 servers in September.[1] Applying the update then, or taking the unpatched servers offline until it could be applied, would have removed the attackers' reported way in, 3 months before the New Year's Eve attack. A clear rule that edge devices get patched within days would have turned that warning into a routine task instead of a company-shaking crisis.
What to do in your business
- List everything that faces the internet. Write down your VPN, firewall, router, remote desktop, email server, website and any device reachable from outside. These get patched first.
- Set a deadline for critical updates. For internet-facing equipment, agree that critical security updates are installed within a few days of release, and put the rule in writing with your IT provider.
- Turn on automatic updates where you can. Many firewalls and routers can update themselves. Where they cannot, sign up for the vendor's security alerts.
- Treat outside warnings as urgent. If a vendor, researcher or government agency tells you a system is vulnerable, assign a named person to fix it that week and confirm when done.
- Keep offline backups and a manual plan. Test that you can restore key systems from backups that ransomware cannot reach, and know how you would keep serving customers for a week without computers.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: How a small business keeps software and devices patched, and why default passwords must go
- What caused the Equifax breach? An unpatched website and an expired certificate
- How the Capital One breach happened: one misconfigured cloud firewall
- What happened to Knight Capital: $460 million lost in 45 minutes
- How WannaCry hit the NHS: the fix existed 2 months before the attack
- How the Heartland breach happened: 130 million cards and an informant
- How the HSE cyber attack happened: one spreadsheet and 8 weeks of ignored alerts
- Every patching and monitoring control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- Bitdefender HOTforSecurity: Pulse Secure VPN server exploit opens the way for Sodinokibi ransomware, Travelex falls victim
- Threatpost: Travelex pays $2.3M in bitcoin to hackers who hijacked network in January
- FinTech Global: Travelex has recovered some of its systems after being crippled by a ransomware attack for two weeks
- Graham Cluley: Travelex hobbles back online, one month after ransomware hit it hard
- The Next Web: Travelex paid $2.3M in bitcoin to get its systems back from hackers
- Travel Weekly: Over 1,300 Travelex UK jobs lost in complex debt restructure