Case file · TRAVELEX 2020

How the Travelex ransomware attack happened: 7 warned, unpatched VPN servers

Published 2026-09-29 · 5 min read · Missing control: Patch internet-facing VPNs within days

Travelex was told in September 2019 that 7 of its remote access servers had a known, fixable security hole, and on New Year's Eve ransomware came in anyway.[1] This case file covers how the attack played out, what it cost the currency exchange giant, and the one control that would have closed the door months earlier.

What happened

Travelex, based in London, was one of the world's best-known foreign currency exchange companies, with airport counters and a large online business. It also supplied travel money services behind the scenes for major UK banks and supermarkets.[2]

On September 13, 2019, a threat intelligence firm that scans the internet for vulnerable systems told Travelex that 7 of its Pulse Secure VPN servers were unpatched against a serious flaw. A VPN server is the gateway staff use to reach the company network from outside. The maker had released fixes months earlier.[1]

On December 31, 2019, attackers using the Sodinokibi ransomware, also called REvil, struck Travelex. The company took its systems offline, and operations were disrupted across some 30 countries.[1] Websites in more than 20 countries went dark, the mobile app stopped working, and branch staff fell back to pen and paper. Banks that relied on Travelex, including Barclays, HSBC, Sainsbury's Bank, Tesco and Virgin Money, could not sell travel money online.[2]

The criminals behind the attack claimed they had been inside the network for 6 months and had taken 5 gigabytes of customer data, and they demanded $6 million.[1] Travelex began bringing some customer-facing services back after about 2 weeks, and its main online services returned roughly a month after the attack.[3][4]

How they got in

A VPN server sits on the edge of the network, facing the open internet, so anyone in the world can reach it. That is its job: it lets employees log in from home or on the road. It also makes it one of the most exposed machines a company owns.

In 2019 a serious flaw was found in Pulse Secure's VPN product, and the vendor published patches in the spring. Security researchers then scanned the internet and found many companies had not installed them; about 1,000 vulnerable servers were still online around the time of the attack.[1] Criminal groups used the unpatched servers as a way in, and the vendor itself warned that attackers were using the flaw to spread this exact ransomware.[1]

Travelex was on the list of companies warned in September, and patches had been available for more than 6 months by the time the attack landed.[1] Once inside, the attackers had time to spread across systems and, by their own account, to copy data before triggering the encryption that locked everything up.

What it cost

In April 2020 the Wall Street Journal reported that Travelex had paid the attackers about $2.3 million in bitcoin to get its systems back.[5] That was on top of weeks of lost sales, manual workarounds and damage to its bank partnerships.[2]

Then the pandemic shut down international travel. In August 2020 Travelex's UK business went into administration as part of a rescue deal, and more than 1,300 UK jobs were cut. The administrators cited both the cyberattack and the collapse in travel caused by COVID-19.[6] The ransomware did not single-handedly sink the company, but it hit at the worst possible time and left it weaker going into the crisis.

The missing control

The missing control: patching internet-facing systems within days, not months. A VPN gateway that the whole internet can reach needs security updates as soon as they are released, especially once the flaw is public and being used by attackers.

Travelex had more than the usual warning. There was a vendor fix, public reporting that criminals were exploiting the flaw, and a direct notice about its own 7 servers in September.[1] Applying the update then, or taking the unpatched servers offline until it could be applied, would have removed the attackers' reported way in, 3 months before the New Year's Eve attack. A clear rule that edge devices get patched within days would have turned that warning into a routine task instead of a company-shaking crisis.

What to do in your business

Watch the case
Travelex was warned about 7 unpatched servers, then ransomware hitDrops 2027-01-19
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More patching and monitoring cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. Bitdefender HOTforSecurity: Pulse Secure VPN server exploit opens the way for Sodinokibi ransomware, Travelex falls victim
  2. Threatpost: Travelex pays $2.3M in bitcoin to hackers who hijacked network in January
  3. FinTech Global: Travelex has recovered some of its systems after being crippled by a ransomware attack for two weeks
  4. Graham Cluley: Travelex hobbles back online, one month after ransomware hit it hard
  5. The Next Web: Travelex paid $2.3M in bitcoin to get its systems back from hackers
  6. Travel Weekly: Over 1,300 Travelex UK jobs lost in complex debt restructure