Travelex was hit by Sodinokibi/REvil ransomware in a New Year’s Eve attack that disrupted its website, mobile app, and card-payment systems across more than 1,500 stores worldwide. The attackers said they had encrypted the company’s network, stolen more than 5GB of files, deleted backups, and demanded $3 million, later escalating pressure by threatening to publish or sell allegedly stolen customer data that they claimed included dates of birth, Social Security numbers, and payment-card information. Travelex acknowledged that some data had been encrypted but said it had no evidence that customer data had been exfiltrated, creating a direct dispute with the gang’s public claims.
Reporting later indicated Travelex likely paid 285 bitcoin—about $2.3 million at the time—to the REvil operators as recovery efforts dragged on for weeks. The incident drew added scrutiny because researchers had previously flagged Travelex’s exposure to insecure internet-facing services, including a potentially unpatched Pulse Secure VPN vulnerable to CVE-2019-11510 and Windows servers exposed without Network Level Authentication, though the exact intrusion path was not confirmed. Travelex did not directly confirm the payment, saying it had worked with external experts while keeping regulators, partners, and U.K. law enforcement informed as services were gradually restored.

TTPs, infrastructure, and targeting history in one profile.
10 events from the most recent confirmed update back to the earliest known activity.
The Wall Street Journal reported that Travelex paid the REvil gang 285 bitcoin, worth about $2.3 million at the time, citing a person with knowledge of the transaction. Travelex declined to directly confirm the payment and said a U.K. law-enforcement investigation was continuing.
Travelex stated that some data encryption had occurred and that it had taken steps to contain the ransomware's spread. The company said it had no evidence that structured personal customer data had been encrypted or that any data had been exfiltrated.
The Sodinokibi/REvil operators told BleepingComputer they had increased their ransom demand from $3 million to $6 million while claiming to be negotiating with Travelex. They also threatened to release or sell allegedly stolen customer data if payment was not made.
Reporting confirmed that Travelex had been infected with Sodinokibi/REvil ransomware. The attackers claimed they encrypted the entire network, stole more than 5GB of personal data, deleted backups, and demanded $3 million while threatening to publish the data within seven days if unpaid.
ComputerWeekly first reported insider information that Travelex had suffered a ransomware attack. This was one of the earliest public reports identifying the nature of the outage.
By the end of January, Travelex began restoring operations and bringing services back online after weeks of disruption. Some systems had remained offline for an extended period following the attack.
Travelex suffered a cyberattack beginning on December 31 that disrupted its website, mobile app, and card-payment capabilities across more than 1,500 stores worldwide. The company took systems offline to contain the incident and prevent the malware from spreading.
A public exploit for Pulse Secure VPN vulnerability CVE-2019-11510 became available, after which attackers began scanning the internet for vulnerable endpoints. The article cites this as part of the threat landscape preceding the Travelex incident.
French authorities released a free decryptor for pyLocky ransomware versions 1 and 2, allowing victims to recover encrypted files without paying. The tool was developed with contributions from the French Ministry of Interior, BEFTI, ST(SI)² of the Gendarmerie nationale, and volunteer researchers.
Pulse Secure patched CVE-2019-11510, a VPN vulnerability that could allow unauthenticated remote access to corporate networks on unpatched systems. The flaw was later discussed as a possible exposure relevant to Travelex's environment.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
grahamcluley.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.