← Travelex

2020 Ransomware (Sodinokibi/REvil)

2020 Unknown records affected Share on X

Data compromised

DOB, credit cards, national insurance numbers

Technical writeup

Dec 31, 2019 / Jan 2020. Travelex was hit by Sodinokibi/REvil ransomware. Attackers claimed 6 months of network access and exfiltration of 5GB of customer data including DOB, credit card info, and national insurance numbers. Travelex paid $2.3M ransom; systems offline for ~2.5 weeks across 30 countries. Unpatched Pulse Secure VPN (CVE-2019-11510) was likely the entry point. Parent company Finablr entered administration.

Root cause

Ransomware; unpatched VPN vulnerability (CVE-2019-11510).

References