2020 Ransomware (Sodinokibi/REvil)
Data compromised
DOB, credit cards, national insurance numbers
Technical writeup
Dec 31, 2019 / Jan 2020. Travelex was hit by Sodinokibi/REvil ransomware. Attackers claimed 6 months of network access and exfiltration of 5GB of customer data including DOB, credit card info, and national insurance numbers. Travelex paid $2.3M ransom; systems offline for ~2.5 weeks across 30 countries. Unpatched Pulse Secure VPN (CVE-2019-11510) was likely the entry point. Parent company Finablr entered administration.
Root cause
Ransomware; unpatched VPN vulnerability (CVE-2019-11510).