How Travelex is trying to recover from Dec. 31 hack, ordering staff to hand over laptops, using WhatsApp to bypass email, as hackers demand $6M for client data
Travelex had already suspended some services after malware hit its systems on Dec. 31, insisting at that point that no customer data was compromised. The Financial Times reporting shows how deep the disruption runs: staff are surrendering laptops and routing work through WhatsApp because email is untrusted, while the attackers demand $6M for client data.
The arc matters because the company's public posture shifted within months — by April, reporting showed Travelex paid hackers 285 BTC, roughly $2.3M, to regain access, a fraction of the original demand but a confirmation that operations were held hostage rather than quickly restored.
First-order effects
Travelex's currency-exchange operations run on manual workarounds — WhatsApp instead of email, recalled laptops — meaning partners and customers face degraded service while the $6M demand hangs over any data-breach disclosure.
Second-order effects
Corporate clients relying on Travelex for foreign-exchange services must weigh fallback providers, and the gap between the $6M demand and the eventual 285 BTC payment gives every future attacker a real-world reference price for extorting a payments firm.
The trend: Ransomware is migrating from single-company extortion toward supply-chain leverage over financial intermediaries, where one compromised node converts directly into customer-data demands across an entire client base.
World's largest retail currency dealer Travelex is already two weeks offline due to a ransomware attack. I don't feel sorry for them (see their business practices in screenshot) https://www.ft.com/... https://twitter.com/...
UPDATE: Hackers say they have 5gbs of customer data and want $6m from Travelex. The REvil group claims to have had access to the company's systems for 6 months. https://www.bbc.co.uk/...
“They had 7 unpatched Pulse Secure servers” I get that patching is incredibly complex, hard & not as simple as many make it out to be, but there is simply no excuse for having VPNs with a pre-auth RCE vuln, used to protect sensitive data and networks not patched. #Travelex
S&P have downgraded Travelex's credit rating to negative, saying “The effect of this incident will weigh on Travelex's already tight covenant headroom. The incident raises questions about the company's stand-alone creditworthiness.” https://www.standard.co.uk/...
REvil admin saying on Darknet they will release Travelex info. Travelex saying they will NOT pay. If REvil are bluffing, it will damage their operations in future. https://twitter.com/...
Travelex, whose currency booths glimmer with exchange rates around the world, has been dark for nine days after being hacked and held to ransom https://www.nytimes.com/...
Big addition to the annals of unintended consequences: the stiff fines possible for privacy breaches under EU GDPR incentivize ransomeware attacks for big payouts https://www.nytimes.com/... via @NYTimes
Hey look, I'm in The New York Times today. (I'll have more on this story in a bit). “The episode raised questions about how many more parts of the financial system could be at risk, said Bob Sullivan,... https://www.nytimes.com/...