/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Report: Travelex paid hackers 285 BTC, worth around $2.3M, to regain access to its systems after a ransomware attack on New Year's Eve

Travelex paid hackers $2.3 million worth of Bitcoin to regain access to its computer systems after a devastating ransomware attack on New Year's Eve, reports the Wall Street Journal. Source: Wall Street Journal .

The Next Web David Canellis

Context & Ripple Effects

Travelex's New Year's Eve breach unfolded publicly in stages: the company first suspended services citing malware while insisting no customer data had been compromised, then within two weeks was running recovery on WhatsApp and hand-delivered laptops as hackers demanded $6 million for client data. The Wall Street Journal's report closes that arc with a number: 285 BTC, about $2.3 million at the time — well under the original demand.

The disclosure lands amid a widening record of travel-sector firms settling in bitcoin. A leaked chat log later showed US travel management firm CWT negotiating down to a $4.5 million BTC payment, making Travelex one data point in an emerging pattern rather than an outlier.

First-order effects

  • Travelex has confirmed it capitulated: it paid roughly a third of the $6 million demanded, meaning the attackers' leverage came from locked systems and threatened client-data exposure, not just encryption.
  • Bitcoin is established as the settlement rail of choice — pseudonymous enough for attackers, liquid enough to move millions during a live outage.

Second-order effects

  • Every disclosed payment lowers the perceived risk of attacking travel and financial-services firms whose revenue depends on uptime, effectively subsidizing the next campaign against peers like CWT.
  • Insurers, boards, and regulators now have a documented precedent of a major currency-exchange firm paying, forcing explicit decisions on whether ransom coverage and disclosure policies treat payment as routine incident response.

Third-order effects

  • Paying no longer ends the story: US investigators' later seizure of nearly 64 of the ~75 bitcoins Colonial Pipeline paid shows law enforcement tracing and clawing back ransoms, shifting the calculus from 'pay quietly' to 'pay and still face recovery and scrutiny.'
  • If the pattern holds, ransomware moves from an IT problem to a national-security and sanctions-compliance issue, with payment disclosures becoming mandatory rather than voluntary.

The trend: Ransomware is industrializing into a negotiated bitcoin-settled extortion market targeting uptime-dependent firms, even as investigators learn to trace and seize the payments.

Discussion

  • @spignal Stanley Pignal on x
    Travelex paid $2.3m to hackers to get it's IT systems back up and running, which is roughly how much it charges customers to change £100 into $ at Heathrow. https://twitter.com/...
  • @wsjmarkets @wsjmarkets on x
    U.K. foreign-exchange company paid about $2.3 million in bitcoin to cybercriminals months before its business began unraveling https://www.wsj.com/...
  • @elizabethrkoh Elizabeth Koh on x
    You won't want to miss anything in this @wsj scoop but esp. this: “The Journal reached the ostensible hackers by replicating what a cybersecurity consultant believes to be the virus used to attack Travelex. That opened up a chat portal meant to serve as a hotline to the hackers.”…
  • @gossithedog Kevin Beaumont on x
    Wall Street Journal reports Travelex secretly paid ransomware group REvil $2.3m. REvil say they deleted data they had stolen from Travelex in exchange for the payment. Really strange considering Travelex said they had the NCA on site and ICO involved.. https://www.wsj.com/...
  • @zackwhittaker Zack Whittaker on x
    Travelex “responded by paying the hackers the equivalent of $2.3 million, according to a person familiar with the transaction.” https://www.wsj.com/...