Travelex website was hit by Sodinokibi ransomware

(Image credit: Shutterstock.com / ymgerman)

Travelex has confirmed that a major cyberattack that took its business offline last week was caused by ransomware.

The foreign exchange giant has revealed it was hit by the notorious Sodinikibi ransomware in an attack on New Year's Eve, with the criminals behind the attack demanding a $6m payment to restore stolen files.

Travelex was forced to take down its websites in 30 countries in an attempt to try and control the attack, with customers across Europe, Asia and the US still unable to gain online access to their accounts.

Ransom

The group behind the attack, known as REvil, claim to have gained access to Travelex's network six months ago. 

REvil says it has a 5GB stash of downloaded information from the company, including customer dates of birth, credit card information and national insurance numbers.

"In the case of payment, we will delete and will not use that (data)base and restore them the entire network," the group said in a statement.

"The deadline for doubling the payment is two days. Then another seven days and the sale of the entire base."

Travelex may be set to face further punishment after the ICO revealed it had not received a data breach notice from the company. Under GDPR legislation, organisations must notify the ICO within 72 hours - unless the breach is deemed not to pose a risk to people's rights and freedoms.

Failure to comply could cost Travelex millions in fines, with the ICO able to issue a fine of four percent of an offender's global turnover.

"If an organisation decides that a breach doesn't need to be reported, they should keep their own record of it and be able to explain why it wasn't reported if necessary," the ICO added.

Travelex says it is working with the Metropolitan Police alongside its own teams of IT specialists and external cyber-security experts to investigate the attack.

"On Thursday, 2 January, the Met's Cyber Crime Team were contacted with regards to a reported ransomware attack involving a foreign currency exchange," the Met said in a statement. "Inquiries into the circumstances are ongoing."

Via BBC

TOPICS
Mike Moore
Deputy Editor, TechRadar Pro

Mike Moore is Deputy Editor at TechRadar Pro. He has worked as a B2B and B2C tech journalist for nearly a decade, including at one of the UK's leading national newspapers and fellow Future title ITProPortal, and when he's not keeping track of all the latest enterprise and workplace trends, can most likely be found watching, following or taking part in some kind of sport.

Latest in Security
Woman shocked by online scam, holding her credit card outside
Cybercriminals used vendor backdoor to steal almost $600,000 of Taylor Swift tickets
Woman using iMessage on iPhone
UK government guidelines remove encryption advice following Apple backdoor spat
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
HTTPS in a browser address bar
Malicious "polymorphic" Chrome extensions can mimic other tools to trick victims
ransomware avast
Hackers spotted using unsecured webcam to launch cyberattack
Latest in News
MacBook Air mute key
The new M4 MacBook Air finally fixes an Apple keyboard annoyance that's been around for decades
A collage of Ellie and Joel in The Last of Us season 2
The Last of Us season 2's new trailer teases a huge showdown between Bella Ramsey's Ellie and Pedro Pascal's Joel, but the big moment I'm waiting for is still being held back
Apple iPhone 16 Pro Max REVIEW
New iPhone 17 Air leak may have revealed some key specs – and how it compares to the iPhone 17 Pro Max
Gaming with AI
I asked Gemini to play a text-based adventure game with me and the AI whisked me away to a word-based fantasy
Apple iPhone 16 Review
Three iPhone 17 model dummy units appear in a hands-on video leak
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
New Samsung Galaxy S25 Edge may have revealed some key details – including its price