CIO Brief: When Ransomware Stops Revenue — The Travelex Timeline
Retrospective: this article looks back at events from December 2019, written in 2026 with the benefit of hindsight.
The short version: On New Year's Eve 2019, ransomware shut down Travelex's systems for weeks. Attackers reportedly got in through a remote access device that had a patch available for eight months. The company paid a ransom and later went into administration.
Why ransomware is a revenue problem
Travelex couldn't sell currency, and the banks and retailers relying on it couldn't serve their customers either. The cost wasn't just the ransom — it was weeks of lost revenue, partner damage and reputational harm at the worst possible time of year.
The timeline matters
- Months before: a patch for the VPN flaw was available and government agencies warned about exploitation.
- Attack day: systems encrypted, services offline.
- Weeks after: manual workarounds, partner frustration, regulatory questions.
Questions to ask your team
- Which of our internet-facing devices — VPNs, firewalls, remote access gateways — have critical patches outstanding?
- How long does it take us to patch them after an urgent warning?
- If ransomware hit our main systems tonight, how long until we could take orders again?
- Have we tested restoring from backups at full scale?
What good looks like
Edge devices patched within days of critical advisories, MFA on all remote access, tested backups that ransomware can't reach, and a recovery plan measured in hours or days rather than weeks.
The decision
Ask for your recovery time estimate for core revenue systems after ransomware, and when it was last tested. If the answer is a guess, fund a restore test this quarter.
- Travelex Ransomware (Dec 2019): Unpatched VPN Servers and a Business Standstill Incident Teardowns
- How to Retire Legacy VPNs in Favor of Zero Trust Access How-To & Hardening
- Detecting VPN Vulnerability Exploitation: Sentinel and GuardDuty Detections Detection & Response