Travelex Ransomware (Dec 2019): Unpatched VPN Servers and a Business Standstill
Retrospective: this article looks back at events from December 2019, written in 2026 with the benefit of hindsight.
On December 31, 2019, foreign exchange company Travelex was hit by Sodinokibi (REvil) ransomware. Its websites and systems went offline for weeks, and banks and retailers that relied on Travelex for currency services couldn't serve customers.
How it happened
Security researchers reported that Travelex had been running Pulse Secure VPN servers vulnerable to CVE-2019-11510, a critical flaw patched in April 2019 that allowed attackers to read files — including credentials — without authentication. Exploitation was widespread, and US and UK agencies had warned organizations to patch. Ransomware groups used the access to enter networks, move laterally and deploy encryption.
Consequences
Travelex reportedly paid a ransom of about $2.3 million. Its systems were disrupted for weeks during peak travel season. Combined with the COVID-19 collapse in travel months later, the company entered administration in 2020, with parts of the business restructured.
Why it mattered
Travelex showed that a single unpatched internet-facing device could take down an entire business. VPN appliances, which sit at the edge of the network and are trusted by design, became a primary target. That trend continued with vulnerabilities in Fortinet, Citrix, Ivanti and other remote access products through the 2020s.
Lessons in hindsight
- Edge devices need the fastest patching — days, not months.
- Assume VPN compromise exposes credentials. Rotate them after patching a credential-leaking flaw.
- MFA on VPN access limits the value of stolen credentials.
- Zero trust network access reduces dependence on network-wide VPN access entirely.
- Ransomware is a business continuity event, not just an IT incident.
- How to Retire Legacy VPNs in Favor of Zero Trust Access How-To & Hardening
- Detecting VPN Vulnerability Exploitation: Sentinel and GuardDuty Detections Detection & Response
- CIO Brief: When Ransomware Stops Revenue — The Travelex Timeline CIO Briefings