Multi-CloudCIO BriefingsRetrospectives

CIO Brief: When Ransomware Stops Revenue — The Travelex Timeline

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from December 2019, written in 2026 with the benefit of hindsight.

The short version: On New Year's Eve 2019, ransomware shut down Travelex's systems for weeks. Attackers reportedly got in through a remote access device that had a patch available for eight months. The company paid a ransom and later went into administration.

Why ransomware is a revenue problem

Travelex couldn't sell currency, and the banks and retailers relying on it couldn't serve their customers either. The cost wasn't just the ransom — it was weeks of lost revenue, partner damage and reputational harm at the worst possible time of year.

The timeline matters

  • Months before: a patch for the VPN flaw was available and government agencies warned about exploitation.
  • Attack day: systems encrypted, services offline.
  • Weeks after: manual workarounds, partner frustration, regulatory questions.

Questions to ask your team

  • Which of our internet-facing devices — VPNs, firewalls, remote access gateways — have critical patches outstanding?
  • How long does it take us to patch them after an urgent warning?
  • If ransomware hit our main systems tonight, how long until we could take orders again?
  • Have we tested restoring from backups at full scale?

What good looks like

Edge devices patched within days of critical advisories, MFA on all remote access, tested backups that ransomware can't reach, and a recovery plan measured in hours or days rather than weeks.

The decision

Ask for your recovery time estimate for core revenue systems after ransomware, and when it was last tested. If the answer is a guess, fund a restore test this quarter.

travelex ransomware impactTravelex2019

More on this story