Multi-CloudIncident TeardownsRetrospectives

Travelex Ransomware (Dec 2019): Unpatched VPN Servers and a Business Standstill

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from December 2019, written in 2026 with the benefit of hindsight.

On December 31, 2019, foreign exchange company Travelex was hit by Sodinokibi (REvil) ransomware. Its websites and systems went offline for weeks, and banks and retailers that relied on Travelex for currency services couldn't serve customers.

How it happened

Security researchers reported that Travelex had been running Pulse Secure VPN servers vulnerable to CVE-2019-11510, a critical flaw patched in April 2019 that allowed attackers to read files — including credentials — without authentication. Exploitation was widespread, and US and UK agencies had warned organizations to patch. Ransomware groups used the access to enter networks, move laterally and deploy encryption.

Consequences

Travelex reportedly paid a ransom of about $2.3 million. Its systems were disrupted for weeks during peak travel season. Combined with the COVID-19 collapse in travel months later, the company entered administration in 2020, with parts of the business restructured.

Why it mattered

Travelex showed that a single unpatched internet-facing device could take down an entire business. VPN appliances, which sit at the edge of the network and are trusted by design, became a primary target. That trend continued with vulnerabilities in Fortinet, Citrix, Ivanti and other remote access products through the 2020s.

Lessons in hindsight

  • Edge devices need the fastest patching — days, not months.
  • Assume VPN compromise exposes credentials. Rotate them after patching a credential-leaking flaw.
  • MFA on VPN access limits the value of stolen credentials.
  • Zero trust network access reduces dependence on network-wide VPN access entirely.
  • Ransomware is a business continuity event, not just an IT incident.
travelex ransomwareTravelex2019

More on this story