What happened?
On 31 December 2019, one of the world’s largest foreign exchange companies took every website and mobile app it owned offline. By 7 January 2020 the world knew why: Sodinokibi, the ransomware also tracked as REvil, had encrypted the corporate network of Travelex, and the operators wanted 4.6 million pounds to unlock it. The attack cascaded immediately into the real economy – ASDA, Tesco and Sainsbury’s travel money portals all went dark because they were white-label fronts for Travelex systems. What followed was a month-long manual recovery, a multi-million dollar payment reported by the Wall Street Journal, and by August 2020 an administration that cut more than a thousand UK jobs. This is the verified timeline of the first landmark ransomware story of the decade.
Quick Answer: The Travelex ransomware attack began when Sodinokibi (REvil) operators encrypting the corporate network forced the company to take all customer-facing systems offline on 31 December 2019. The 4.6 million pound (6 million dollar) ransom demand became public on 7 January 2020, along with claims that 5GB of customer data had been copied. Travelex restored bank order systems on 16 January, reportedly paid 2.3 million dollars per later Wall Street Journal reporting, and entered administration on 6 August 2020 carrying the debts and disruption of the incident.
The first any customer knew was silence. On New Year’s Eve 2019, travelex.com and its international siblings stopped responding, and the mobile apps followed. The company’s initial statement spoke of scheduled maintenance and then of a virus, but the operational footprint told the real story: the foreign exchange provider for a chain of UK supermarkets had taken everything down because everything was encrypted. White-label customers noticed within hours. ASDA, Tesco and Sainsbury’s all sold travel money through Travelex back-end services, and their online ordering pages displayed error messages through the first week of January while in-store services limped on manual processes.
The demand becomes public
On 7 January 2020 the situation acquired a number. Media outlets reported that criminals were holding Travelex to ransom, demanding 4.6 million pounds – about 6 million dollars – with the Sodinokibi strain identified as the weapon. The criminals claimed to have copied more than 5GB of customer data, a classic early instance of the double-extortion playbook that would define the following years: pay to unlock your systems, pay again to prevent publication, and trust the word of criminals on whether a copy exists. A seven-day deadline was reported, the kind of manufactured urgency designed to force decisions before forensic teams fully understand the incident.
Travelex’s responses came in careful stages. On 13 January the company announced that it had found no evidence of data being copied – an important nuance, since absence of evidence in a partly encrypted environment is not proof of absence – and said services were resuming. On 16 January it confirmed that automated order placement for several UK high street banks had been restored, and that international money transfers would relaunch by month’s end. On 17 January the chief executive appeared in a video message to say store systems were working again. Each milestone was real, and each one confirmed how deep the encryption had reached.
The paper trail
| Date | Event |
|---|---|
| 2019-12-31 | Travelex takes UK and international websites and apps offline following the attack; supermarket white-label travel money services fail with them |
| 2020-01-07 | Ransom becomes public: 4.6 million pound demand, Sodinokibi identified, claims of 5GB of copied customer data and a seven-day deadline |
| 2020-01-13 | Travelex states no evidence of customer data being copied has been found; services begin resuming |
| 2020-01-16 | Automated order placement restored for several UK high street banks; money transfer relaunch promised by month end |
| 2020-01-17 | Chief executive video message confirms in-store staff systems are working again |
| 2020-04-09 | Wall Street Journal reports Travelex paid the criminals 2.3 million dollars |
| 2020-08-06 | Travelex enters administration; PwC appointed to multiple subsidiaries |
Why Sodinokibi mattered
Sodinokibi, the RaaS operation also known as REvil, was in early 2020 the ascending power in ransomware. It had absorbed techniques and, by widespread industry assessment, affiliates from the GandCrab operation, and it ran the affiliate model professionally: core developers maintained the encryptor, negotiation infrastructure and later the leak site, while affiliates brought access and took the larger share. The Travelex attack displayed the model’s signature discipline. The demand was set high but negotiable. The data-theft claim created a second lever that worked even if backups existed. And the targeting of a payments-adjacent company guaranteed that downtime converted directly into measurable commercial pain, strengthening the criminals’ negotiating position every day systems stayed down.
The payment question
On 9 April 2020 the Wall Street Journal reported that Travelex had paid the attackers 2.3 million dollars. The company did not confirm the figure at the time, and official statements never essayed a number, which is the norm: payment confirmations create legal exposure, insurance complications, and copycat interest. But the reported figure, roughly half the opening demand, matches the typical descent curve of Sodinokibi negotiations documented across that era. For defenders, the payment question is never really about one company. Every verified large payment functions as market research for criminal project planning: it prices downtime, demonstrates solvent victims at scale, and funds the next operation’s tooling and payroll. The year that followed – hospitals, councils, manufacturers – showed what that reinvestment looked like.
Why recovery took weeks
Travelex is often remembered as a website outage, but the encryption reached in-store tills, ordering APIs for bank partners, staff systems and back-office processing. Ransomware at that scale forces an organization to rebuild in layers: isolate what remains, reimage endpoints, restore from any backups that survive, and re-establish integrations one by one because each connection point can reseed the infection if it was dormant. The 16 January restoration of bank order systems, more than two weeks after the attack, was the first sign the spine was back. Manual workarounds – staff reading rates from printed sheets, processing orders by phone – kept retail alive while engineers rebuilt the digital estate. That pattern, brute-force manual continuity plus slow verified restoration, is now standard incident doctrine, and Travelex remains one of its clearest public case studies.
From breach to administration
It would be too simple to say ransomware alone killed Travelex, and honest analysis does not claim it. The company carried heavy debts from its 2015 acquisition, its parent Finablr was sliding toward its own crisis, and COVID-19 would ground international travel within weeks of the incident. But the attack compounded all three pressures at the worst moment. It destroyed a productive quarter of revenue, forced emergency technology spending, and weakened counterparties’ confidence precisely when the group needed credit and buyers. On 6 August 2020, administrators from PwC were appointed to multiple subsidiaries. The restructuring that followed cut over 1,300 UK jobs and closed the majority of UK stores. Anguish of that scale has multiple authors, but the encryption event was the hinge.
- White-label is shared risk: ASDA, Tesco and Sainsbury’s lost travel money services to an attack none of them suffered directly; every third-party dependency is an inherited attack surface.
- “No evidence of copying” is not “no copying”: victims can only report what forensics can see; treat double-extortion claims as plausible until proven otherwise.
- Downtime is the negotiating lever: attacks are priced against business interruption, which makes continuity planning a ransomware control as surely as patching.
- Payment is market data: each large settlement calibrates criminal pricing for everyone else; the decision is per victim but the consequence is shared.
FAQ
What was the Travelex ransomware attack?
It was a ransomware incident in which the Sodinokibi (REvil) operation encrypted the corporate network of Travelex, the world’s largest retail foreign exchange business at the time. The attack forced Travelex to take all websites and apps offline on 31 December 2019 and disrupted white-label travel money services provided to major UK supermarkets and banks. A 4.6 million pound ransom demand became public on 7 January 2020, and recovery stretched across most of January.
What data did the attackers claim to have stolen?
The criminals claimed to have copied more than 5GB of customer personal data and offered a two-part deal: payment for system restoration and payment to prevent publication, with a reported seven-day deadline. Travelex stated on 13 January 2020 that it had found no evidence of data being copied. No verified public dump of Travelex customer data followed, but the claim itself was central to the pressure campaign.
Did Travelex pay the ransom?
The Wall Street Journal reported on 9 April 2020 that Travelex paid 2.3 million dollars to the attackers. The company never officially confirmed payment. The reported figure is roughly half of the initial 6 million dollar demand, consistent with the negotiated reductions typical of Sodinokibi-era extortion.
How long were Travelex systems down?
Customer-facing websites and apps went offline on 31 December 2019 and full service returned in stages through January 2020. By 13 January services were resuming, on 16 January automated bank order systems were restored, and international money transfer relaunch was promised by the end of the month – a recovery arc of roughly four to five weeks for full functionality.
How did the attack affect customers of other brands?
Because ASDA, Tesco and Sainsbury’s sold travel money through white-label services powered by Travelex, their online ordering systems failed when Travelex went offline. Customers of those supermarkets could not order currency online during the outage, illustrating how a single supplier compromise propagates across unrelated consumer brands.
Legacy: the year ransomware grew up in public
Travelex opened 2020 and, in many retrospectives, foreshadowed the decade. It had the celebrity victim, the double-extortion claim, the hidden-then-leaked payment, the industrial fallout, and the corporate casualty count. Security teams took three durable lessons. First, franchise and white-label dependencies make every incident public-facing, regardless of contracts. Second, the extortion conversation happens twice – once for the decryptor, once for the data – and preparing honest answers for the second conversation is now part of breach planning. Third, resilience economics decide outcomes: the organizations that recover fastest pay least and suffer shortest. The administration filing in August 2020 remains the starkest scoreboard entry for what an unprepared encryption event can contribute to, even when it is not the sole cause. The industry that watched Travelex burn spent the rest of the decade building the firebreaks it wished had existed on New Year’s Eve.
