Get 40% Off
👀 👁 🧿 All eyes on Biogen, up +4,56% after posting earnings. Our AI picked it in March 2024.
Which stocks will surge next?
Unlock AI-picked Stocks

Travelex staff go back to basics as ransomware cripples systems

Published 01/08/2020, 09:10 AM
Updated 01/08/2020, 09:10 AM
© Reuters. Signage with graffiti next to it is seen on a branch of Travelex Currency Exchange in London

By Noor Zainab Hussain and Kirstin Ridley

LONDON (Reuters) - Staff at foreign exchange firm Travelex are using pen and paper to serve thousands of customers after the company said cyber hackers were holding its systems to ransom, leading to a global blackout on its online currency exchange services.

The currency trader, which also provides forex services for customers of HSBC (L:HSBA), Barclays (L:BARC), Virgin Money (L:VMUK) and the banking arms of British retailers Tesco (L:TSCO) and Sainsbury (L:SBRY), said on Tuesday a software virus identified on Jan. 2 was a ransomware attack.

The spread of the ransomware, which Travelex said it had successfully contained, forced the company to take all its systems offline, causing chaos for New Year holidaymakers and business travellers seeking online currency services.

The company, which has a presence in more than 70 countries, is currently only able to serve customers face-to-face at its 1,200 on-airport and off-airport locations worldwide.

A criminal investigation led by London's Metropolitan Police is now also underway.

The Financial Conduct Authority, Britain's markets regulator, said it was also in contact with the firm to ensure affected customers were being treated fairly. The National Cyber Security Centre said it was providing technical support.

Scores of people turned to Twitter to vent their frustration at being left without cash they had ordered for their travels.

Travelex's parent company Finablr Plc (L:FINF) said the hackers used a type of ransomware called Sodinokibi -- also commonly referred to as REvil -- in an attempt to encrypt customer data.

3rd party Ad. Not an offer or recommendation by Investing.com. See disclosure here or remove ads .

Travelex said there was no evidence yet that any data had been stolen..

Finablr processes more than 150 million transactions per year -- all of which rely on the efficient and uninterrupted operation of computer and communication systems. According to its listing prospectus, published last year, the company has computer-crime insurance to cover cyber risks.

But the incident sent the company's shares slumping almost 20% to a record low on Wednesday, a drop exacerbated by two major investors selling shares worth about $72 million in the payments firm.

A Virgin Money spokesman said customers were unable to place orders via the Virgin Money Travel Money website or any Travelex website or the contact centre but that customers could process orders at a Travelex Bureau directly.

Sainsbury's Chief Executive Mike Coupe described the incident as "disruptive" but said customers could still buy currency over-the-counter, while a spokesman for Tesco said its 360 in-store Travel Money outlets were operating as normal.

A spokeswoman for HSBC said its UK bank branches held some euro and dollar stock for immediate purchase but it was unable to take travel money orders. Barclays apologised to its affected customers and said it would restore service "as soon as it was able to do so".

Travelex, which had computer specialists and external cybersecurity experts work on isolating the virus, is gradually restoring a number of internal systems and is working to resume normal operations as quickly as possible.

Global companies are increasingly facing ransom-demanding hackers who cripple businesses' technology systems and only stop after receiving substantial payments.

3rd party Ad. Not an offer or recommendation by Investing.com. See disclosure here or remove ads .

These hackers use malicious programmes such as ransomware to take down systems controlling everything from supply chains to payments to manufacturing.

Neither Finablr nor Travelex provided any detail on the costs of handling the incident so far but Finablr said it did not currently expect to suffer any material financial impact from the incident.

Another European company aluminium maker Norsk Hydro (OL:NHY) faced costs of between 300 million and 350 million Norwegian crowns ($39.52 million) in its first quarter last year following a similar cyber attack in March.

"The ongoing attack against Travelex is arguably the worst case scenario for how crippling ransomware can be," Stuart Reed, vice president for cybersecurity at British web services firm Nominet said.

"If there was ever any doubt that a cyber attack could have a significant effect on financial markets, this proves otherwise."

Hackers have grown more sophisticated during the past year, cybersecurity experts say, shifting from individuals to larger companies that can afford bigger ransoms.

In August, hundreds of dental offices around the United States found they could no longer access their patient records because of a Sodinokibi attack, according to Malwarebytes, which sells cybersecurity software.

Finablr's other six brands - UAE Exchange, Xpress Money, Unimoni, Remit2India, Ditto and Swych -- are not affected and are operating normally, it said.

($1 = 8.8580 Norwegian crowns)

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.