Menu
Browse

Cyber Incident Victim: Travelex

Date:

Dec 2019

Location:

United Kingdom

Summary

A foreign-currency exchange service was forced to take its website offline following a cyber attack involving a software virus, prompting manual transaction processing at physical branches. The company stated specialized teams were working to contain the threat and restore systems, with initial investigations indicating no evidence of compromised personal or customer data. Service disruptions extended to third-party partners relying on the platform, including a major bank's travel money operations. Leadership publicly apologized for inconveniences caused by the incident while emphasizing efforts to resume full functionality.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On December 31, 2019, Travelex experienced a cyber attack involving a software virus, prompting immediate action to take its website offline. The foreign currency exchange provider began working to address the incident on New Year’s Eve, suspending certain digital services to contain the virus and prevent potential data compromise. CEO Tony D'Souza publicly apologized for service disruptions, confirming the company had switched to manual foreign-exchange transactions at its physical branches to maintain operations. Travelex emphasized its commitment to restoring full services as quickly as possible while prioritizing data protection. Initial investigations conducted by the company found no evidence that personal or customer data had been accessed or exfiltrated during the attack.

Cyber Incident Image

Travelex mobilized internal IT specialists and external cybersecurity experts to isolate the virus and repair affected systems, with teams working continuously from the attack’s discovery. The manual service model remained in place across branches during the recovery effort. The website outage created secondary disruptions for third-party services reliant on Travelex’s platform, including Tesco Bank’s travel money offerings, which became unavailable. Tesco Bank acknowledged the issue publicly via Twitter but did not specify a resolution timeline. Travelex reiterated its focus on containment and system restoration but provided no further technical details about the attack vector or scope beyond confirming the website takedown as a containment measure. The company maintained its apology to customers for ongoing inconveniences caused by the incident.

Sources
Sources available to members
1 source