Travelex shuts down computers after ransomware attack
Wednesday, 8 January 2020
Foreign exchange service Travelex has shut down its computer systems and websites, including in New Zealand, while it investigates an alleged computer hack.
The BBC reported the company was being held to ransom by a ransomware gang called Sodinokibi that said it gained access to the company's computer network six months ago and downloaded 5 gigabytes of sensitive customer data.
The gang was demanding a US$6 million (NZ$9m) ransom, it reported.
Travelex.co.nz was on Wednesday displaying a notice saying its online, foreign currency purchasing service was temporarily unavailable due to 'planned maintenance' and would be back online shortly.
**READ MORE:
* NotPetya cyber attack's intention may have been malware installation in Ukraine
* Ports of Auckland among first to report fall-out from ransomware attack
* New Zealand upping digital security after 'massive' worldwide** cyberattack
But call centre staff were advising customers who called that Travelex was concerned that a software virus discovered on New Year's Eve had 'compromised some of its services'.
'As precautionary measure in order to protect data and prevent the spread of the virus we immediately took all of our systems offline,' according to a statement staff had been authorised to provide to customers.
'Our investigation to date shows no indication that any personal or customer data has been compromised.'
Travelex owns currency exchange booths in many New Zealand cities.
Its branch network was continuing to provide foreign exchange services manually, the company's statement said.
'We have deployed teams of IT specialists and external cyber-security experts who have been working continuously since New Year's Eve to isolate the virus and restore effected systems,' its statement said.