NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

Juha Saarinen: Travelex attack could have been much worse

Juha Saarinen
By Juha Saarinen
Tech blogger for nzherald.co.nz.·NZ Herald·
13 Jan, 2020 04:00 PM5 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

You can't help feeling that the attack was an accident waiting to happen. Photo / 123RF

You can't help feeling that the attack was an accident waiting to happen. Photo / 123RF

COMMENT:

Imagine popping into work at Travelex on New Year's Eve, waking up the computer and instead of the familiar Windows desktop seeing a message that your files are encrypted and to get access to them you have to pay a few cool million in Bitcoin.

READ MORE:
• target="_blank">Travelex held to ransom by hackers demanding $8.5m
• Juha Saarinen: Protect your digital life with security keys
• Juha Saarinen: Phone number theft a nightmare to sort out

The foreign exchange giant is the latest high-profile organisation to be hit by ransomware criminals. As more details on the attack emerge, you can't help feeling that it was not only an accident waiting to happen but also that Travelex might have dodged an even bigger bullet.

Yes, really: last year, security researchers say they alerted Travelex to critical networked software vulnerabilities that if left unpatched would leave systems wide open to attacks.

Advertisement
Advertise with NZME.

Travelex appears to have taken months to patch the vulnerabilities. Other researchers noted that some of the company's internet-connected cloud servers exposed a Windows remote control service that is currently under large-scale attack as a serious bug in older versions allows hackers to connect to it without authentication and gain full access to systems.

Marcus Hutchins, the security researcher credited with taking the edge off the WannaCry attack, said he didn't understand why after breaching a company that processes something like $100 billion a year the hackers decided merely to ransomware Travelex.

If indeed the attackers were in Travelex's network for six months they had every opportunity to cause "material financial impact".

Advertisement
Advertise with NZME.

As of writing, Travelex is still down and it's not clear when staff will be able to put down their pens and paper and start using computers again. At least Travelex has now removed the "planned maintenance" page on its sites and owned up to the Sodikinobi/REvil attack.

Either way, 2020 must be the year to sit down and figure out how not to get hit by ransomware.

Discover more

Business

Juha Saarinen: Weapons of mouse destruction go wireless

03 Dec 04:00 PM
Business

Keep your tech safe on the road this summer

29 Dec 04:00 PM
Business

Juha Saarinen: Only you can fix fake news

17 Dec 04:00 PM
Business

Juha Saarinen: Microsoft needs to go Marie Kondo on Windows

12 Jan 06:00 AM

The problem is that ransomware has low barriers to entry and is difficult to defend against.

It's easy to obtain malware and use it pseudonymously enough from Eastern Europe or elsewhere to avoid getting arrested immediately. Usually it takes hackers going on a luxury overseas holiday to be arrested and extradited to stand trial but that can take years.

The ransomware attacks are getting nastier too. In December the Maze ransomware crims started posting some data taken from victims' who hadn't paid up. That's one hell of an escalation that could cause serious damage to those ransomed and individuals and companies whose information is being leaked.

Travelex is a currency exchange specialist. Photo / Getty Images
Travelex is a currency exchange specialist. Photo / Getty Images

From companies trying out the digital transformation thing by leaving sensitive data in unprotected cloud storage to ageing and extremely vulnerable computers in schools, universities, local councils and healthcare organisations, there's rich pickings for ransomware raiders everywhere.

Most organisations need IT to function nowadays, but that doesn't mean they know how to manage it well.

Even leaving IT security to the experts can backfire. Last year saw several Managed Service Providers (MSPs) being compromised by ransomware attacks. If you wanted to infect a large number of organisations with ransomware, using a trusted MSP as the attack vector would be the way to do it.

Advertisement
Advertise with NZME.

Nevertheless if you're hit and don't have backups or they're deleted, should you pay the ransom?

If you pay, you're growing an already large criminal enterprise.

Not paying could make things even worse if the hackers publish sensitive data however.

Importantly, there's absolutely no guarantee that the decryptor you pay for will work. It's not like ransomware criminals care about thoroughly testing and ensuring their code is safe to use and bug-free, and that's assuming you receive a decryptor after paying ransom.

If at all possible, don't pay the criminals. The Dutch police and Europol's cybercrime unit working with security vendors have set up The No More Ransom Project site which is a good place for advice and for obtaining tested decryptors for an ever-growing list of ransomware.

Unfortunately, there's no easy answer here. Maybe encouraging Russia to actually disconnect from the global internet (they've done a test run already and it worked) would bring temporary relief but beyond that, more knowledge and understanding of the problem will help.

Think like ransomware criminals breaking into your systems. How might they get in? What would they find in them? Would your organisation survive if the systems and the data they hold were inaccessible, maybe permanently?

Do you need to store sensitive data, especially on internet connected systems? Could it be deleted so that the information doesn't sit on potentially vulnerable servers like a loaded gun, exposing your organisation to mega fines under strict new privacy laws?

There are accredited security firms that can help answer the above questions and other pertinent ones, but if you don't act your organisation could be the next Maersk, Pitney Bowes, Beiersdorf or Travelex. Expect things to get worse.

Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Latest from Business

Premium
Opinion

The Ex-Files: I want to revalue our home before a Family Court hearing and have my child give evidence too

22 Jun 12:00 AM
Business

Dame Theresa Gattung sells premium matchmaking business

21 Jun 11:40 PM
Premium
Media Insider

David Seymour v John Campbell: Act leader turns camera on broadcaster

21 Jun 09:33 PM

Audi offers a sporty spin on city driving with the A3 Sportback and S3 Sportback

sponsored
Advertisement
Advertise with NZME.

Latest from Business

Premium
The Ex-Files: I want to revalue our home before a Family Court hearing and have my child give evidence too

The Ex-Files: I want to revalue our home before a Family Court hearing and have my child give evidence too

22 Jun 12:00 AM

OPINION: The court discourages involving children in disputes, to protect their welfare.

Dame Theresa Gattung sells premium matchmaking business

Dame Theresa Gattung sells premium matchmaking business

21 Jun 11:40 PM
Premium
David Seymour v John Campbell: Act leader turns camera on broadcaster

David Seymour v John Campbell: Act leader turns camera on broadcaster

21 Jun 09:33 PM
Premium
Liam Dann: The upside to this painfully slow economic recovery

Liam Dann: The upside to this painfully slow economic recovery

21 Jun 05:00 PM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP