Skip to main content
The Markets by Proactive
Go to Proactive UK
Proactive UK has moved. Proactive’s coverage of London’s small caps continues on proactiveinvestors.com Go there →
Advertisement
The Markets
by Proactive
Proactive UK has moved.
Coverage of London’s small caps continues on proactiveinvestors.com
Go to Proactive UK
The Markets
by Proactive
Proactive UK has moved.
Small-cap coverage continues on .com
Go to Proactive UK
Advertisement
The Markets
by Proactive
Proactive UK has moved.
Small-cap coverage continues on .com
Go to Proactive UK

Medical technology & services

Finablr plunges despite claims of no “material” impact from Sodinokibi ransomware

Cybercriminals demanded the currency exchange company pay US$6m (£4.6m) to restore the data

Travelex owner Finablr PLC (LON:FIN) said it does not expect a “material” financial impact after the Sodinokibi Windows ransomware attack, though the criminals claim to have swiped customers data.

Cybercriminals demanded the bureau de change chain pay US$6m (£4.6m) to restore the data, they confirmed to the BBC, otherwise threatening to delete the computer systems and sell the customer data on the dark web.

READ: Finablr slips as Travelex subsidiary hit by cyberattack

The attackers have claimed that that customers’ personal data was obtained from the computer system at Travelex, which operates counters in airports and on the high street as well as providing currency exchange services for Virgin Money (LON:VMUK), Tesco (LON:TSCO) and Sainsbury's (LON:SBRY).

“It is just business. We absolutely do not care about you or your details, except getting benefits,” said a readme file for the ransomware, obtained by Computer Weekly.

“If we do not do our work and liabilities – nobody will not co-operate with us. It is not in our interests. If you do not cooperate with our service – for us it does not matter. But you will lose your time and your data, cause just we have the private key. In practice time is much more valuable than money.”

Currency counter claims

But United Arab Emirates-based Finablr said there was “no evidence” that personal customer data has been encrypted and “no evidence that any data has been exfiltrated”, adding that Travelex has successfully contained the spread of the ransomware.

After suffering the cyberattack on New Year's Eve, the currency exchange company was forced to resort to using pen and paper systems at its airport and high streets outlets after the computer systems were closed down, with online customers unable to make transactions.

The FTSE 250 company said in a statement on Wednesday that it was “gradually restoring a number of internal systems” and looking to resume normal operations as soon as it could.

London's Metropolitan Police has confirmed that its cyber crime team is probing “a reported ransomware attack involving a foreign currency exchange”.

Share sale

Overnight it also emerged that major UAE investors were selling US$75mln of Finablr shares in an accelerated bookbuild.

Saeed Mohamed Butti Mohamed Khalfan Al Qebaisi and Khaleefa Butti Omair Yousif Ahmed Al Muhairi, known as Saeed bin Butti and Khalifa bin Butti, also sold US$490mln worth of shares in NMC Health PLC (LON:NMC) as they said they were looking to “reduce outstanding indebtedness of themselves and other corporate entities owned by them”.

Finablr shares were floated last May at 174p and rose to above 210p before Christmas, before dropping more than a quarter since.

On Wednesday the shares fell 17% to 128.2p.

--Adds share price--

Advertisement
The Markets
by Proactive
Proactive UK has moved.
Small-cap coverage continues on .com
Go to Proactive UK