The Co-operative Group, a major British retailer, suffered a significant cyberattack in April that severely disrupted its operations and led to substantial financial losses. The attack forced the company to shut down parts of its IT systems, resulting in empty shelves and supply chain disruptions across its food retail business. Co-op reported a £206 million loss in revenue, with an £80 million hit to profits in the first half of 2025, marking a sharp reversal from the previous year's profit. The incident also triggered a one-off payment of £20 million, the purpose of which has not been publicly explained. Despite the company's efforts to contain the attack by proactively taking systems offline, the attackers managed to steal the personal details of all 6.5 million Co-op members, including names and contact information, though payment card and transaction data were reportedly not compromised. The breach led to weeks of operational chaos, with back-office functions seizing up and the company having to offer significant discounts to lure customers back. The Information Commissioner's Office is expected to investigate the exposure of such a large volume of personal data. Four individuals, including a minor, were arrested in July in connection with the hacks on Co-op and other UK retailers, with the attackers believed to have ties to the Scattered Spider cybercriminal group. Co-op's CEO, Shirine Khoury-Haq, stated that staff worked around the clock to restore operations and protect systems, and credited the company's structure for its resilience. The company managed to avoid a full-scale ransomware lockdown by disconnecting its networks, but the disruption still allowed competitors to take market share. The attack was part of a broader wave of cyber incidents affecting major UK retailers in the spring, including Marks & Spencer and Harrods. The financial impact of the attack was so severe that Co-op reported an underlying operating loss of £32 million, compared to a £47 million profit the previous year. The company has not confirmed whether a ransom was paid, and has not responded to media requests for further comment. The breach has raised concerns about the security of member data and the robustness of Co-op's cyber defenses. The incident underscores the growing threat of cyberattacks to critical retail infrastructure and the potential for widespread operational and financial damage.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Co-op reported that the April cyberattack shaved about £206 million from revenue and caused an £80 million hit to profit, contributing to an underlying operating loss in the first half of 2025. The company said the attack's operational and financial effects were significant.
The UK Cyber Monitoring Centre categorized the Co-op and M&S cyber incidents as a Category 2 systemic event. It estimated combined losses from the attacks at £270 million to £440 million.
In July 2025, the UK National Crime Agency arrested four young suspects in connection with cyberattacks targeting Co-op, Marks & Spencer, and Harrods. Reporting linked the suspects to activity associated with Scattered Spider.
Co-op later confirmed that current and former member data had been accessed in the incident, affecting 6.5 million members. The exposed data included names, contact details, and dates of birth, but not passwords, payment card or bank details, or transaction data.
The cybercrime group calling itself DragonForce told the BBC it was responsible for the Co-op attack and said it had stolen member data. The group provided screenshots and other proof to support its claim.
After the attack became public, Co-op first stated it had no evidence that customer data had been compromised. This position was later revised as the investigation progressed.
In April 2025, Co-op suffered a major cyberattack that disrupted back-office systems and supply chains, causing empty shelves and stock shortages for weeks. The company said it disconnected networks to prevent a full ransomware lockdown.
An extortion message tied to the Co-op intrusion was sent through Microsoft Teams, with screenshots later cited by the threat group as proof of access. This indicates the attack was active by that date.
8 references tracked. Mallory keeps watching after this page renders.
theguardian.com
Open sourceinfosecurity-magazine.com
Open sourcesecurityaffairs.com
Open sourcego.theregister.com
Open sourcetherecord.media
Open sourcetechcrunch.com
Open sourcetheregister.com
Open sourcebbc.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.