Economyuk Daily Report English (UK)
economyuk.co.uk Economyuk Daily Report
Blog Business Local Politics Tech World

Co-op Cyber Attack – 2025 Timeline, £206m Cost and Updates

Henry Bennett Thompson • 2026-04-28 • Reviewed by Oliver Bennett

The Co-operative Group, one of the UK’s largest retailers, faced a significant cyber attack in late April 2025 that disrupted operations across its stores and compromised personal data belonging to millions of members. The incident, attributed to the DragonForce ransomware group and its affiliates, sent shockwaves through the retail sector and prompted widespread media coverage as the full scope of the breach emerged.

The attack forced the company to shut down critical IT systems, including stock management, resulting in empty shelves across hundreds of stores for approximately three weeks. Meanwhile, cybercriminals claimed responsibility and began releasing samples of stolen member data to pressure the retailer. This article provides a comprehensive breakdown of what happened, the timeline of events, the financial impact, and what steps affected customers can take.

What Happened in the Co-op Cyber Attack?

The Co-operative Group detected a major cyber intrusion into its IT infrastructure beginning in late April 2025. Attackers associated with the DragonForce ransomware-as-a-service operation, along with affiliates known as Scattered Spider and The Com, gained access to the retailer’s systems and began extracting sensitive data before the company publicly acknowledged the breach.

Attack Type
Ransomware and data exfiltration
Date of Initial Breach
Late April 2025
Estimated Financial Impact
£206 million in lost sales
Current Status
Investigations ongoing; arrests made

Key Findings

  • The breach affected approximately 20 million current and past Co-op members whose personal information was accessed and stolen
  • Stolen data included names, dates of birth, and contact details; no passwords, financial information, or shopping habits were compromised according to Co-op
  • The company proactively shut down IT systems including stock management to contain the attack and prevent further damage
  • Attackers directly contacted media outlets including the BBC, sharing samples of stolen data to pressure the retailer into compliance
  • Co-op declined to confirm whether any ransom was paid, maintaining that forensic investigations remain active
  • The attack formed part of a broader wave targeting UK retailers including Marks & Spencer and Harrods

Snapshot of Key Facts

Metric Details
Lost Revenue £206 million (confirmed by Co-op)
Affected Members Approximately 20 million
Primary Targets Co-op IT networks and member databases
Law Enforcement National Crime Agency (NCA) involvement
Arrests Made Four individuals by NCA
Related Incidents M&S, Harrods, Dior, Arla also targeted
Attack Attribution DragonForce RaaS, Scattered Spider, The Com
What the data breach included

Co-op confirmed that compromised member records contained names, dates of birth, and contact information. The retailer stated that no passwords, bank details, transaction history, or personal shopping data was accessed during the breach.

Co-op Cyber Attack Timeline

The cyber attack unfolded over several weeks, with the full picture emerging gradually through media reports and official statements. Here is a chronological account of the key events as they became public.

Initial Intrusion and Discovery

BleepingComputer reported that the initial hack occurred on 22 April 2025, involving data exfiltration before any ransomware deployment. However, this specific date remains unconfirmed by other outlets covering the incident. During the Easter weekend of 26-27 April, attackers attempted to gain deeper access to Co-op systems. The DragonForce ransomware group publicly claimed responsibility during this period.

Public Disclosure and Immediate Response

On 30 April 2025, Co-op publicly disclosed the cyber incident. The company made the decision to shut down key IT systems, including stock management functionality, to contain the breach. This action caused immediate disruption across UK stores, with empty shelves becoming a common sight as supply chain logistics faltered. ITV News first reported the story after obtaining a leaked internal email from Digital Officer Rob Elsey.

The following day, 1 May, Co-op instructed staff to avoid using virtual private networks amid concerns that communications might be monitored by the attackers. On 2 May, the retailer confirmed that hackers had accessed and extracted data affecting approximately 20 million current and former members. The stolen information included names, dates of birth, and contact details. Attackers subsequently contacted the BBC directly, providing proof of the breach to pressure the company.

Recovery and Ongoing Operations

CEO Shirine Khoury-Haq began emailing customers in early May, describing the attackers as “highly sophisticated.” Gradual restocking efforts commenced, with shelves slowly returning to normal over several weeks. Co-op issued three further customer update emails on 6 May, 15 May, and 30 May detailing recovery progress. An official press release on 14 May outlined the company’s system precautions and recovery strategy, emphasizing safety over speed in bringing systems back online.

Timeline uncertainty

The exact date of initial intrusion remains disputed among sources. While one outlet cited 22 April as the hack date, no other publications confirmed this specific timeline. Recovery efforts continued into late May and beyond, though no further public updates were available as of May 2025.

Cost and Financial Impact of the Co-op Cyber Attack

The cyber attack exacted a substantial financial toll on the Co-operative Group, though several figures remain estimates or have not been publicly disclosed. The confirmed impact includes lost revenue, operational disruption, and ongoing investigation costs.

Confirmed Financial Losses

Co-op publicly confirmed losses of £206 million in sales directly attributable to the cyber attack. This figure represents revenue that could not be captured during the period of system disruption and reduced operational capacity. The company declined to specify whether insurance coverage would offset any portion of these losses, and no details regarding ransom demands or payments were disclosed.

Operational Costs

Beyond direct revenue loss, the retailer faced significant costs associated with emergency IT response, system restoration, forensic investigations, and accelerated security improvements. Supply chain disruption required intensive coordination with distributors and suppliers to resume normal stock levels. The three-week period of empty shelves and reduced service capabilities also impacted customer confidence and loyalty during a critical trading period.

Undisclosed Figures

Several financial details remain confidential. Co-op has not publicly revealed the amount of any ransom demand, whether any payment was made, the extent of cyber insurance coverage, or specific compensation provisions for affected members. The company has maintained a policy of non-disclosure regarding similar past incidents, including a 2021 ransomware attack on an American agricultural cooperative where the demanded figure was reported at $5.9 million but declined.

Compensation and insurance

Co-op has not announced any formal compensation scheme for affected members whose data was compromised. Customers concerned about potential misuse of their personal information should monitor financial statements, consider credit freezes, and review guidance from the Information Commissioner’s Office.

Latest Updates on the Co-op Cyber Attack

As of the latest available reports from May 2025, the Co-operative Group continues to navigate the aftermath of the cyber attack. Law enforcement agencies have become involved, and the retailer has implemented enhanced security measures while communicating regularly with affected members.

Law Enforcement Response

The National Crime Agency confirmed involvement in investigating the attack alongside international partners. Reports indicate that four individuals were arrested in connection with attacks on M&S, Co-op, and Harrods. The NCA issued a public statement detailing the arrests, though specific details about the suspects or the evidence gathered remain limited due to ongoing proceedings.

Co-op’s Recovery Efforts

The retailer has prioritized controlled system restoration over rapid recovery, a strategy emphasized in official communications. Customer-facing updates were distributed via email on multiple dates throughout May, providing reassurance and guidance. The company’s dedicated cyber incident webpage contains current information for members seeking guidance on the breach and protective measures they can take.

Ongoing Investigations

Forensic investigations remain active according to Co-op’s public statements. The company continues working with cybersecurity experts and law enforcement to determine the full scope of the breach and identify additional protective measures needed. No timeline has been provided for when these investigations might conclude.

Staying informed

Customers seeking the most current information should regularly check the official Co-op cyber incident FAQs and monitor communications from the retailer directly.

What Should You Do After the Co-op Cyber Attack?

If you are a Co-op member or customer who may have been affected by the data breach, several steps can help protect your personal information and mitigate potential risks from the exposure of your details.

Immediate Actions

  • Monitor your financial accounts and credit reports for any unusual activity or unauthorized transactions
  • Be vigilant for phishing emails or suspicious communications claiming to be from Co-op, especially those requesting additional personal information
  • Consider placing a fraud alert or credit freeze with major credit reference agencies
  • Update passwords for any accounts that use similar credentials to those you may have shared with Co-op
  • Review your Co-op membership account for any unfamiliar changes or activity

Protective Measures

While Co-op has confirmed that no financial information or passwords were compromised, the exposed personal details (names, dates of birth, contact information) could still be valuable to fraudsters for identity theft or social engineering attacks. Members should verify the authenticity of any communication claiming to originate from Co-op by contacting the retailer through official channels rather than clicking links in unexpected emails. Those interested in understanding common fraud tactics may find our guide on identifying suspicious calls and messages useful for protecting against social engineering attempts.

Seeking Further Guidance

The Information Commissioner’s Office (ICO) oversees data protection compliance in the UK and may issue guidance following investigations into the breach. Customers with concerns about how their data has been handled can contact the ICO directly. For specific questions about individual circumstances, consulting with a legal professional specializing in data protection may be advisable. For those interested in financial planning, you can learn more about the maximum contribution ei 2025.

What Is Clear and What Remains Uncertain?

Understanding the distinction between confirmed facts and unresolved questions helps frame expectations about the Co-op cyber attack and its consequences.

Established Information Unresolved Questions
Attack occurred in April-May 2025 Exact date of initial intrusion
DragonForce and affiliates responsible Whether any ransom was paid
20 million members’ data accessed Details of insurance coverage
£206 million in lost sales confirmed Compensation plans for members
No passwords or financial data stolen Full timeline for complete system recovery
Four arrests made by NCA Identity of arrested individuals

Broader Context: Retail Sector Under Siege

The Co-op cyber attack did not occur in isolation. It formed part of a coordinated campaign targeting prominent UK retailers and luxury brands during the same period. Marks & Spencer experienced significant disruption to its click-and-collect service and customer data, while Harrods also reported falling victim to similar attacks. French luxury house Dior and dairy co-operative Arla were among other entities affected by the same threat actors.

Security analysts noted that the DragonForce ransomware-as-a-service model allows multiple distinct hacking groups to deploy the same malware toolkit, complicating attribution but suggesting a shared infrastructure behind the attacks. The involvement of English-speaking affiliate groups like Scattered Spider indicated a sophisticated understanding of UK business operations and social engineering techniques.

The wave of attacks highlighted systemic vulnerabilities in the retail sector, where complex supply chains, legacy IT systems, and high volumes of customer data create attractive targets for financially motivated cybercriminals. Security experts have urged retailers to invest in threat detection capabilities, employee training, and incident response planning as essential defensive measures.

Official Sources and Key Statements

Multiple authoritative sources have provided information about the cyber attack, ranging from official company statements to law enforcement communications and investigative journalism.

“We can confirm that we have been subject to a sophisticated cyber attack. We took immediate action to isolate the affected systems and are working with leading cybersecurity experts to investigate this incident and restore normal operations safely.”

— Co-operative Group official statement, May 2025

“This incident demonstrates the ongoing threat from ransomware groups targeting major retailers. We continue to work closely with affected organizations and international partners to pursue those responsible.”

— National Crime Agency statement regarding retail cyber attacks

Additional coverage from outlets including BBC News, ITV News, Computer Weekly, and The Independent has contributed to public understanding of the incident. The attackers themselves communicated directly with journalists, sharing data samples to demonstrate the scope of their access and apply pressure for ransom negotiations.

Summary and Key Takeaways

The Co-operative Group cyber attack represents one of the most significant retail data breaches in recent UK history. Affecting approximately 20 million members and causing confirmed losses of £206 million, the incident exposed both the scale of modern cyber threats and the operational vulnerabilities facing large retailers.

While the attack has been attributed to the DragonForce ransomware group and its affiliates, with four arrests made by UK law enforcement, many questions remain unanswered. The company continues its recovery efforts, emphasizing careful system restoration over speed. Affected customers should remain vigilant against potential fraud while monitoring official communications for further updates.

For those seeking to understand more about network security and technical infrastructure, our guide on securing home networks and router configuration offers foundational information that complements broader cybersecurity awareness.

Frequently Asked Questions

Was Co-op’s ransom demand disclosed publicly?

Co-op has not disclosed any details regarding ransom demands, payments, or negotiations. The company has maintained confidentiality on this matter consistent with its approach in previous security incidents.

How did attackers gain access to Co-op systems?

Attackers exploited unpatched vulnerabilities or system misconfigurations according to cybersecurity analysts. The involvement of English-speaking affiliate groups suggests sophisticated social engineering capabilities were also deployed.

Was the Co-op data breach connected to attacks on M&S and Harrods?

Security researchers and law enforcement agencies have indicated that the same DragonForce affiliates were involved in attacks on multiple UK retailers including M&S and Harrods, though each company has handled its investigation independently.

What should I do if I receive a suspicious email claiming to be from Co-op?

Do not click any links or download attachments. Verify the communication by contacting Co-op directly through their official website or customer service channels. Report suspicious emails to your email provider and the National Cyber Security Centre.

Has Co-op offered compensation to affected members?

As of May 2025, Co-op had not announced any formal compensation scheme for members affected by the data breach. The company encouraged concerned members to review its official guidance and monitor communications for updates.

When did the Co-op share updates about the cyber attack?

Co-op issued customer update emails on 6 May, 15 May, and 30 May 2025, with an official press release on 14 May. A dedicated cyber incident page on the Co-op website continues to provide current information.

What personal data was stolen in the Co-op breach?

Co-op confirmed that stolen data included names, dates of birth, and contact information for approximately 20 million current and former members. The company stated that no passwords, bank details, or shopping history were compromised.

How long did the operational disruption last?

Stock shortages and empty shelves persisted for approximately three weeks following the attack. Gradual restocking began in early May, with shelves returning to normal conditions over subsequent weeks as systems were carefully restored.


Henry Bennett Thompson

About the author

Henry Bennett Thompson

Coverage is updated through the day with transparent source checks.