Co-op Cyber Incident 2025: Third-Party Access and the Decision to Disconnect
The third UK retailer hit in a two-week wave detected its intruders in hours, cut its own network before the ransomware could fire, and never paid a penny. It still lost the data of all 6.5 million members and £206 million in sales. This is what the good outcome costs.
Case type: Social engineering / attempted ransomware / data theft
Identified: Apr 22, 2025 Disclosed: Apr 30, 2025
Attribution: Scattered Spider affiliates / DragonForce RaaS
Every breach in this series so far is a story about failure: warnings missed, calls believed, doors left open for years. This one is different. Co-op's defenses, at the moment of truth, largely worked. The alarms fired in hours. The containment decision came fast. The ransomware never went off. And it still cost a quarter of a billion pounds in lost sales and the personal data of every single member.
In April 2025, a wave of attacks hit UK retail in quick succession: Marks & Spencer over Easter, then Co-op, then an attempt on Harrods, all linked to the Scattered Spider ecosystem, the same English-speaking social-engineering collective behind the MGM and Caesars attacks covered earlier in this series, this time operating as affiliates of the DragonForce ransomware-as-a-service platform. Co-op's chapter of that wave is the closest thing modern extortion produces to a success story, which is exactly why it's worth reading closely. It shows what detection investment actually buys, and what it can never buy back.
Attackers gained access to Co-op's environment on April 22, 2025, days after the M&S attack surfaced. The entry matched the wave's signature: identity-driven social engineering, with reporting pointing to compromised credentials, the ecosystem's standard playbook of impersonation-driven access rather than any technical exploit. Once inside, they went straight for the asset that mattered: the membership database, and began copying it. They also prepared the second act, staging the DragonForce encryptor for deployment across Co-op's systems.
The second act never came. Co-op's monitoring flagged the unusual activity, reportedly within hours, and the company made the MGM decision at Co-op speed: it disconnected parts of its own network, cutting remote access and taking systems offline on its own terms before the ransomware could fire. The self-amputation worked twice over. It kept every system unencrypted, and it severed the attackers before they could cover their tracks, preserving forensic evidence that would matter later. The attackers, denied their encryption leverage, fell back to pure extortion: they contacted the BBC directly, sharing samples of stolen data and claiming twenty million records. Co-op engaged with no demand and paid nothing
What followed was the operational bill. With stock management and logistics systems offline or degraded, Co-op's roughly 2,400 food stores ran on manual ordering for weeks. Shelves gapped, worst in the remote and island communities where Co-op is often the only grocer. Back-office and call-center functions were disrupted, and some payment services worked intermittently. Recovery came in stages through May. On July 16, chief executive Shirine Khoury-Haq confirmed the full scope on national television: the data of all 6.5 million members, names, dates of birth, contact details, though no passwords, card, or transaction data, had been taken, and she apologized to every one of them. September's interim results priced it: roughly £206 million in lost revenue and an £80 million hit to operating profit.
The best outcome available still cost $270 million
Set Co-op beside the rest of this series and its performance is remarkable. Caesars didn't notice its intruders for twenty days; Co-op noticed in hours. MGM's containment shutdown came after escalation to its core infrastructure; Co-op's came before the encryptor fired. 23andMe dismissed an accurate warning as a hoax; Co-op believed its alarms and acted on them. By every operational measure this series tracks, Co-op is the best-performing victim yet, and it still lost its entire membership database and a quarter of a billion pounds in sales.
Speed didn't save the data. It saved everything else.
That's the honest shape of modern extortion defense. Exfiltration happens at machine speed, in the first hours, before even excellent detection can respond. What detection and decisive containment actually buy is everything downstream: no encryption, no rebuild, no ransom negotiation, preserved evidence, and an incident you manage rather than one that manages you. Co-op got all of that. The membership data was simply gone before the contest began, which is why data-layer defenses, minimization, segmentation, and exfiltration-rate alerting, are the only controls that operate on the attacker's timeline.
M&S got the fire. Co-op got the smoke.
The same affiliate ecosystem hit Marks & Spencer days earlier, and there the encryptor deployed: hundreds of systems, a 46-day online sales outage, and a profit impact the company put at roughly $390 million. Co-op, attacked by the same crews with the same toolkit in the same fortnight, kept every system unencrypted and restored operations in weeks. The difference wasn't the attackers, the malware, or luck. It was the interval between intrusion and response, and the pre-existing willingness to accept self-inflicted disruption as a containment price. That's the whole argument for detection and response investment, run as a natural experiment across two of Britain's most recognizable retailers in the same news cycle.
Not one decision. A set of conditions.
Co-op's outcome, better than its neighbors' and still painful, was set by four conditions, two it controlled and two it didn't:
Seventeen to twenty years old
The four suspects arrested in July were aged seventeen to twenty, and one was reportedly connected to the MGM attack this series covered, an incident that happened when they would have been barely out of school. The Scattered Spider ecosystem's defining trait has never been technical sophistication; it is fluent, native-English social manipulation, executed by very young people recruited through gaming and online communities. Co-op's response reached for that root: alongside its recovery, it announced a partnership aimed at steering young technical talent away from cybercrime. Whatever that program achieves, the instinct is right, and it is the same instinct this series is built on. The attacks are a human system. So is the defense, and so, it turns out, is the supply of attackers.
"Detection Is a Spending Decision."
The Co-op incident is the proof case this series has been building toward: resilience investments pay, measurably. Hours of dwell instead of weeks, an encryptor that never fired, evidence intact enough to serve arrests, a leader who fronted the failure personally, and not a penny paid. And the same incident is the proof of the limit: all 6.5 million members' data gone in the opening hours, $270 million in sales lost to the recovery, and communities staring at gapped shelves for weeks. Both halves are true, and leadership should hold them together.
The organizations that fare best against this ecosystem aren't the ones with perfect perimeters. They're the ones that assume the perimeter fails, fund the alarms, pre-authorize the self-amputation, rehearse the manual weeks, and defend the data layer on the only timeline that matters: the attacker's first hours.
BECAUSE THE RETURN ON DETECTION IS MEASURED IN THE RANSOMS YOU NEVER NEGOTIATE AND THE DAYS YOU NEVER LOSE.
Sources
CyberInsider, "Co-op Confirms Cyberattack Exposed Data of All 6.5 Million Members," July 2025: https://cyberinsider.com/co-op-confirms-cyberattack-exposed-data-of-all-6-5-million-members/
Computer Weekly, "Chaos spreads at Co-op and M&S following DragonForce attacks," May 2025: https://www.computerweekly.com/news/366623685/Chaos-spreads-at-Co-op-MS-following-DragonForce-attacks
CPO Magazine, "The Co-op Confirms Significant Data Theft from an Apparent Dragonforce Ransomware Cyber Attack," May 2025: https://www.cpomagazine.com/cyber-security/the-co-op-confirms-significant-data-theft-from-an-apparent-dragonforce-ransomware-cyber-attack/


Comments