Breach report
RetailCo-op (Co-operative Group)
UK retail giant Co-op confirms hackers stole all 6.5 million customer records
The Co-op's chief executive admitted in July 2025 that hackers who struck in April had stolen personal data on all 6.5 million of the British retailer's members, part of the same social engineering campaign that crippled Marks & Spencer.
Reported by TechCrunch
Records exposed
6.5M
6.5 million members
Scale vs. largest on file
- When
- 2025
- How they got in
- Social engineering of IT help desk (Scattered Spider)
- Sector
- Retail
In late April 2025, the Co-operative Group, one of Britain's largest grocery and funeral care businesses, said it had taken parts of its IT systems offline after detecting attempts to break into its network. Within days, hackers contacted the BBC claiming they had stolen data on millions of Co-op members and employees, and the company acknowledged that a significant amount of member information had been extracted. On July 16, chief executive Shirine Khoury-Haq confirmed that the data of all 6.5 million members had been taken, saying she was deeply sorry.
The stolen information included names, addresses and contact details. The Co-op said the attackers did not obtain passwords, bank or credit card details, or information about members' transactions and purchases. Unlike Marks & Spencer, the Co-op's rapid decision to shut down systems appears to have prevented the attackers from deploying ransomware and encrypting its network, although it caused significant disruption to back-office functions and left some stores with shortages of stock.
The attack was attributed to Scattered Spider, the loose network of young hackers that also targeted Marks & Spencer and Harrods in the same weeks. The group typically gains access by impersonating employees in calls to IT help desks to have passwords and multifactor authentication reset. Hackers affiliated with the DragonForce ransomware operation claimed responsibility in messages to journalists. In July 2025, the National Crime Agency arrested four people aged 17 to 20 in connection with the retail attacks.
The financial cost was considerable. The Co-op later reported that the incident had cut revenue by more than £200 million in the first half of the year and said it expected about £120 million in lost earnings for the full year, noting that it did not have insurance covering the attack. It offered members a shopping voucher as a goodwill gesture.
The Co-op breach reinforced lessons from the broader 2025 campaign against British retailers: the weakest point is often the human processes around identity verification, not technical defenses. It also showed that a fast, disciplined decision to disconnect systems can limit damage even when data theft cannot be prevented. For members, the exposure of contact details increased the risk of targeted phishing, and the company warned customers to be cautious of unsolicited messages.