Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsThe Co-operative Group restricted parts of its IT network after detecting a cyber attack in April 2025. Stores, quick-commerce operations and funeral homes were trading normally when the restriction was announced on April 30, but back-office, communications and call-centre systems were affected. Co-op later confirmed that attackers had accessed and extracted member data. The company’s March 2026 estimate put the direct 2025 revenue impact at £285 million and the profitability impact at £107 million.
What happened and when
| Date | Confirmed development |
|---|---|
| April 25, 2025 | The date later given by Co-op’s chief executive and the UK National Cyber Security Centre (NCSC) for the start of a multi-stage cyber attack. |
| April 30, 2025 | Co-op disclosed attempts to gain unauthorised access and restricted some back-office and communications systems. It said stores, quick-commerce operations and funeral homes were trading normally. Computer Weekly reported the initial announcement. |
| May 2, 2025 | Co-op confirmed that attackers had accessed and extracted data from one system and that the incident was being investigated with the NCSC and National Crime Agency. Co-op’s incident update described the affected and excluded data categories. |
| October 14, 2025 | The NCSC published a Co-op CEO account describing the event as a multi-stage attack and confirming that some members’ information had been accessed. Read the NCSC account. |
| March 26, 2026 | Co-op estimated the attack had reduced 2025 revenue by £285 million and profitability by £107 million. See the trading update. |
What Co-op actually shut down
Co-op did not announce a shutdown of its entire technology estate or a blanket closure of shops. It restricted systems it considered necessary to isolate, including parts of its back-office, communications and call-centre environment. The company did not publish a complete system list, technical architecture or shutdown timetable.
That distinction matters. Frontline sites can remain open while internal communications, administration, customer support, logistics and other functions operate with reduced access or manual workarounds.
Why disabling systems can be the right security decision
When an organisation suspects that an account or system is compromised, disconnecting or restricting it can be faster and safer than keeping it online while investigators work out what happened.
#1 Best Overall
- It can limit an intruder’s ability to move from one system to another.
- It can reduce the chance of additional data access.
- It can preserve evidence for forensic analysis.
- It gives security teams time to identify affected accounts, credentials and machines.
- It can protect more critical operational systems from being reached.
The trade-off is immediate business disruption: call-centre work, internal coordination, administration and supply-chain activity may slow even when customers can still enter stores.
What data was accessed
Co-op’s later member information says the extracted data included names, residential addresses, email addresses, phone numbers and dates of birth. Co-op said the affected data it identified did not include passwords, bank details, credit-card details, transaction data or information about members’ or customers’ products and services.
| Identified as accessed | Not identified by Co-op as accessed |
|---|---|
| Names | Passwords |
| Residential addresses | Bank details |
| Email addresses | Credit-card details |
| Phone numbers | Transactions |
| Dates of birth | Product or service information |
Co-op described the affected population as a significant number of current and former members, without publishing a precise total on the incident pages cited here. That is different from the number of all Co-op customers or the number of current members.
What members and customers should do
- Use official information. Check Co-op’s cyber-incident FAQs and other official updates rather than links in unexpected messages.
- Expect targeted phishing. Names, addresses, phone numbers and dates of birth can make fraudulent emails, texts and calls sound convincing.
- Do not disclose secrets. Co-op or another legitimate organisation should not require you to reveal a password, one-time code or payment details in response to an unsolicited contact.
- Treat refund and compensation offers cautiously. Criminals may use the incident as a pretext for fake account recovery, refunds or compensation.
- Monitor accounts and messages. The absence of payment-card data from Co-op’s identified categories does not eliminate impersonation risk.
The Information Commissioner’s Office (ICO) also advised people affected by retailer incidents to monitor organisational updates and follow the organisation’s instructions. Its statement is available at ico.org.uk.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
Was this the same attack as the Marks & Spencer incident?
The incidents occurred close together and both involved major UK retailers, but the initial reporting established no link between them. Timing alone is not evidence of a shared criminal group or campaign. Any later claim about common perpetrators should be treated as an attributed external allegation unless supported by a law-enforcement or company finding.
Was it ransomware?
Co-op’s official statements do not establish that ransomware encrypted its systems or that the company paid a ransom. The confirmed description is a multi-stage cyber attack involving unauthorised access and data extraction. Calling it ransomware without a clearly attributed source would go beyond the evidence.
Rank #4
Who investigated the incident?
Co-op said it was investigating with the NCSC and National Crime Agency. The ICO said it had received reports from Co-op and Marks & Spencer and was making enquiries while working with the NCSC.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.The longer-term cost
Co-op’s March 2026 estimate separated the £107 million profitability impact into an estimated £86 million margin effect and £21 million of incremental non-recurring costs. The company said market share had returned to or exceeded pre-attack levels in every business area by 2026. Those figures show why “stores remained open” should not be read as “the incident had little business impact”: disruption to supporting systems and customer behaviour can affect sales and margins for months.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Best Value
What businesses can learn
In the NCSC-published account, Co-op’s response highlighted practical preparation rather than a single technical fix:
- Segment critical systems so a compromise is harder to spread.
- Rehearse incident-response decisions before a crisis.
- Maintain clear communication plans for colleagues, customers and suppliers.
- Be prepared to restrict access quickly when compromise is suspected.
- Plan for prolonged recovery and manual operations, not only restoration of servers.
Bottom line
Co-op’s decision to restrict IT systems was a containment measure, not proof that every system had failed. It helped limit the incident while investigators worked, but attackers had already accessed and extracted member information. The result was a material privacy risk for affected people and a substantial operational and financial cost for the business.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




