Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteCo-op appears to have stopped attackers from encrypting much of its IT environment after it restricted access to parts of its systems. But the attackers’ claim that the retailer “yanked their own plug” is not independent proof of exactly what happened—and avoiding widespread encryption did not prevent a major data breach or substantial disruption.
In July 2025, Co-op’s CEO confirmed that data relating to approximately 6.5 million current and former members had been stolen. The incident shows why stopping ransomware encryption is not the same as stopping an intrusion, preventing data theft, or avoiding business losses.
What happened in the Co-op cyberattack?
Co-op detected suspicious activity in April 2025 and restricted access to additional systems as it responded. The company publicly disclosed the cyberattack on April 30, saying data had been taken from one system. The National Cyber Security Centre (NCSC) issued a statement about incidents affecting UK retailers on May 1.
On May 16, reporting relayed the attackers’ account that Co-op had disconnected systems before they could deploy ransomware encryption. That vivid phrase was the attackers’ characterization of the response, not a forensic finding. Co-op’s reported action was to restrict access to parts of its IT environment; it does not establish that every computer or store was physically unplugged. TechRepublic’s incident coverage describes the containment response and the attackers’ claim.
Recommended Free Tools
#1 Best Overall
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
The later disclosure changed the significance of the initial story: on July 16, Co-op’s CEO confirmed that data relating to approximately 6.5 million members had been stolen. BleepingComputer reported the confirmation.
What does “avoided ransomware” mean?
Ransomware attacks can involve several stages, and encryption is only one of them. Attackers may gain access, compromise identities or privileges, move through a network, look for valuable information, copy data, and then deploy an encryptor to disrupt systems and demand payment. Those events can happen in different combinations and order.
In Co-op’s case, the available reporting supports a careful conclusion: the retailer appears to have interrupted or limited the encryption phase by restricting access to systems. It does not show that the intrusion or data theft was prevented. A business can suffer a ransomware-related intrusion and extortion attempt even if attackers do not broadly encrypt its environment.
Rank #2
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
- Intrusion: attackers obtained access to systems.
- Exfiltration: attackers copied data out.
- Encryption: attackers used ransomware to make systems unavailable.
Co-op appears to have limited the third stage, but the later confirmed data theft shows that containment came after attackers had accessed and copied information.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →What data was stolen, and what did Co-op say was not accessed?
Co-op later confirmed that data relating to approximately 6.5 million current and former members had been stolen. Reported categories included names, addresses and contact information. Early attacker claims referred to data on 20 million people, but that was not the confirmed membership figure and should not be treated as a verified count. BleepingComputer’s earlier account distinguishes the initial claims from the company’s disclosures.
In its reported assessment at the time, Co-op said it did not believe passwords, bank or credit-card details, transactions, or purchase information had been accessed. That is a company assessment about the scope it understood then; it is not proof about every item that may have been in attacker-held material. The distinction matters for members: a breach of contact details can still enable convincing phishing or impersonation even when payment credentials are not believed to be involved.
Rank #3
- World’s First 6TB 2.5” Portable Hard Drive
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
How did the attack affect stores and the business?
Restricting systems can reduce an attacker’s ability to spread, but the same systems support ordinary retail operations. Co-op experienced disruption affecting supply-chain operations and stock availability, card payments, call-center functions, order tracking, and other back-office services. Stores can remain open while the systems that replenish shelves, support online orders, or help customers are impaired.
Co-op later reported an approximately £80 million operating-profit impact in its first-half 2025 results, equivalent to about $107 million at the exchange rate used in the report. This is a company financial-results figure, not a measure of the incident’s total economic cost. BleepingComputer reported the figure.
Who was behind the attack?
DragonForce was the ransomware brand or operation named in reporting and by the attackers. Reporting also linked the activity to Scattered Spider, a label commonly used for loosely connected English-speaking social-engineering actors rather than necessarily one fixed gang. Those names are attribution claims, not by themselves proof of the identities of the people responsible.
Rank #4
- SonicWall Advanced Protection Service Suite for NSA3700 - 3 Year License (02-SSC-6910)
- Capture ATP with RTDMI for Enterprise: Defend against zero-day exploits and ransomware using multi-engine cloud sandboxing and advanced memory inspection.
- Full Threat Protection Stack: Includes Gateway AV, Intrusion Prevention, Anti-Spyware, Application Control, and Content Filtering for layered defense.
- 24x7 Global Support & Firmware Updates: Keep your firewall protected and operational with continuous technical assistance and critical firmware upgrades.
- Application Intelligence & Network Control: Identify and control network activity with deep traffic analytics and reporting features.
UK authorities later announced arrests linked to attacks against M&S, Co-op and Harrods. An arrest or investigative attribution is not the same as a final court determination of responsibility. TechRadar reported the arrests.
How did Co-op’s incident compare with M&S?
Both retailers were affected by cyber incidents in April 2025, but their reported outcomes were not identical. Co-op appears to have limited broad encryption after restricting systems, while confirming extensive member-data theft. M&S reported customer-data theft and endured prolonged disruption to online ordering, contactless payments and other retail functions. Its regulatory announcement said some customer data had been taken. M&S’s May 13, 2025 disclosure provides its account.
| Issue | Co-op | M&S |
|---|---|---|
| Encryption and containment | Appears to have prevented or limited broad encryption by restricting access to parts of its systems. | Ransomware was reportedly deployed, with prolonged operational disruption. |
| Data theft | Confirmed; approximately 6.5 million members’ data was affected. | Confirmed; some customer data was taken. |
| Reported operational effects | Stock and supply-chain disruption, payment problems, call-center and order-tracking issues. | Disruption to online ordering, contactless payments and other retail operations. |
| What the comparison can show | Rapid isolation may limit encryption while leaving data theft and business disruption. | Encryption can prolong disruption when it affects business operations. |
This is not a controlled comparison. The companies’ systems, access paths, timing, dependencies, response decisions and attacker progress differed. Reporting has also pointed to detection investments and network segregation as relevant to Co-op’s response; the outcome cannot be credited to a single “pull the plug” decision or security product. ITPro discusses early detection and network segregation.
Best Value
- Slim durable design to help take your important files with you
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
Why can shutting systems down help—and what can go wrong?
Isolating affected systems can cut off attacker access to identity services, shared files, remote-management tools and business applications. It can prevent an encryptor from reaching additional devices and give responders time to investigate, preserve evidence, reset credentials, isolate accounts and plan recovery.
But an indiscriminate shutdown can create its own operational crisis. In a retailer, inventory, payments, distribution, ordering and customer support depend on connected systems. Abruptly stopping them can mean lost sales, failed payments, delayed replenishment and staff relying on manual processes. Uncoordinated shutdowns can also make evidence harder to preserve, interrupt safety-critical operations, or leave attackers active in overlooked segments. Restoration becomes harder when system dependencies and recovery priorities have not been mapped.
Targeted isolation is usually the more useful objective: disconnect affected endpoints, accounts or network segments while keeping essential services running where it is safe to do so. If responders cannot determine where the attacker is operating, broader isolation may be necessary, but the decision should follow a pre-agreed plan rather than a reflex to turn everything off.
What should organizations learn from the incident?
The NCSC’s statement on the retailer incidents is a useful starting point for response and recovery planning. The practical lesson is to prepare for fast, selective containment and to rehearse how critical services will continue and recover.
Free tools Windows power users keep installed
One-click scans. No signup required.
- Set identity boundaries: separate privileged accounts and administrative access from everyday user accounts, and use phishing-resistant multifactor authentication for high-risk and help-desk accounts.
- Watch for identity abuse: investigate unusual login patterns, impossible travel, unexpected MFA prompts, new-device enrollment and suspicious help-desk activity.
- Limit lateral movement: segment corporate, administrative, payment, customer-facing and supply-chain systems where feasible, so compromise in one area does not automatically expose the rest.
- Protect recovery copies: keep offline, immutable or otherwise isolated backups, and test restoration. Backups reachable through compromised administrator credentials may be exposed too.
- Pre-authorize isolation: define who can disconnect systems, what should be isolated first, which services must remain available and how responders preserve evidence.
- Practice outage operations: rehearse manual store processes and priority restoration for payments, inventory, distribution, customer service and online orders.
- Reduce data exposure: collect only personal information the business needs and set retention limits, so a breach has less data to expose.
- Plan communications: prepare processes for notifying staff, customers, suppliers, regulators and law enforcement, and coordinate technical recovery with legal and operational teams.
What should Co-op members do?
Members should be alert to messages or calls that use personal details to sound legitimate, especially requests to click a link, share a code, reset a password, or provide payment information. Verify unexpected contact through a channel reached independently rather than using the contact details or links in the message.
Co-op’s reported assessment was that passwords and payment details were not believed to have been accessed. If a password used for a Co-op-related account is reused elsewhere, changing it on the other services is prudent; use a unique password and multifactor authentication where available. Do not assume that a contact-information breach means card details were stolen, but do treat unexpected requests for credentials or money with caution.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




