October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Co-op shut some IT systems to contain 2025 cyber attack: what happened next

Co-op restricted parts of its IT network in April 2025 to contain a cyber attack. Stores initially stayed open, but member data was later confirmed accessed and the company estimated a £285 million revenue impact.
From TheFinanceBase Team4 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Co-operative Group restricted parts of its IT network after detecting a cyber attack in April 2025. Stores, quick-commerce operations and funeral homes were trading normally when the restriction was announced on April 30, but back-office, communications and call-centre systems were affected. Co-op later confirmed that attackers had accessed and extracted member data. The company’s March 2026 estimate put the direct 2025 revenue impact at £285 million and the profitability impact at £107 million.

What happened and when

Date Confirmed development
April 25, 2025 The date later given by Co-op’s chief executive and the UK National Cyber Security Centre (NCSC) for the start of a multi-stage cyber attack.
April 30, 2025 Co-op disclosed attempts to gain unauthorised access and restricted some back-office and communications systems. It said stores, quick-commerce operations and funeral homes were trading normally. Computer Weekly reported the initial announcement.
May 2, 2025 Co-op confirmed that attackers had accessed and extracted data from one system and that the incident was being investigated with the NCSC and National Crime Agency. Co-op’s incident update described the affected and excluded data categories.
October 14, 2025 The NCSC published a Co-op CEO account describing the event as a multi-stage attack and confirming that some members’ information had been accessed. Read the NCSC account.
March 26, 2026 Co-op estimated the attack had reduced 2025 revenue by £285 million and profitability by £107 million. See the trading update.

What Co-op actually shut down

Co-op did not announce a shutdown of its entire technology estate or a blanket closure of shops. It restricted systems it considered necessary to isolate, including parts of its back-office, communications and call-centre environment. The company did not publish a complete system list, technical architecture or shutdown timetable.

That distinction matters. Frontline sites can remain open while internal communications, administration, customer support, logistics and other functions operate with reduced access or manual workarounds.

Why disabling systems can be the right security decision

When an organisation suspects that an account or system is compromised, disconnecting or restricting it can be faster and safer than keeping it online while investigators work out what happened.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • It can limit an intruder’s ability to move from one system to another.
  • It can reduce the chance of additional data access.
  • It can preserve evidence for forensic analysis.
  • It gives security teams time to identify affected accounts, credentials and machines.
  • It can protect more critical operational systems from being reached.

The trade-off is immediate business disruption: call-centre work, internal coordination, administration and supply-chain activity may slow even when customers can still enter stores.

What data was accessed

Co-op’s later member information says the extracted data included names, residential addresses, email addresses, phone numbers and dates of birth. Co-op said the affected data it identified did not include passwords, bank details, credit-card details, transaction data or information about members’ or customers’ products and services.

Identified as accessed Not identified by Co-op as accessed
Names Passwords
Residential addresses Bank details
Email addresses Credit-card details
Phone numbers Transactions
Dates of birth Product or service information

Co-op described the affected population as a significant number of current and former members, without publishing a precise total on the incident pages cited here. That is different from the number of all Co-op customers or the number of current members.

What members and customers should do

  1. Use official information. Check Co-op’s cyber-incident FAQs and other official updates rather than links in unexpected messages.
  2. Expect targeted phishing. Names, addresses, phone numbers and dates of birth can make fraudulent emails, texts and calls sound convincing.
  3. Do not disclose secrets. Co-op or another legitimate organisation should not require you to reveal a password, one-time code or payment details in response to an unsolicited contact.
  4. Treat refund and compensation offers cautiously. Criminals may use the incident as a pretext for fake account recovery, refunds or compensation.
  5. Monitor accounts and messages. The absence of payment-card data from Co-op’s identified categories does not eliminate impersonation risk.

The Information Commissioner’s Office (ICO) also advised people affected by retailer incidents to monitor organisational updates and follow the organisation’s instructions. Its statement is available at ico.org.uk.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Was this the same attack as the Marks & Spencer incident?

The incidents occurred close together and both involved major UK retailers, but the initial reporting established no link between them. Timing alone is not evidence of a shared criminal group or campaign. Any later claim about common perpetrators should be treated as an attributed external allegation unless supported by a law-enforcement or company finding.

Was it ransomware?

Co-op’s official statements do not establish that ransomware encrypted its systems or that the company paid a ransom. The confirmed description is a multi-stage cyber attack involving unauthorised access and data extraction. Calling it ransomware without a clearly attributed source would go beyond the evidence.

Who investigated the incident?

Co-op said it was investigating with the NCSC and National Crime Agency. The ICO said it had received reports from Co-op and Marks & Spencer and was making enquiries while working with the NCSC.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

The longer-term cost

Co-op’s March 2026 estimate separated the £107 million profitability impact into an estimated £86 million margin effect and £21 million of incremental non-recurring costs. The company said market share had returned to or exceeded pre-attack levels in every business area by 2026. Those figures show why “stores remained open” should not be read as “the incident had little business impact”: disruption to supporting systems and customer behaviour can affect sales and margins for months.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What businesses can learn

In the NCSC-published account, Co-op’s response highlighted practical preparation rather than a single technical fix:

  • Segment critical systems so a compromise is harder to spread.
  • Rehearse incident-response decisions before a crisis.
  • Maintain clear communication plans for colleagues, customers and suppliers.
  • Be prepared to restrict access quickly when compromise is suspected.
  • Plan for prolonged recovery and manual operations, not only restoration of servers.

Bottom line

Co-op’s decision to restrict IT systems was a containment measure, not proof that every system had failed. It helped limit the incident while investigators worked, but attackers had already accessed and extracted member information. The result was a material privacy risk for affected people and a substantial operational and financial cost for the business.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.