Co-op Group confirmed member data theft after DragonForce intrusion

Organization
Co-op Group
Exploit
Ransomware
Industry
Retail

The Co-op Group disclosed on 30 April 2025 that it had shut down parts of its IT systems as a precaution after detecting attempted unauthorised access. The retailer initially played down the impact, saying the disruption was small and that there was no evidence customer data had been taken.

Within days the company revised that position. Co-op said attackers had accessed and extracted data from one of its systems, and its chief executive confirmed that a limited amount of member data covering names, dates of birth and contact details for current and past members was involved. The retailer said passwords, bank and credit card details and transaction histories were not compromised, and told members no action was required.

The DragonForce ransomware operation claimed responsibility and said it held records on around 20 million people in the Co-op membership scheme, a figure the retailer declined to confirm. The BBC reported reviewing a sample of roughly 10,000 records containing membership card numbers, names, addresses, emails and phone numbers, and said the attackers had sent an extortion message to a Co-op security executive over Microsoft Teams on 25 April.

Researchers described the intrusion as starting with social engineering of an employee whose password was reset to grant network access, followed by theft of the Active Directory credential database. Co-op said it was working with the National Cyber Security Centre and the National Crime Agency. DragonForce also claimed the Marks and Spencer attack and an attempted intrusion at Harrods.

Sources