On 30 April 2025, the Co-operative Group (Co-op), one of the UK's largest consumer co-operatives, said it had taken "proactive measures" against a cyber attack and shut down parts of its IT systems. Within days it confirmed that attackers had taken member data, and in July its chief executive, Shirine Khoury-Haq, confirmed that the personal data of all 6.5 million members had been stolen: names, dates of birth, email addresses, phone numbers and home addresses. Co-op said no financial information or passwords were taken. The attack ran in parallel with the attack on Marks & Spencer and an attempted attack on Harrods, and has been linked to the Scattered Spider collective and the DragonForce ransomware operation. According to Help Net Security's summary of reporting, the attackers social-engineered their way into an employee's account by having its password reset, then went after the Active Directory database. Co-op said it evicted the attackers before ransomware could be deployed. In July 2025, the National Crime Agency arrested four people in connection with the attacks.
Key takeaways
- Co-op confirmed that the personal data of all 6.5 million members was stolen; financial data and passwords were not affected, it said.
- Attackers reportedly posed as staff to get an employee's password reset, then targeted the Active Directory ntds.dit file holding credential hashes.
- The attack is linked to Scattered Spider tactics and DragonForce ransomware; Co-op said attackers were evicted before ransomware was deployed.
- The UK National Crime Agency arrested four people in July 2025 in connection with the M&S, Co-op and Harrods attacks.
- The identity lesson: help desk password resets and account recovery are identity controls, and they need verification as strong as the login they replace.
At a glance
| Organisation | The Co-operative Group (Co-op) |
|---|---|
| When | Attack disclosed 30 April 2025; member data theft confirmed in May 2025; full scope (6.5 million members) confirmed July 2025 |
| Attacker | Linked to the Scattered Spider collective and the DragonForce ransomware operation |
| Entry point | Social engineering: impersonating an employee to have their account password reset, according to Help Net Security's summary of reporting |
| Identities abused | A compromised employee account; the attackers then targeted Active Directory credential data |
| Impact | Names, dates of birth and contact details of 6.5 million members stolen; systems shut down; extortion attempted |
| Category | Human identity (not listed as an NHI or AI agent breach). Incident class: human-identity breach (help desk social engineering) |
What happened
Co-op first disclosed "unauthorized access attempts" on 30 April 2025, as CyberInsider put it, and pulled some of its IT systems offline. Computer Weekly reported that on 1 May Co-op told staff to stop using their VPNs and be wary that their communications might be monitored. The BBC then reported that the attackers had been inside the network for days before the disclosure and were threatening to release stolen data. On 6 May, Khoury-Haq confirmed in a message to members that attackers "were able to access a limited amount of member data, which included name, date of birth and contact details, but they have not been able to access any members' financial information." She added: "Passwords have not been compromised and we are not asking members to do anything differently."
Help Net Security summarised the reported method: the group "social-engineered an employee, took over their account by resetting the password, used the account to access Co-op's network, then went after the Active Directory (Windows) ntds.dit database file, which holds encrypted credentials for employee accounts." Security researcher Kevin Beaumont, a former Co-op employee, said the attackers used tactics popularised by Scattered Spider, such as "posing as company IT and helpdesk staff to trick actual employees into divulging account credentials," and warned that "if your internal employees could go rogue and cause significant damage before detection, you have a serious problem if an external e-crime group 'becomes' an employee."
In July 2025, Khoury-Haq told BBC Breakfast that all 6.5 million members' data had been taken. "I am incredibly sorry," she said, as reported by Computer Weekly, which added that she expressed relief that Scattered Spider had been evicted before they could deploy ransomware. CyberInsider reported that on 10 July the National Crime Agency arrested four people, aged 17 to 20, in connection with the attacks on M&S, Co-op and Harrods; they were released on bail.
Timeline
| Date | Event |
|---|---|
| 22 April 2025 | Marks & Spencer confirms a cyber attack, part of the same wave. |
| 30 April 2025 | Co-op discloses the attack and shuts down some IT systems. |
| 1 May 2025 | Co-op tells staff to stop using VPNs, Computer Weekly reports. |
| 6 May 2025 | Co-op's CEO confirms member data was taken. |
| 10 July 2025 | The National Crime Agency arrests four people. |
| 16 July 2025 | Co-op's CEO confirms all 6.5 million members' data was stolen. |
How it happened: the identity attack path
- Help desk impersonation. Attackers posed as an employee to have their password reset, according to reporting.
- Account takeover. They used the employee's account to access Co-op's network.
- Credential harvesting. They targeted the Active Directory ntds.dit file, which holds credential hashes for accounts.
- Data theft. Member data was exfiltrated from membership systems.
- Extortion and eviction. The attackers attempted extortion; Co-op evicted them before ransomware was deployed.
Impact
- Members: names, dates of birth, email addresses, phone numbers and home addresses of 6.5 million members stolen.
- Not affected: passwords, payment card details and transaction history, according to Co-op.
- Operations: IT systems shut down to contain the attack, disrupting back-office and customer support operations, CyberInsider reported; Computer Weekly reported store shelves emptying.
What this means for NHI governance
This is a human-identity breach, flagged as such on our breach hub. The entry point was a person's account, reached by persuading a help desk to reset it. We include it because of what came next: the ntds.dit file the attackers went after holds the credential hashes of every account in the domain, including service accounts, machine accounts and the krbtgt account. Once that file is taken, recovery must cover non-human accounts too, which are often the hardest to rotate.
The central lesson is about account recovery. A password reset is an authentication event, and if a caller can pass it with information an attacker can find or guess, it is the weakest login in the organisation. See our Account Recovery and Help Desk Security Guide and Active Directory and Entra ID Hardening Guide.
Recommendations
- Strengthen help desk identity verification. Require verification that cannot be social-engineered, such as in-person or video checks with ID or manager approval, before resets. See the Account Recovery and Help Desk Security Guide.
- Use phishing-resistant MFA. Passkeys and hardware keys resist the tricks Scattered Spider relies on. See the Passwordless and Passkeys Guide.
- Protect and monitor Active Directory. Alert on access to ntds.dit and domain controller backups. See the Active Directory and Entra ID Hardening Guide.
- Rotate service accounts after a domain compromise. Include krbtgt and all non-human accounts in recovery. See the Service Account Security Guide.
- Detect accounts behaving out of pattern. Beaumont's warning about attackers "becoming" employees calls for behaviour-based detection. See the ITDR Guide.
Frequently asked questions
How many Co-op members were affected?
Co-op's chief executive confirmed in July 2025 that the personal data of all 6.5 million members was stolen, including names, dates of birth and contact details.
How did hackers get into Co-op?
According to reporting summarised by Help Net Security, attackers social-engineered the reset of an employee's account password, used it to access the network and targeted Active Directory credential data.
Who was behind the Co-op attack?
The attack has been linked to the Scattered Spider collective and DragonForce ransomware. The National Crime Agency arrested four people in July 2025 in connection with the attacks on M&S, Co-op and Harrods.
Related NHI Mgmt Group resources
Marks and Spencer Cyber Attack 2025 · Cisco Active Directory Credentials Leak · Account Recovery and Help Desk Security Guide · Active Directory and Entra ID Hardening Guide · Service Account Security Guide
How NHI Mgmt Group can help
Help desk resets and directory recovery are where human and non-human identity risk meet. We help teams harden account recovery and plan directory recovery that covers every service account. See our NHI and AI agent security training.
References
- Help Net Security: UK retailers under cyber attack: Co-op member data compromised (5 May 2025)
- CyberInsider: Co-op Confirms Member Data Breach Following Cyberattack Incident (6 May 2025)
- Computer Weekly: Co-op chief 'incredibly sorry' for theft of 6.5m members' data (16 July 2025)
- CyberInsider: Co-op Confirms Cyberattack Exposed Data of All 6.5 Million Members (17 July 2025)