Cyberattack on British retailer Co-op shaved about $275 million from revenues, company says

The Co-op retail chain took a £206 million (about $274 million) hit to its revenues due to a cyberattack in April that led to empty store shelves and the theft of customer data.

The attack was one of several high-profile incidents in the spring affecting U.K. businesses, including the retail giant Marks & Spencer (M&S). Four people, including one teenage minor, were arrested in July in connection to the hacks on Co-op, M&S and Harrods. The hackers are reportedly believed to have ties to the Scattered Spider group — a loose-knit collection of young cybercriminals. 

In an earnings report filed on Thursday, Co-op said its food business was hit hardest by the incident, “with availability reduced as systems were proactively taken offline.” In-store supplies were noticeably impacted weeks after the incident was detected, with CEO Shirine Khoury-Haq telling customers that staff were “working day and night to protect our systems and get our operations back on track.” 

“Stores continued to trade but were impacted by stock availability, competitor activity to take market share, and the temporary loss of key trading systems and promotional offers,” the company said in its earnings report. 

Co-op was reportedly able to avoid having its systems locked down by ransomware by disconnecting its networks. Nonetheless, all of its 6.5 million members had data stolen in the incident. 

It said total profit loss caused by the cyberattack in the first half of the year was £80 million ($106.7 million). 

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

James Reddick

James Reddick

has worked as a journalist around the world, including in Lebanon and in Cambodia, where he was Deputy Managing Editor of The Phnom Penh Post. He is also a radio and podcast producer for outlets like Snap Judgment.

 

Total
0
Shares
Previous Post

Urgent: Cisco ASA Zero-Day Duo Under Attack; CISA Triggers Emergency Mitigation Directive

Next Post

Cisco ASA Firewall Zero-Day Exploits Deploy RayInitiator and LINE VIPER Malware

Related Posts

New EVALUSION ClickFix Campaign Delivers Amatera Stealer and NetSupport RAT

Cybersecurity researchers have discovered malware campaigns using the now-prevalent ClickFix social engineering tactic to deploy Amatera Stealer and NetSupport RAT. The activity, observed this month, is being tracked by eSentire under the moniker EVALUSION. First spotted in June 2025, Amatera is assessed to be an evolution of ACR (short for "AcridRain") Stealer, which was available under the
Read More

Apple Backports Fix for CVE-2025-43300 Exploited in Sophisticated Spyware Attack

Apple on Monday backported fixes for a recently patched security flaw that has been actively exploited in the wild. The vulnerability in question is CVE-2025-43300 (CVSS score: 8.8), an out-of-bounds write issue in the ImageIO component that could result in memory corruption when processing a malicious image file. "Apple is aware of a report that this issue may have been exploited in an
Read More