The British retail group, The Co-operative Group (Co-op), announced that it was forced to disable some of its information systems due to an attempted cyberattack.

According to the company's spokesperson, hackers attempted to gain access to specific systems. In response, the company took preventive actions to ensure their protection. However, call center and back office operations have been affected, experiencing delays and malfunctions.
So far, it has not been clarified whether the attacks achieved their goal.
See also: France: Blames Russian hackers APT28 for attacks on the country
The Co-op, which is one of Britain's largest food retailers with more than 5 million members, said its physical stores were operating as normaland that no action was required from customers at this time.
When asked by TechCrunch, the Co-op declined to provide details about the nature of the incident or whether a report had been made to the UK Data Protection Authority (which is required in the event of a potential data breach). However, the company confirmed that it is working with the National Cyber Security Centre (NCSC) to assess and manage the situation.
Additionally, the Co‑op representative did not clarify whether there has been any direct communication with the perpetrators of the attack (as ransomware groups do when they attack and demand ransom).
See also: Apple's 'AirBorne' flaws lead to zero-click AirPlay attacks
The Co-op incident comes at a time of heightened concern about cybersecurity, with Marks & Spencer also suffering a cyberattackthat prevented customers from receiving their online orders. Marks & Spencer said it had notified regulators. The fallout from the attack is now in its second week.
Protection against cyber attacks
Businesses, regardless of size or sector, must take comprehensive protection measures against cyber attacks. Below are basic and effective measures they can adopt:
1. Staff training
Human error remains one of the most common reasons for breaches. Regular employee training on security issues (e.g., phishing email recognition, secure password use) is critical.
2. Use of strong and up-to-date security systems
- Installation and regular updating antivirus and anti-malware software.
- Use of firewalls and intrusion detection systems.
- Ensuring that all operating systems and applications are up to date with the latest patches.
3. Access and control policies
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
- Limiting access to critical data to authorized individuals only.
- Use authentication multi-factor (MFA).
- Removal of user accounts that are no longer used.
4. Secure storage and encryption of data
Data must be stored in secure locations and encrypted, both at rest and in transit.
See also: Hitachi Vantara: Problems due to Akira ransomware attack

5. Frequent and automated backups
Regular backups , ideally in offline or cloud environments, ensure data recovery in the event of a ransomware attack or other loss.
6. Attack simulations (penetration testing)
Regular evaluation of system security through pen tests helps identify vulnerabilities before attackers discover them.
7. Incident Response Team (Incident Response Team)
Designated team and action plan in case of a cyber attack, to minimize response time and impact.
8. Collaboration with cybersecurity experts
External support from cybersecurity consultants or service enhances business readiness, especially for small and medium-sized businesses without an in-house IT department.
Source: techcrunch.com
