The Co-operative Group (Co-op) in the UK recently published its financial results for the first half of 2025, revealing that the unprecedented cyberattack in April caused serious damage. The blow to the group's operations is estimated at 80 million pounds ($107 million), with the loss coming from both one-off additional costs of 20 million pounds and lost sales of 60 million pounds while the systems were down.

The impact of the attack was also felt on revenue, which fell by 206 million pounds ($277 million). Management estimates there will be an additional 20 million pounds in losses in the second half as the recovery continues gradually.
See also: Neon call recording app victim of security breach
The Co-op Group and the extent of its services
The Co-op is one of the largest member cooperative groups in the UK, operating across a range of sectors: food retail, life services and business-to-business services. It has 2,300 retail stores and 59 franchise stores, making its critical infrastructure a particularly attractive target for cyberattacks.
In late April, the Co-op was forced to shut down parts of IT systems after suspicious activity was detected, causing limited disruptions to back-office services and call centres.

The nature of cyberattack
The attack was linked to the DragonForce ransomware and Scattered Spider. The hackers managed to gain access to personal data of 6.5 million members, including current and former users, and compromise critical Windows domain controllers. Despite the Co-op's immediate response, the recovery effort was extended and the systems were out of service for weeks.
On July 10, the UK's National Crime Agency arrested four young men aged 17-20, who were allegedly involved in the attack, as well as other similar attacks on Marks & Spencer and Harrods.
See also: Conditional release for teenage hacker who attacked casino
Treatment and temporary solutions
The Co-op managed to prevent data encryption, limiting the damage, but the group's operations were significantly disrupted. Some systems were taken offline, resulting in trading disruptions and limited stock availability, particularly in the food sector.
The company temporarily introduced manual processes and offered discount vouchers to its members. Despite these efforts, the Co-op faced serious challenges in stock allocation and sales collapsed in some product categories.
See also: New backdoor attacks tech and legal sectors

Financial resilience and liquidity management
Despite the crisis, the Co-op’s liquidity remained strong, with £800m of capital available to deal with external pressures. The finance director stressed that no funding concerns had arisen, while management remained focused on the group’s long-term ambitions, seeking to strengthen security processes and the resilience of its infrastructure.
Cybersecurity courses for the industry
The attack on the Co-op is a reminder to all large businesses: investing in cybersecurity is no longer optional. Protecting privacy , ensuring IT infrastructure is resilient and responding quickly to incidents is critical to maintaining consumer trust. Furthermore, the business demonstrated that being flexible in processes and quickly adopting alternative solutions is key to limiting the financial impact.
See also: COLDRIVER group distributes new backdoor BAITSWITCH
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The April 2025 cyberattack has left a significant mark on Co-op, highlighting the growing risk for large businesses that rely on digital systems. Despite the serious losses, the company has shown resilience, effectively managing its liquidity and strengthening its security procedures. This case serves as a lesson for the entire industry, highlighting that protecting data and investing in secure infrastructure are not just options but a necessity.
