Skip to content
City PM
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Opinion
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Opinion
Wednesday 16 July 2025 10:58 am  |  Updated:  Wednesday 16 July 2025 10:59 am

Co-op boss confirms data of all 6.5m members stolen

By: Saskia Koopman

Tech Reporter

Add as a preferred source on Google
The Co-op shut down parts of its IT systems on April 30 after detecting a potential breach.
Chief executive Shirine Khoury-Haq said she was “devastated” by the impact of the incident on workers and members

The chief executive of Co-op has confirmed that the personal data of all its 6.5m members was stolen during a major cyber attack in April, marking one of the most widespread data breaches in UK retail history.

Speaking publicly for the first time since the attack, Shirine Khoury-Haq said the breach had a “devastating” impact on customers and staff, and described the hack as “deeply personal”.

“There was no financial or transactional data taken, but names, addresses and contact information was accessed”, Khoury-Haq told BBC Breakfast. “It hurt my members… and that I take personally”.

The comments come just days after the National Crime Agency (NCA) arrested four individuals in connection with the attack, including three teenagers and a 20-year-old woman, following a joint operation across Staffordshire, London, and the West Midlands.

Retail cybercrime wave

The attack on Co-op was part of a coordinated wave of cyber intrusions targeting high-profile UK retailers, including Marks & Spencer and Harrods.

The NCA confirmed last week that the group of suspects were arrested on suspicion of blackmail, money laundering, Computer Misuse Act offences, and participation in an organised crime group.

According to investigators, the group attempted to deploy ransomware across Co-op’s systems but was blocked at the last moment when IT staff severed internet access, potentially avoiding catastrophic business disruption.

However, Co-op later admitted hackers had gained access to a “significant” volume of customer and employee data, including membership details from its profit-sharing scheme.

M&S suffered significant operational damage from a related attack, which has reportedly cost the FTSE 100 retailers £300m in lost earnings.

The company is preparing a £100m insurance claim to recover part of that loss, having had a cyber insurance policy in place through Allianz and Beazley.

Read more

Co-Op and Next among firms launching workplace savings scheme

Profit at Next rise 13.8 per cent in the first six months of the year

Co-op and Harrods, however, did not hold cyber insurance at the time of the attacks – potentially leaving them exposed to material financial and reputational risk.

Co-ops significant damage

Khoury-Haq described the internal scramble to contain the breach, recalling how IT staff worked around the clock to halt further intrusion.

“I met with our IT staff while they were in the midst of it”, she said. “I will never forget the looks on their faces as they tried to fight off these criminals”.

After the hackers were ejected from Co-op’s systems, Khoury-Haq said the firm was able to track their actions in real time and share that data with law enforcement.

Despite these efforts, she acknowledged that the damage was significant. “People will be worried, and all members should be concerned”.

Sector-wide reckoning

The spree of attacks has prompted renewed scrutiny of corporate cybersecurity practices, particularly among UK retailers with vast stores of customer data and legacy IT systems.

In Co-op’s case, the breach also triggered disruption to contactless payments and customer service lines across its food stores in May.

The company restored full payment functionality by mid-May.

Co-op operated under a mutual model, with its 6.5m members owning a share in the business.

“Hacking is not a victimless crime”, said a Co-op spokesperson. “We’ve engaged fully with the NCA throughout and are pleased that this has led to arrests on behalf of our members”.

Read more

The Debate: Should CEOs be held personally accountable for cyberattacks?

Evil-looking keyboard symbolizing cybersecurity threats and hacking risks in a digital landscape.

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Tech
  • Business
  • Retail

People & Organisations

  • Co-op
  • Cyber
  • cyber attack
  • Cyber crime
  • cyber insurance
  • data breach
  • Marks & Spencer

Trending Articles

  • Top Burnham adviser calls for capital gains and inheritance tax hikes

  • Clarkson’s Farm and why businesses must stop blaming the weather

  • Two solicitors linked to Post Office scandal charged with misconduct

  • Lloyd’s deputy chair: The City is a club in the best sense

  • A meeting with the breakfast king of Mayfair

More from City PM

  • Co-Op and Next among firms launching workplace savings scheme

    Personal Finance
    Profit at Next rise 13.8 per cent in the first six months of the year
  • The Debate: Should CEOs be held personally accountable for cyberattacks?

    Opinion
    Evil-looking keyboard symbolizing cybersecurity threats and hacking risks in a digital landscape.
  • Professional services firms the ‘flavour of the month’ for cyberattacks

    Prof Services
    The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”
  • Finimize data: Fees alone won’t win UK retail investors

    Business Wire
  • As it happened: FTSE 100 see-saws amid global jitters as market outlook turns ‘risky and dangerous’

    Markets
    Donald Trump addressing media at a press event, wearing a suit and tie, with reporters and cameras in the background.
  • Government sets out conditions for unlocking ‘trapped capital’ in defined benefit pension schemes

    Personal Finance
    Dominic Cummings claims China has stolen vast amounts of secret UK material
  • Fraud losses surge as scammers use AI to manipulate victims

    Personal Finance
    Executives argue the measures threaten firms’ business models, particularly smaller fintechs more relatively exposed to fraud and with less capital to cover mandatory reimbursement. (Photo by Artur Widak/NurPhoto via Getty Images)
  • Georgia PM’s Starmer outburst over City PM sanctions scoop

    Life&Style
    Georgia PM reacts passionately during press conference on Starmers sanction remarks, highlighting diplomatic tensions.

City PM — European politics, business and analysis.

Europe

  • Germany
  • France
  • Europe
  • UK & Ireland

Topics

  • Business
  • Markets
  • AI
  • Technology
  • Opinion
  • Energy

More

  • Politics
  • Economics
  • Fintech
  • Legal
  • Sport
  • Life

Company

  • About City PM
  • Editorial Policy
  • Corrections
  • Contact
  • Terms of Use
  • Privacy Policy
  • Cookie Policy
© 2026 City PM · Published by CityPM Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
About · Editorial Policy · Corrections · Contact · Privacy