Co-op Admits Massive Data Breach: Customer Information Stolen in DragonForce Ransomware Attack


# Co-op Cyberattack More Severe Than Initially Reported: Data Stolen from Millions

Co-op has confirmed that its recent cyberattack was significantly worse than first acknowledged, with hackers successfully extracting data from company systems. “The accessed data included information relating to a significant number of our current and past members,” Co-op stated, clarifying that while personal information such as names and contact details were compromised, passwords, financial information, and transaction data remained secure.

Initially downplaying the incident as an “attempted intrusion,” Co-op has now admitted to a full-scale breach. Sources indicate the attack occurred around April 22, using tactics similar to those employed against Marks and Spencer. Hackers used social engineering to reset an employee’s password, gaining network access and stealing the Windows NTDS.dit file containing password hashes for Windows accounts.

## DragonForce Ransomware Claims Responsibility

The BBC has reported that affiliates of the DragonForce ransomware operation are behind the attack. The threat actors claim to have stolen data from approximately 20 million people registered in Co-op’s membership reward program. They contacted Co-op executives directly through Microsoft Teams messages to initiate extortion demands.

In response, Co-op is rebuilding its Windows domain controllers and strengthening security measures with assistance from Microsoft DART and KPMG. The company has also warned employees to exercise caution when using Microsoft Teams.

## Understanding the Threat Actors

DragonForce operates as a ransomware-as-a-service platform where affiliates use their encryption tools and negotiation sites in exchange for 20-30% of ransom payments. The operation is believed to be working with English-speaking threat actors associated with “Scattered Spider” or “Octo Tempest” – known for social engineering attacks, SIM swapping, and MFA fatigue techniques.

Rather than a defined group, Scattered Spider represents a loose community of financially motivated hackers who share tactics and communication channels. While some original members have been arrested in international operations, new actors continue to employ similar methods in escalating attacks.

The same threat actors also claimed responsibility for an attempted cyberattack on Harrods, indicating a pattern of targeting high-profile UK retailers.

Share This Article