The Co-op has taken parts of its IT infrastructure offline after detecting an attempted cyberattack, just days after Marks & Spencer reported a significant cybersecurity incident.
The mutual, which operates more than 2,000 grocery stores and over 800 funeral homes, alongside legal and financial services businesses, confirmed it had proactively shut down some business systems to safeguard its operations.
Services affected include internal tools used by store teams and the Co-op’s legal services division. The group said these precautionary measures were part of its wider response to the security threat.
Despite the disruption, the Co-op said all retail outlets, including rapid home delivery services, continue to operate normally, as do its funeral care services.
Dray Agha, Senior Manager of Security Operations at Huntress, said: “The Co-op’s swift action to pre-emptively disable access to key systems reflects a mature, proactive incident response posture. Shutting down virtual desktops and limiting backend functions, while disruptive, is often a necessary measure to contain threats before they escalate into full-scale breaches.
“This incident aligns with a broader trend we’re seeing where attackers increasingly target retail and essential services with initial access attempts, often through phishing or credential abuse, before escalating to ransomware or data theft. Defenders must stay vigilant, especially in sectors managing large volumes of sensitive customer and payment data.
“This is a timely reminder of why continuous threat detection and rapid response are critical. Real-time investigation and intervention mean the difference between an interruption and a catastrophe.”
Jake Moore, Global Cybersecurity Advisor, ESET, said: “The Scattered Spider hacking group are known for bragging about their conquests and even requesting kudos from their peers in showing exactly how they were successful or even highlighting similar vulnerabilities that may eve still be live elsewhere. It’s therefore typical for other companies in the same sector to ramp up defences or even shut down parts of their systems after a major cyberattack to mitigate any potential threat. This is often a precautionary measure to prevent similar breaches, especially when there are shared vulnerabilities.”

