Executive Summary
In April 2025, the Co-operative Group (Co-op), a major UK member-owned retailer, experienced a sophisticated cyberattack attributed to Scattered Spider affiliates linked to the DragonForce ransomware operation. The attack targeted Co-op’s IT infrastructure, forcing the group to shut down critical systems, causing major disruptions to back-office and call-center operations, and necessitating rapid manual workarounds. Although Co-op's incident response prevented data encryption, attackers stole sensitive personal information of all 6.5 million current and past members, including names and contact details. The breach resulted in significant operational outages, with £80 million ($107 million USD) in immediate financial losses and longer-term revenue reduction due to impacted retail operations and customer trust.
This incident highlights the evolving threat of identity-driven ransomware attacks and the increasing willingness of threat actors to disrupt critical infrastructure for financial gain. The scale and impact of the Co-op breach underscore the need for advanced security controls and segmented, resilient architectures to counter modern ransomware groups.
Why This Matters Now
Ransomware operators increasingly leverage personal data theft and fast-disruptive tactics, even in highly regulated and critical sectors like retail food supply. The Co-op breach exemplifies urgent security gaps in east-west traffic visibility, zero trust segmentation, and rapid incident response—making this a pivotal learning opportunity as similar attacks escalate.
Attack Path Analysis
Attackers linked to Scattered Spider gained an initial foothold into Co-op’s network, likely via social engineering or exploiting weak credentials. Once inside, they escalated privileges to gain broad access to domain controllers. The threat actors moved laterally, compromising additional systems and internal services, eventually establishing command and control channels to manage the attack remotely. Personal data of millions of members was exfiltrated before an attempted ransomware deployment, which, while thwarted, still caused major operational disruption and financial loss.
Kill Chain Progression
Initial Compromise
Description
Adversaries obtained initial access through phishing or credential theft, exploiting insufficient authentication controls or exposed services.
Related CVEs
CVE-2015-2291
CVSS 7.8An issue in the Intel Ethernet diagnostics driver for Windows allows an attacker to terminate security software, potentially leading to unauthorized access.
Affected Products:
Intel Ethernet diagnostics driver – before 1.3.1.0
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Valid Accounts
Phishing: Spearphishing Attachment
Create Account: Local Account
Data Encrypted for Impact
Windows Management Instrumentation
OS Credential Dumping
Exfiltration Over C2 Channel
File Deletion
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
GDPR – Security of Processing and Breach Notification
Control ID: Articles 32 & 33
PCI DSS 4.0 – Implement monitoring and logging
Control ID: 10.2.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: Section 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management
Control ID: Article 10
NIS2 Directive – Risk Management Measures
Control ID: Article 21(2)
CISA Zero Trust Maturity Model 2.0 – Identity Security and Least Privilege
Control ID: Identity Pillar – Authentication and Authorization
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Retail Industry
Scattered Spider ransomware targeting retail operations causes massive inventory disruption, customer data breaches, and revenue losses requiring zero trust segmentation and egress security controls.
Food/Beverages
Food retail chains face supply chain disruption, stock allocation failures, and trading system outages from ransomware attacks, necessitating multicloud visibility and threat detection capabilities.
Financial Services
Member financial data exposure and payment system vulnerabilities in cooperative financial services require enhanced encrypted traffic protection and anomaly detection for ransomware prevention.
Consumer Services
Customer service operations and call centers targeted by Scattered Spider affiliates need secure hybrid connectivity and Kubernetes security to protect member data systems.
Sources
- Co-op says it lost $107 million after Scattered Spider attackhttps://www.bleepingcomputer.com/news/security/co-op-says-it-lost-107-million-after-scattered-spider-attack/Verified
- Co-op boss admits all 6.5m members had data stolen in cyber-attackhttps://www.theguardian.com/business/2025/jul/16/co-op-boss-admits-all-65m-members-had-data-stolen-in-cyber-attackVerified
- Co-op forced to shut down part of IT system after hack attempthttps://www.theguardian.com/business/2025/apr/30/co-op-forced-to-shut-down-part-of-it-system-after-hack-attemptVerified
- UK arrests four people over cyber attacks on Marks & Spencer, Co-op and Harrodshttps://apnews.com/article/9f9ea474a42acd147b81c5a7ff3ff05dVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Implementing CNSF controls such as Zero Trust Segmentation, East-West Traffic Security, Egress Policy Enforcement, and Threat Detection would have reduced blast radius, constrained lateral attacker movement, and provided earlier detection and mitigation of exfiltration and disruptive actions.
Control: Threat Detection & Anomaly Response
Mitigation: Suspicious logins or anomalous authentication attempts would be detected in real time.
Control: Multicloud Visibility & Control
Mitigation: Centralized monitoring would reveal privilege changes and abnormal permission use.
Control: Zero Trust Segmentation
Mitigation: Lateral spread would be blocked by strict microsegmentation and identity-based policies.
Control: Cloud Firewall (ACF) and Inline IPS (Suricata)
Mitigation: Outbound C2 traffic is detected and/or blocked by inline IPS and firewall inspection.
Control: Egress Security & Policy Enforcement
Mitigation: Unauthorized outbound data transfers would be blocked or flagged.
Ransomware propagation attempts within the environment are prevented by internal flow controls.
Impact at a Glance
Affected Business Functions
- Retail Operations
- Customer Service
- Supply Chain Management
Estimated downtime: 30 days
Estimated loss: $150,000,000
Personal data of all 6.5 million Co-op members, including names, addresses, and contact details, were stolen. No financial information was compromised.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to contain and isolate threats, preventing uncontrolled lateral movement.
- • Enforce comprehensive Egress Security and strict policy enforcement to block C2 and exfiltration channels.
- • Deploy continuous Threat Detection & Anomaly Response to identify abnormal behavior and accelerate incident response.
- • Ensure Multicloud Visibility & centralized control to rapidly detect and react to privilege escalation or policy violations.
- • Harden east-west traffic flows and apply inline IPS inspection to detect ransomware and prevent malicious payload distribution.



