The Containment Era is here. →Explore

Executive Summary

In April 2025, the Co-operative Group (Co-op), a major UK member-owned retailer, experienced a sophisticated cyberattack attributed to Scattered Spider affiliates linked to the DragonForce ransomware operation. The attack targeted Co-op’s IT infrastructure, forcing the group to shut down critical systems, causing major disruptions to back-office and call-center operations, and necessitating rapid manual workarounds. Although Co-op's incident response prevented data encryption, attackers stole sensitive personal information of all 6.5 million current and past members, including names and contact details. The breach resulted in significant operational outages, with £80 million ($107 million USD) in immediate financial losses and longer-term revenue reduction due to impacted retail operations and customer trust.

This incident highlights the evolving threat of identity-driven ransomware attacks and the increasing willingness of threat actors to disrupt critical infrastructure for financial gain. The scale and impact of the Co-op breach underscore the need for advanced security controls and segmented, resilient architectures to counter modern ransomware groups.

Why This Matters Now

Ransomware operators increasingly leverage personal data theft and fast-disruptive tactics, even in highly regulated and critical sectors like retail food supply. The Co-op breach exemplifies urgent security gaps in east-west traffic visibility, zero trust segmentation, and rapid incident response—making this a pivotal learning opportunity as similar attacks escalate.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Affiliates of the Scattered Spider group exploited vulnerabilities in Co-op's IT systems, stealing member data and disrupting operations, though ransomware encryption was ultimately prevented.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Implementing CNSF controls such as Zero Trust Segmentation, East-West Traffic Security, Egress Policy Enforcement, and Threat Detection would have reduced blast radius, constrained lateral attacker movement, and provided earlier detection and mitigation of exfiltration and disruptive actions.

Initial Compromise

Control: Threat Detection & Anomaly Response

Mitigation: Suspicious logins or anomalous authentication attempts would be detected in real time.

Privilege Escalation

Control: Multicloud Visibility & Control

Mitigation: Centralized monitoring would reveal privilege changes and abnormal permission use.

Lateral Movement

Control: Zero Trust Segmentation

Mitigation: Lateral spread would be blocked by strict microsegmentation and identity-based policies.

Command & Control

Control: Cloud Firewall (ACF) and Inline IPS (Suricata)

Mitigation: Outbound C2 traffic is detected and/or blocked by inline IPS and firewall inspection.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Unauthorized outbound data transfers would be blocked or flagged.

Impact (Mitigations)

Ransomware propagation attempts within the environment are prevented by internal flow controls.

Impact at a Glance

Affected Business Functions

  • Retail Operations
  • Customer Service
  • Supply Chain Management
Operational Disruption

Estimated downtime: 30 days

Financial Impact

Estimated loss: $150,000,000

Data Exposure

Personal data of all 6.5 million Co-op members, including names, addresses, and contact details, were stolen. No financial information was compromised.

Recommended Actions

  • Implement Zero Trust Segmentation to contain and isolate threats, preventing uncontrolled lateral movement.
  • Enforce comprehensive Egress Security and strict policy enforcement to block C2 and exfiltration channels.
  • Deploy continuous Threat Detection & Anomaly Response to identify abnormal behavior and accelerate incident response.
  • Ensure Multicloud Visibility & centralized control to rapidly detect and react to privilege escalation or policy violations.
  • Harden east-west traffic flows and apply inline IPS inspection to detect ransomware and prevent malicious payload distribution.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image