Co-op has reportedly been forced to shut down its IT systems following an attempted hack of its network earlier in the week.
The attempted attack took place just days after M&S suffered a cyber-attack which is still causing the store woe, leading to empty shelves and interrupted orders.
The Co-op owns over 2,000 grocery stores and more than 8000 funeral homes, as well as financial and legal services firms.
Co-op says that the firm has since taken “proactive steps” to protect its systems following the attempted hack, “which resulted in a small impact to some of our back office and call centre services.”
The spokesperson said: “All our stores (including quick commerce operations) and funeral homes are trading as usual.
“We are working hard to reduce any disruption to our services and would like to thank our colleagues, members, partners and suppliers for their understanding during this period.
“We are not asking our members or customers to do anything differently at this point. We will continue to provide updates as necessary.”
It is unclear if Co-op identified the attempted hack via increased checks sparked by the M&S cyber-attack, which has now been credited to the prolific cyber gang Scattered Spider.
Co-op’s reaction to the attempted hack, including not asking its customers to do anything different, suggests that customer data was not compromised in the incident.
Retailers are facing more and more IT incidents and interruptions, though not all of them are related to attempted or successful attacks.
At the tail end of last year, Morrisons faced a cyber incident connected to Blue Yonder, its tech vendor. Sainsbury’s and Tesco also faced IT interruptions, though these were not related to cyber-attacks.
The continuing trend may offer a wake-up call to retailers as M&S continues to face interruptions to its services and Co-op gets to grips with the attempted hack.
Recommended reading
- Scattered Spider Linked to M&S Cyber-attack Chaos
- M&S Apologises To Customers Following ‘Cyber Incident’
- How Have Cyber Experts Reacted to the M&S ‘Incident’?
“The attempted hack on Co-op’s IT systems forced a shutdown of crucial back-office functions and exposed alarming vulnerabilities,” Scott Dawson, CEO of DECTA, a payment processor firm, said.
“Retailers can no longer afford to treat resilience as optional as this becomes more of a trend.”
“This incident, coming on the heels of major breaches at Marks & Spencer and other high-profile targets, highlights how brittle legacy architectures and siloed security practices are, and no match for sophisticated threat actors. Until businesses adopt uniform metrics and invest in fail-safe recovery plans, every transaction—and every customer relationship—remains at risk. When a single intrusion forces entire back-office operations offline, every step from inventory management to customer service teeters on collapse.
“Much like the repeated failures of banking apps, this illustrates a fundamental weakness in the resilience of the systems we rely on most. It’s no longer enough to simply talk about resilience; it’s a crucial element of modern business, especially when dealing with finances. The lack of standardised ways to measure resilience has contributed to it being dismissed as mere rhetoric by some business leaders.”
“It’s time to move beyond rhetoric: businesses must move from reactive patchwork to proactive resilience engineering architected into every layer of IT strategy, or retailers will continue to pay the price. Only then can retailers protect revenue streams, reputations and the trust of the millions who rely on them.”





