Co-op’s chief executive, Shirine Khoury-Haq, has confirmed that all 6.5 million of the retailer’s members had their data compromised in April’s major cyber-attack.
Speaking publicly for the first time since the incident, Khoury-Haq told BBC interviewers that all of Co-op’s members ‘should be concerned’ after the store lost millions of names, addresses and contact information to hackers, although claimed that no financial or transaction data had been stolen.
“I’m devastated that information was taken,” she told BBC Breakfast, adding that she was ‘incredibly sorry’ for the impact of the cyber-attack on Co-op’s members and customers, saying that, “We know a lot of that information is out there anyway, but people will be worried.”
Describing the initial moments after the hack, the chief exec said: “Early on I met with our IT staff and they were in the midst of it. I will never forget the looks on their faces, trying to fight off these criminals.”
Security teams swiftly shut down portions of Co-op’s systems following the attack, though Khoury-Haq said that after the hackers were removed, “they could not erase what they did, so we could monitor every mouse click”, giving law enforcement insight into their nefarious activities.
The news that all of Co-op’s members have been impacted by the breach is the latest in a drip-feed of information given out in the months since the cyber-attack on 30th April.
Initially, the store said that the incident would have only a ‘small impact’ on call-centre and back office functions and did not advise customers to do anything differently or take extra precautions.
However, after the BBC was contacted by the alleged hackers in May, Co-op soon acknowledged that it had become clear the incident was more serious than it had originally reported.
Months on, the retailer is taking an innovative approach to help prevent similar cyber incidents in the future.
Announcing a new strategic partnership with The Hacking Games, a UK-based social impact business, Co-op said it hopes to identify young cyber talent and channel their skills into positive, ethical careers.
The store’s positive response to its deep security crisis is notable given that the NCA recently arrested four young adults, all under the age of 21, as part of investigations into the Co-op hack.
Recommended reading
- NCSC Launches Vulnerability Research Initiative
- Record 7.3 Tbps DDoS Attack Blocked
- Why Are Young People Becoming Cyber-criminals?
Research shows that around three in five (61%) of hackers in the UK started by exploring coding and online games, while 69% of European teenagers admit to committing some form of cybercrime or online offence.
With that in mind, Co-op said that the initiative combines a long-term response to its own cyber-attack with the urgent need to engage Gen Z and inspire them to pursue careers in cybersecurity
“We know first-hand what it feels like to be targeted by cybercrime,” said Khoury-Haq.
“At Co-op, we can’t just stand back and hope it doesn’t happen again – to us or to others. Our partnership with The Hacking Games lets us reach talented young people early, guide their skills toward protection rather than harm, and open real paths into ethical work.”





