Co-op Confirms Hackers Stole Significant Customer Data

The cooperative has been compelled to acknowledge that a cyberattack was more severe than initially stated.

The retailer said on Friday that cyber criminals have stolen data on a “significant” number of its members, having previously claimed the attack
had only a “minor effect” on how it functions
.

A cybercrime group called DragonForce claimed responsibility for the assault as well.
similar attacks on Marks & Spencer and Harrods
.

The gang told the BBC they had stolen the private information of 20m people who signed up to the Co-op’s membership scheme – forcing the retailer to admit the hack was worse than feared.

The Co-op would not say exactly how many people’s data had been stolen when asked for clarification by The Telegraph.

Initially, when the Co-op first announced the cyberattack, they stated that it was causing “a minor effect on some of our backend operations and customer service centers.”

Reportedly, the hackers presented the BBC with screenshots of emails they had dispatched to the retail company’s cybersecurity head on April 25th.

Hackers ‘gained access to and removed data’

A spokesman for the Co-op said on Friday it was “continuing to experience sustained malicious attempts by hackers to access our systems” as it works with government cyber security experts to try and limit the damage of the attack”.

They stated: “Due to the continuous forensic investigation, we have discovered that the attackers managed to infiltrate and retrieve data from one of our systems. This compromised data pertained to a substantial quantity of both our present and former members.”

This dataset encompasses personal information of Co-operative Group members, including their names and contact details; however, it does not encompass members’ passwords, banking or credit card specifics, transaction records, or data related to any products or services provided by the Co-operative Group.

It has enlisted the help of both the National Cyber Security Centre (NCSC) and the National Crime Agency (NCA) as it combats the cyberattack, which follows a similar breach at Marks & Spencer, causing significant disruption for the upscale retailer.
third attack on Harrods
followed on Thursday.

A representative for DragonForce informed Bloomberg that their intention was to blackmail money from the retailers they aimed at.

Marks & Spencer has suffered significantly and had to discontinue accepting contactless payments and halt online ordering following the cyber-attack. Additionally, customers encountered difficulties.
empty shelves
.

It was reported that the retailer’s systems had fallen victim to DragonForce’s ransomware, causing their computer files to be encrypted and making them essentially unusable.

The spokesperson from Co-op stated, “We have taken steps to guarantee that unauthorized entry into our systems is prevented while also striving to reduce inconvenience for our members, clients, employees, and collaborators.”

We value the trust our members have placed in our Co-op by sharing information with us. Safeguarding the privacy of our members’ and customers’ data is crucial, and we deeply regret that this issue has occurred.

Recommended

Working from home has turned Britain into an easy target for cyber attackers.

Read more


Subscribe to the Front Page newsletter at no cost: Your key resource for today’s schedule from The Telegraph—delivered directly to your mailbox every single day of the week.

Leave a Comment