Co-op takes systems offline following unauthorised access attempts
The British group Co-op reported unauthorised access attempts and shut down part of its back office and call center systems as a containment measure.

News summary
The British group Co-op reported unauthorised access attempts and shut down part of its back office and call center systems as a containment measure. It subsequently confirmed the extraction of customer data.
Disconnecting systems can limit an attack, but it is only manageable if the company understands dependencies, maintains backups, and has a tested continuity plan.
Source: Reuters — 30 April 2025
What happened
On 30 April 2025 the British group Co-op reported unauthorised access attempts on its systems and shut down part of its back office and call centre as a containment measure. Days later the company confirmed that customer data had been extracted.
The incident was part of a series of attacks on British retailers occurring within a short window, with a common pattern of impersonation targeting support services to gain access.
What it means for a mid-sized business
Proactively disconnecting systems can limit the scope of an attack, but it is only manageable if the business already knows what depends on what: which customer service, sales or logistics processes are affected if the back office is shut down.
The case also confirms that confirmation of data extraction can arrive days after initial detection, which requires careful communication as the investigation progresses, without minimising or alarming without grounds.
What to review
Elements that support orderly containment without total business paralysis:
- A dependency map between back office, call centre, physical store and online channel.
- Recoverable backups of customer service systems and personal data.
- A continuity plan defining which processes keep running manually during containment.
- A customer communication protocol updated as the incident investigation progresses.
Frequently Asked Questions
- Was customer data theft confirmed?
- Yes. Days after detecting the access attempts, Co-op confirmed that customer data had been extracted.
- Why shut down the call centre if the problem was system access?
- Because the call centre relied on the same back-office systems being protected; keeping it running would have left open the access route being closed off.
- What lesson applies to a mid-sized business with centralised customer service?
- Know in advance which processes can keep running manually or through an alternative if the main customer service system is disconnected.
Concepts mentioned in this article: Backup
Is your company prepared for an incident of this nature? At Seintec, we can review access, backups, cloud, endpoints, and procedures to reduce exposure and recovery times. Let’s talk.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.