Skip to main content

Co-op takes systems offline following unauthorised access attempts

The British group Co-op reported unauthorised access attempts and shut down part of its back office and call center systems as a containment measure.

CybersecuritySeintec team2-3 min read
Co-op takes systems offline following unauthorised access attempts

News summary

The British group Co-op reported unauthorised access attempts and shut down part of its back office and call center systems as a containment measure. It subsequently confirmed the extraction of customer data.

Disconnecting systems can limit an attack, but it is only manageable if the company understands dependencies, maintains backups, and has a tested continuity plan.

Source: Reuters — 30 April 2025

What happened

On 30 April 2025 the British group Co-op reported unauthorised access attempts on its systems and shut down part of its back office and call centre as a containment measure. Days later the company confirmed that customer data had been extracted.

The incident was part of a series of attacks on British retailers occurring within a short window, with a common pattern of impersonation targeting support services to gain access.

What it means for a mid-sized business

Proactively disconnecting systems can limit the scope of an attack, but it is only manageable if the business already knows what depends on what: which customer service, sales or logistics processes are affected if the back office is shut down.

The case also confirms that confirmation of data extraction can arrive days after initial detection, which requires careful communication as the investigation progresses, without minimising or alarming without grounds.

What to review

Elements that support orderly containment without total business paralysis:

  • A dependency map between back office, call centre, physical store and online channel.
  • Recoverable backups of customer service systems and personal data.
  • A continuity plan defining which processes keep running manually during containment.
  • A customer communication protocol updated as the incident investigation progresses.

Frequently Asked Questions

Was customer data theft confirmed?
Yes. Days after detecting the access attempts, Co-op confirmed that customer data had been extracted.
Why shut down the call centre if the problem was system access?
Because the call centre relied on the same back-office systems being protected; keeping it running would have left open the access route being closed off.
What lesson applies to a mid-sized business with centralised customer service?
Know in advance which processes can keep running manually or through an alternative if the main customer service system is disconnected.

Concepts mentioned in this article: Backup

Is your company prepared for an incident of this nature? At Seintec, we can review access, backups, cloud, endpoints, and procedures to reduce exposure and recovery times. Let’s talk.

Contact Seintec

Related service

Cybersecurity

We shield your business so it never stops.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.