The Co-operative Group confirmed that names, dates of birth, email addresses, telephone numbers and home addresses belonging to all 6.5 million of its members were taken during the intrusion it disclosed on 30 April 2025. No financial or transactional data was reported stolen.
The Word Doing The Work Is "All"
Breach notifications are normally written in the language of partial exposure — a subset of accounts, a proportion of customers, records belonging to individuals who transacted during a particular window.
Co-op did not have that sentence available. The membership database is a single table with a row for every member, and the intruders reached the table. There is no subset to describe.
Loyalty Schemes Are Built To Be Complete
This desk filed the same structure at 26-0202: a loyalty programme is not a marketing add-on, it is the mechanism by which an anonymous shopper becomes an identified one. Completeness is the entire product.
That design goal and the breach outcome are the same fact viewed from either side. A scheme that held partial records would be worth less commercially and would have leaked less. Nobody has ever been asked to price that trade.
What Was Not Taken Matters Too
No payment data was reported taken, and that is a genuine architectural success — card data sits behind tokenisation and a separate compliance regime that has, in this instance, worked as intended.
The awkward observation is that the regime exists because the card networks made it a condition of doing business. There is no equivalent commercial force behind a name, a date of birth and a home address, so those sat in the general estate. The data that had an industry protecting its own liability survived; the data that only affected members did not.
Compiled from public reporting, listed below. The chief executive apologised publicly in a broadcast interview; we describe that rather than quoting it. Reporting attributes the wider campaign to the cluster tracked as Scattered Spider — see 25-0512 for our treatment of that attribution. Corrections: corrections@forensicpost.com.