Desk live·
ForensicPost
Breaches/Retail/File 25-0501

Co-op Confirms Data of All 6.5 Million Members Was Taken

Co-op confirmed that the personal data of all 6.5 million of its members was taken in the April 2025 intrusion. The membership scheme was the breach.

Constructed geometry · not a chart of case data
JurisdictionUnited KingdomManchesterthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetCo-operative Group
ActorScattered Spider
D. Kennedy11 min readConfidence: high3 sources reviewed

The Co-operative Group confirmed that names, dates of birth, email addresses, telephone numbers and home addresses belonging to all 6.5 million of its members were taken during the intrusion it disclosed on 30 April 2025. No financial or transactional data was reported stolen.

The Word Doing The Work Is "All"

Breach notifications are normally written in the language of partial exposure — a subset of accounts, a proportion of customers, records belonging to individuals who transacted during a particular window.

Co-op did not have that sentence available. The membership database is a single table with a row for every member, and the intruders reached the table. There is no subset to describe.

Loyalty Schemes Are Built To Be Complete

This desk filed the same structure at 26-0202: a loyalty programme is not a marketing add-on, it is the mechanism by which an anonymous shopper becomes an identified one. Completeness is the entire product.

That design goal and the breach outcome are the same fact viewed from either side. A scheme that held partial records would be worth less commercially and would have leaked less. Nobody has ever been asked to price that trade.

What Was Not Taken Matters Too

No payment data was reported taken, and that is a genuine architectural success — card data sits behind tokenisation and a separate compliance regime that has, in this instance, worked as intended.

The awkward observation is that the regime exists because the card networks made it a condition of doing business. There is no equivalent commercial force behind a name, a date of birth and a home address, so those sat in the general estate. The data that had an industry protecting its own liability survived; the data that only affected members did not.

How we reported this

Compiled from public reporting, listed below. The chief executive apologised publicly in a broadcast interview; we describe that rather than quoting it. Reporting attributes the wider campaign to the cluster tracked as Scattered Spider — see 25-0512 for our treatment of that attribution. Corrections: corrections@forensicpost.com.

Sources
  1. UK retail giant Co-op confirms hackers stole all 6.5 million customer recordsTechCrunch
  2. Co-op chief ‘incredibly sorry’ for theft of 6.5m members’ dataComputer Weekly
  3. Co-op confirms cyberattack exposed data of all 6.5 million membersCyberInsider
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary