News
  • Login
  • Home
  • News
  • Sport
  • Worklife
  • Travel
  • Reel
  • Future
  • More
Friday, July 3, 2026
No Result
View All Result

NEWS

3 °c
London
8 ° Wed
9 ° Thu
11 ° Fri
13 ° Sat
  • Home
  • Video
  • World
    • All
    • Africa
    • Asia
    • Australia
    • Europe
    • Latin America
    • Middle East
    • US & Canada

    Australia vs Ireland: Joe Schmidt not planning Leinster return and rules out another Test job

    Instagram running ads promoting child sexual abuse material in India, BBC finds

    Ebola treatments trial begins in the Democratic Republic of Congo

    Nine Thai monks killed after 11-year-old driver collides with procession

    Vatican excommunicates conservative SSPX followers

    Venezuela quake survivor pulled out alive after eight days on

    Bomb blast at central Damascus cafe kills six, state media say

    Dangerous heatwave scorches US ahead of Fourth of July holiday

    What are US and Japanese soldiers doing in the middle of the Australian bush?

  • UK
    • All
    • England
    • N. Ireland
    • Politics
    • Scotland
    • Wales

    Lamb kebabs made of goat compared to horsemeat in lasagne scandal

    Kate Forbes: I was ‘slam dunk’ for SNP leadership until revealing gay marriage views

    Murci fashion side hustle from nan’s house turns into £10m business

    Noah Donohoe: Inquest adjourned until later in year after late-night sitting

    Pubs allowed to stay open until 5am for England Mexico match

    Boys who raped teen girls in Fordingbridge given custodial sentences after review

    Dog cruelty cases rise in Wales following XL bully ban

    The parents fighting to save a high school with just eight pupils

    Pontypridd man who used food bank after graduating wants to end stigma

  • Business
    • All
    • Companies
    • Connected World
    • Economy
    • Entrepreneurship
    • Global Trade
    • Technology of Business

    ‘We give up to £400 to a honeymoon fund’: How much should you gift at a wedding?

    World Cup dreams shattered as StubHub tickets cancelled at last minute

    USMCA: Why the expected fight over the North American trade deal never kicked off

    Diesel sees biggest monthly fall in 26 years. What’s happening to fuel prices?

    Up to 150 ex-WHSmith high street stores to close as rescue deal approved

    What is GDP and how fast is the UK economy growing?

    Fable and Mythos: Anthropic says US lifts export ban on its advanced AI tools

    British American Tobacco to cut 9,000 jobs

    Plea for households to read energy meter as prices rise

  • Tech
  • Entertainment & Arts

    Dancers say Lizzo ‘needs to be held accountable’ over harassment claims

    Freddie Mercury: Contents of former home being sold at auction

    Harry Potter and the Cursed Child marks seven years in West End

    Sinéad O’Connor: In her own words

    Tom Jones: Neighbour surprised to find singer in flat below

    BBC presenter: What is the evidence?

    Watch: The latest on BBC presenter story… in under a minute

    Watch: George Alagiah’s extraordinary career

    BBC News presenter pays tribute to ‘much loved’ colleague George Alagiah

    Excited filmgoers: 'Barbie is everything'

  • Science
  • Health
  • In Pictures
  • Reality Check
  • Have your say
  • More
    • Newsbeat
    • Long Reads

NEWS

No Result
View All Result
Home Tech

Co-op DragonForce cyber attack includes customer data, firm admits

May 3, 2025
in Tech
7 min read
250 3
0
491
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter


Joe Tidy

Cyber correspondent, BBC World Service

Getty Images Co-op sign lit up at night in LondonGetty Images

Cyber criminals have told BBC News their hack against Co-op is far more serious than the company previously admitted.

Hackers contacted the BBC with proof they had infiltrated IT networks and stolen huge amounts of customer and employee data.

After being approached on Friday, a Co-op spokesperson said the hackers “accessed data relating to a significant number of our current and past members”.

Co-op had previously said that it had taken “proactive measures” to fend off hackers and that it was only having a “small impact” on its operations.

It also assured the public that there was “no evidence that customer data was compromised”.

The cyber criminals claim to have the private information of 20 million people who signed up to Co-op’s membership scheme, but the firm would not confirm that number.

The criminals, who are using the name DragonForce, say they are also responsible for the ongoing attack on M&S and an attempted hack of Harrods.

The attacks have led government minister Pat McFadden to warn companies to “treat cyber security as an absolute priority”.

The anonymous hackers showed the BBC screenshots of the first extortion message they sent to Co-op’s head of cyber security in an internal Microsoft Teams chat on 25 April.

“Hello, we exfiltrated the data from your company,” the chat says.

“We have customer database, and Co-op member card data.”

They also showed screenshots of a call with the head of security which took place around a week ago.

The hackers say they messaged other members of the executive committee too as part of their scheme to blackmail the firm.

Co-op has more than 2,500 supermarkets as well as 800 funeral homes and an insurance business.

It employs around 70,000 staff nationwide.

The cyber attack was announced by the company on Wednesday.

On Thursday, it was revealed Co-op staff were being urged to keep their cameras on during Teams meetings, ordered not to record or transcribe calls, and to verify that all participants were genuine Co-op staff.

The security measure now appears to be a direct result of the hackers having access to internal Teams chats and calls.

DragonForce shared databases with the BBC that includes usernames and passwords of all employees.

They also sent a sample of 10,000 customers data including Co-op membership card numbers, names, home addresses, emails and phone numbers.

The BBC has destroyed the data it received, and is not publishing or sharing these documents.

DragonForce claims

The Co-op membership database is thought to be highly valuable to the company.

Since the BBC contacted Co-op about the hackers’ evidence, the firm has disclosed the full extent of the breach to its staff and the stock market.

“This data includes Co-op Group members’ personal data such as names and contact details, and did not include members’ passwords, bank or credit card details, transactions or information relating to any members’ or customers’ products or services with the Co-op Group,” a spokesperson said.

DragonForce want the BBC to report the hack – they are apparently trying to extort the company for money.

But the criminals wouldn’t say what they plan to do with the data if they don’t get paid.

They refused to talk about M&S or Harrods and when asked about how they feel about causing so much distress and damage to business and customers, they refused to answer.

DragonForce is a ransomware group known for scrambling victims’ data and demanding a ransom is paid to get the key to unscramble it. They are also known to have stolen data as part of their extortion tactics.

DragonForce operates an affiliate cyber crime service so anyone can use their malicious software and website to carry out attacks and extortions.

It’s not known who is ultimately using the DragonForce service to attack the retailers, but some security experts say the tactics seen are similar to that of a loosely coordinated group of hackers who have been called Scattered Spider or Octo Tempest.

The gang operates on Telegram and Discord channels and is English-speaking and young – in some cases only teenagers.

Conversations with the Co-op hackers were carried out in text form – but it is clear the hacker, who called himself a spokesperson, was a fluent English speaker.

They say two of the hackers want to be known as “Raymond Reddington” and “Dembe Zuma” after characters from US crime thriller Blacklist which involves a wanted criminal helping police take down other criminals on a ‘blacklist’.

The hackers say “we’re putting UK retailers on the Blacklist”.

Co-op says it is working with the NCSC and the NCA and said in a statement it is very sorry this situation has arisen.

‘Wake-up call’

UK government officials have met over the cyber attacks, with national security staff and the chief executive of the National Cyber Security Centre discussing support for retailers.

In a keynote speech next week setting out government action, minister Pat McFadden – who has responsibility for cyber security – will say the attacks need to be a “wake-up call” for every UK business.

“In a world where the cybercriminals targeting us are relentless in their pursuit of profit – with attempts being made every hour of every day – companies must treat cyber security as an absolute priority.

“We’ve watched in real-time the disruption these attacks have caused – including to working families going about their everyday lives.

“It serves as a powerful reminder that just as you would never leave your car or your house unlocked on your way to work. We have to treat our digital shop fronts the same way.”

A green promotional banner with black squares and rectangles forming pixels, moving in from the right. The text says: “Tech Decoded: The world’s biggest tech news in your inbox every Monday.”



Source link

Tags: admitsattackCoOpcustomerCyberdataDragonForceFirmincludes

Related Posts

Artificial intelligence: Yann LeCun works on more flexible AI

July 3, 2026
0

"We don't have robots that are nearly as good at understanding the physical world as a rat," says Yann...

Car tracking features for ‘convenience not security’ warns Kia

July 2, 2026
0

"Kia Connect is a customer convenience feature, not a certified security vehicle tracker," the firm told the BBC."Therefore, it...

E-scooters being advertised for commuting despite UK road ban

July 1, 2026
0

Retailers including Amazon, Argos and Currys have been found to advertise e‑scooters for use on public roads and paths,...

  • Australia helicopter collision: Mid-air clash wreckage covers Gold Coast

    523 shares
    Share 209 Tweet 131
  • UK inflation: Supermarkets say price rises will ease soon

    515 shares
    Share 206 Tweet 129
  • Ballyjamesduff: Man dies after hit-and-run in County Cavan

    510 shares
    Share 204 Tweet 128
  • Somalia: Rare access to its US-funded 'lightning commando brigade

    508 shares
    Share 203 Tweet 127
  • Google faces new multi-billion advertising lawsuit

    508 shares
    Share 203 Tweet 127
  • Trending
  • Comments
  • Latest

Australia helicopter collision: Mid-air clash wreckage covers Gold Coast

January 10, 2023

UK inflation: Supermarkets say price rises will ease soon

April 19, 2023

Ballyjamesduff: Man dies after hit-and-run in County Cavan

August 19, 2022

Stranger Things actor Jamie Campbell Bower praised for addiction post

0

NHS to close Tavistock child gender identity clinic

0

Cold sores traced back to kissing in Bronze Age by Cambridge research

0

Thousands of fish killed in Bromley park pollution mystery

July 3, 2026

Lamb kebabs made of goat compared to horsemeat in lasagne scandal

July 3, 2026

Nara Smith: Daughter’s cancer diagnosis prompts wave of support

July 3, 2026

Categories

Science

Thousands of fish killed in Bromley park pollution mystery

July 3, 2026
0

Thames Water, which operates the local drainage network, said it was "urgently investigating the pollution incident" but its cause...

Read more

Lamb kebabs made of goat compared to horsemeat in lasagne scandal

July 3, 2026
News

Copyright © 2020 JBC News Powered by JOOJ.us

Explore the JBC

  • Home
  • News
  • Sport
  • Worklife
  • Travel
  • Reel
  • Future
  • More

Follow Us

  • Home Main
  • Video
  • World
  • Top News
  • Business
  • Sport
  • Tech
  • UK
  • In Pictures
  • Health
  • Reality Check
  • Science
  • Entertainment & Arts
  • Login

Copyright © 2020 JBC News Powered by JOOJ.us

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
News
More Sites

    MORE

  • Home
  • News
  • Sport
  • Worklife
  • Travel
  • Reel
  • Future
  • More
  • News

    JBC News