According to BleepingComputer, Co-op Group confirmed on 2 May 2025 that attackers accessed and extracted member personal data after a breach believed to have occurred around 22 April 2025. Public reporting describes social engineering of the IT helpdesk to reset an employee password, which handed the attackers a valid workforce credential and network access. Co-op said names and contact details for a significant number of current and past members left one system, and that the set excluded member passwords, bank or card details, transactions, and product or service data. Coverage also points to later Windows domain compromise indicators, including reported NTDS.dit theft, plus domain-controller rebuild and Entra ID hardening with Microsoft DART. DragonForce affiliates claimed the attack to the BBC and floated a ~20 million membership-registration figure; public reporting does not establish that count as Co-op’s confirmed total. The playbook sits next to the same-wave M&S helpdesk password-reset case, not inside one shared intrusion.

If you want the prevention angle, read the related article on mfa2point0.com.

FAQ

How did the Co-op attackers get their first foothold?

The Co-op attackers got their first foothold by socially engineering the IT helpdesk into resetting an employee password. According to BleepingComputer, that reset produced a usable workforce credential and network access. Public reporting associates the method with Scattered Spider-like tactics also described against Marks & Spencer the prior week, without treating Co-op and M&S as one incident. Public reporting does not establish TAP issuance, a spoofed login page, AiTM session capture, push fatigue, or SIM swap as the Co-op-specific helpdesk mechanism.

Did MFA fail on the Co-op helpdesk reset?

Public reporting does not establish whether MFA was present, skipped, fatigued, or otherwise handled on the Co-op helpdesk password-reset path. What sources do show is a recovery-path failure: support was talked into issuing a new employee password from an attacker narrative. Once that password worked on the network, authentication was already finished. A fix for phishable recovery and enrollment exists; the companion post covers that side without turning this into a product walkthrough.

What member data did Co-op confirm was taken?

Co-op confirmed attackers accessed and extracted member personal data such as names and contact details from one system. The company’s statement to BleepingComputer said the accessed set “did not include members' passwords, bank or credit card details, transactions or information relating to any members' or customers' products or services with the Co-op Group,” and that it covered “a significant number of our current and past members.” DragonForce-linked actors claimed data tied to roughly 20 million membership-program registrations; public reporting does not establish that figure as Co-op’s verified count. Ransom demand amount is not reported in the sources used here.

Why do NTDS.dit and the domain rebuild show up after a password reset?

After the reset-enabled foothold, reporting indicates Windows domain compromise that included theft of NTDS.dit, the Active Directory database that holds password hashes. Co-op rebuilt domain controllers and hardened Entra ID with Microsoft DART assistance, with KPMG also named on AWS work in coverage. That stage is residual post-authentication compromise. Login MFA does not protect an AD database once an employee credential already worked on the network. Member-data extraction from an internal system sits in the same post-foothold bucket.

Is the Co-op breach the same attack as Marks & Spencer or Harrods?

No. Co-op and Marks & Spencer are separate incidents. BleepingComputer links them as same-wave context: DragonForce-affiliated actors and similar helpdesk social-engineering / Scattered Spider-like tactics reported against M&S the prior week. Harrods appears only as a DragonForce operator claim of an attempted cyberattack. Treat the names as adjacent reporting and affiliate noise, not one fused forensic timeline. Public reporting does not establish full attribution beyond the DragonForce affiliate claim and the TTP association.