Hackers Allegedly Breach UK Retailers’ Networks in Ransomware Attacks

Hackers Allegedly Breach UK Retailers’ Networks in Ransomware Attacks

Retail Cyber Siege: Co-op Confirms Breach as DragonForce Targets Major UK Brands

A sophisticated cybercrime campaign has rocked the UK retail sector, with the cyber extortion group known as DragonForce taking credit for a coordinated wave of ransomware attacks. Among the most impacted is Co-op, which has now confirmed that attackers infiltrated its internal systems and accessed sensitive membership data.

This latest breach, part of a broader assault that includes attempts on Marks & Spencer and Harrods, has drawn heightened scrutiny from cybersecurity agencies and government officials alike.

Co-op Breach: Beyond Initial Assurances

While Co-op initially described the cyber intrusion as minor, the reality appears far more serious. The company has now acknowledged that an external threat actor penetrated one of its systems and exfiltrated personal information tied to “a significant number” of both current and former members.

The ransomware syndicate behind the attack, DragonForce, provided the BBC with leaked files allegedly containing customer names, addresses, email addresses, phone numbers, and membership card numbers. Passwords and payment details were reportedly not among the stolen data, according to Co-op.

Security professionals suggest the breach began with a meticulously crafted social engineering campaign. Posing as IT support staff, the attackers may have tricked employees into surrendering login credentials or multi-factor authentication tokens, gaining a foothold in the network.

Once inside, they are believed to have compromised the organization’s Active Directory system (NTDS.dit) — a prime target due to its store of encrypted login data for all domain users.

Disabling Defenses: A Calculated Strike

After establishing privileged access, the attackers likely deployed a method known as Bring Your Own Vulnerable Driver (BYOVD) — a tactic that leverages legitimate, yet flawed, Windows drivers to neutralize antivirus protections. To further cement their control and prevent data recovery, DragonForce operatives likely erased backup snapshots (Volume Shadow Copies), effectively crippling the system’s ability to self-restore.

Retailers in the Crosshairs

The ongoing cyber campaign extends beyond Co-op. Marks & Spencer is facing system outages and online sales disruptions, with signs suggesting the infiltration began as early as February 2025. Attackers reportedly extracted credential hashes and maintained stealthy access using legitimate login methods.

An attempted breach at Harrods was also disclosed, although the company has not confirmed the extent of any intrusion.

What’s particularly alarming to analysts is DragonForce’s ransomware-as-a-service model. Operating more like a criminal franchise than a lone hacker cell, the group relies on affiliate partners to conduct attacks. Affiliates receive the lion’s share of ransom payments — up to 80% — while DragonForce supplies backend infrastructure, data leak sites, and negotiation frameworks.

Official Response and Security Clampdown

The UK government has begun to respond. Cabinet Office Minister Pat McFadden is expected to use his platform at the upcoming CyberUK conference to issue a stark warning: cybersecurity is no longer optional — it is a foundational priority.

Meanwhile, Co-op has enacted stricter internal protocols. Remote access has been curtailed, select IT systems taken offline, and all virtual meetings now require participant verification and camera use to thwart impersonation tactics.

As the threat landscape continues to evolve, experts warn that any business managing large volumes of customer data — especially within retail — is at increasing risk. With DragonForce still active and undeterred, this wave of ransomware activity may represent just the opening salvo in a much larger digital conflict.

More Articles & Posts