Loading replies...
×
Co-op Group have 5 open jobs left, with nothing posted for 11 days.

Co-op's AGM is this weekend, and M&S yearly results and investor contact are next week.

Gonna be awkward for different reasons, e.g. Co-op is member (customer) owned, so the people's data Co-op had stolen are effectively the shareholders and are invited.

The Channel Islands Coop, which is different to Co-op Group, has been able to restock shelves by moving away from Co-op Group for supply distribution and moving to local suppliers. https://www.bbc.co.uk/news/articles/c3d4xvg3x1do
CI Coop secures local supplies amid stock shortages

The supermarket expects "steady improvements each day", after a cyber attack leads to empty shelves.

BBC News

The Grocer reports Nisa and Costcutter are running out of fruit & veg, fresh meat and poultry, dairy products, chilled ready meals, snacks and desserts.

Nisa and Costcutter are supplied by Co-op Wholesale, which is dependent on Co-op Group.

“It’s really poor. I feel bad for them but what makes it worse is their hush-hush mentality about it. There’s no proper level of communication and we get random updates.”

Co-op Wholesale claim there are no problems. https://www.thegrocer.co.uk/news/nisa-and-costcutter-hit-by-stock-shortages-amid-co-op-cyberattack/704393.article

Nisa and Costcutter hit by stock shortages amid Co-op cyberattack

In communications sent to retailers, the symbol groups listed products that were either 'temporarily unavailable' or 'out of stock' as a result of supplier issues

The Grocer
A look at supplies in stores today, after Co-op told ITV yesterday that stores were restocked 😅
And a video

Co-op Group have told their suppliers that "systemic-based orders will resume for ambient, fresh, and frozen products commencing Wednesday 14 May". They say forecasting system will still be impacted.

https://www.thegrocer.co.uk/news/co-op-to-get-systems-back-on-track-after-cyberattack/704425.article

Co-op to get systems back on track after cyberattack

As the Co-op turns orders back online, it has warned suppliers that it is unable to provide 'accurate product forecasting ahead of Wednesday's orders'

The Grocer
Harrods say they are not asking customers to do anything differently at this point.
Financial Times report Marks and Spencer expect to claim £100m on their cyber insurance, the maximum allowed, suggesting losses probably more. https://www.ft.com/content/723b6195-1ce7-4b5f-94f5-729e9152c578
M&S cyber insurance payout to be worth up to £100mn

UK retailer to file big claim as it admits for first time that some customer data was stolen in recent hack

Financial Times

Co-op Group say they have exited containment and begun recovery phase https://www.theguardian.com/business/2025/may/14/co-op-cyber-attack-stock-availability-in-stores-will-not-improve-until-weekend

Marks and Spencer are still in containment

If you want figures for your board to set expectations in big game ransomware incidents, Co-op containment just over 2 weeks, M&S just over 3 weeks so far - recovery comes after.

In terms of external assistance, Co-op have Microsoft Incident Response (DART), KPMG and crisis comms. M&S have CrowdStrike, Microsoft, Fenix and crisis comms.

Co-op cyber-attack: stock availability in stores ‘will not improve until weekend’

Group in ‘recovery phase’ and working closely with suppliers after customers complain of empty shelves

The Guardian

The threat actor at Co-op says Co-op shut systems down, which appears to have really pissed off the threat actor. This was the right, and smart, thing to do.

While I was at Co-op we did a rehearsal of ransomware deployment on point of sale devices with the retail team, and the outcome was a business ending event due to the inability to take payments for a prolonged period of time. So early intervention with containment was the right thing to do, 100%.

https://www.bbc.co.uk/news/articles/cwy382w9eglo

'They yanked their own plug': how Co-op averted an even worse cyber attack

The revelation - from the criminals responsible - explains why the Co-op is getting back to business faster than M&S.

BBC News
Co-op Group recruitment looks like it is starting again, first new roles in two weeks posted. https://hcnq.fa.em2.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX/jobs
Co-op External Career Section Careers

Find your Co-op job

Co-op External Career Section
Marks and Spencer say food distribution to their stores is returning to normal. It follows Co-op's announcement yesterday that food and drink distribution will begin to return to normal from the weekend. https://www.reuters.com/business/retail-consumer/uks-ms-says-food-availability-improving-every-day-2025-05-15/
27 new jobs at Co-op added today, and it's only midday. So recruitment was definitely paused for two weeks and now active again.

M&S have finally told staff that data about themselves was stolen: https://www.telegraph.co.uk/business/2025/05/16/ms-staff-data-stolen-by-hackers-in-cyber-attack/

You may notice I said they had staff data stolen on May 9th in this thread.

M&S staff data stolen by hackers in cyber attack

Employees’ email addresses and full names have been taken by hackers, sources claim

The Telegraph

For the record, the tools listed in this article aren't used by Co-op.

https://www.computing.co.uk/news/2025/security/five-cyber-tools-co-op-used-to-defeat-ransomware-attack

The link in the article to Vectra Cognito AI has a Coop Sweden logo on it, and the Coop Sweden CISO is named. Coop Sweden is different company. Coop Sweden went on to have a ransomware attack that crippled the org, including point of sale, so I don't think it's a good sales point. Same with Silverfort.

Google AI has ingested the article and now uses it to claim Co-op Group use the tools.

Here are the five cyber tools Co-op used to help defeat its recent ransomware attack

Computing research has identified the security tools and partners the Co-op used to stop last month’s cyberattack in its tracks.

M&S recruitment is still fully stopped, almost a month in. Co-op opened 46 new vacancies today.
Marks and Spencer’s CEO will lose a £1.1m share grant as a result of their cyber incident. https://www.ft.com/content/43531d25-4f7a-4d6e-b809-e85bb8f0033e
M&S chief executive faces £1.1mn pay hit after cyber attack

Stuart Machin’s awards set to shrink after UK retailer’s share price drops following disclosure of sweeping hack

Financial Times

The Times reports M&S were breached through a contractor and that human error is to blame. (Both M&S and Co-op use TCS for their IT Service Desk).

The threat actor went undetected for 52 hours. (I suspect detection was when their ESXi cluster got encrypted).

M&S have told the Times they had no “direct” communication with DragonForce, which is code for they’re using a third party to negotiate - standard practice.

https://www.thetimes.com/uk/technology-uk/article/m-and-s-boss-cyber-attack-7d9hvk6ds

M&S bosses under fire after ‘damaging and embarrassing’ cyberattack

The Times reveals that the hackers penetrated the retailer’s IT systems through a contractor and worked undetected for about 52 hours before the alarm was raised

The Times

M&S looks to be moving to reposition their incident as a third party failure, which I imagine will help redirect some of the blame (they present their financial results during the week to investors): https://www.bbc.co.uk/news/articles/cpqe213vw3po

Both M&S and Co-op outsourced their IT, including their Service Desk (helpdesk), to TCS (Tata) around 2018, as part of cost savings.

M&S hackers believed to have gained access through third party

The retailer has been struggling to get its services back to normal after a cyber-attack in April.

BBC News

There's nothing to suggest TCS itself have a breach btw.

Basically, if you go for the lowest cost helpdesk - you might want to follow the NCSC advice on authenticating password and MFA token resets.

I've put a 3 part deep dive blog series coming out probably next week called Living-Off-The-Company, which is about how teenagers have realised large orgs have outsourced to MSPs who follow the same format of SOP documentation, use of cloud services etc. Orgs have introduced commonality to surf.

@GossiTheDog Something, something, can't outsource risk.
@GossiTheDog
Argh, flashbacks to trying to convince directors that outsourcing IT is bad. Very bad.
@GossiTheDog paywall 😭
RemovePaywall | Free online paywall remover

Remove Paywall, free online paywall remover. Get access to articles without having to pay or login. Works on Bloomberg and hundreds more.

@GossiTheDog having recently dealt with TCS, nothing would surprise me.
@GossiTheDog No direct contact with DragonForce? I'm sure they'll drag them Through The Fire And The Flames over this one.

@GossiTheDog “we aren’t a computer company, so off to India / China / Vietnam / Philippines / etc for all this non-core-business shit”

“Why company not run without computers? Who did this?”

@jpm @GossiTheDog funny how they don't outsource the executive staff. Executives are also non-core-business. Yes, of it's not core business there are reasons to consider outsourcing. But that's the first step in a process, not the simple definition of what must be outsourced.
@GossiTheDog more CEOs should have this sort of consequence for getting breached like this.
@GossiTheDog @grumpybozo you betcha that something will be done about it then.

@GossiTheDog to be fair, IIRC, Coop Sweden went down because their payment provider used Kaseya.

So, it was ransomware on a fourth party, nothing Coop Sweden had any direct control over

@GossiTheDog As a Co-op member, I'm very happy to see them getting back to business
@GossiTheDog
This was yesterday evening in my local co-op store (close to central Manchester.) Still lots of empty spaces on the shelves.
@GossiTheDog All the co-op stores near me have been bare, was like the early covid days
@GossiTheDog And I was expecting the first vacancy to be CTO 😆
@GossiTheDog No opening for a new CISO yet then...
@GossiTheDog They need to advertise for some cyber security positions, perhaps...
@GossiTheDog Those who know this is going to become more and more.

@GossiTheDog

The quote

> They torched shareholder value

made me laugh

they have no idea what the Coop is

@benh @GossiTheDog I have no idea either. Do you have a TL;DR? What's the relation between Coop and Co-op?
@GossiTheDog I have memories of those exercises 😅 (particularly logistics chiming in with 'erm, we'd need to kill all supplier orders asap' and the room going quiet 😳)
Just glad some of the lessons sank in....
@GossiTheDog
Confident on containment within 2 weeks?
@GossiTheDog I will henceforth not do anything differntly and therefore continue not to be a Harrods customer.
@GossiTheDog exactly... They should be talking to the butler.
@GossiTheDog Forecasting system [right now] === manual stock checks and supply chain staff guessing on spreadsheets where to send things
@GossiTheDog title sounds like a bad rap line.
@GossiTheDog “Ambient”?
@thanne @GossiTheDog
Ambient is shop-speak for stuff that is kept at room temperature. So biscuits, tea and coffee, tinned stuff, etc.

@GossiTheDog, TP;DR.

(Too portrait; didn't watch.)

@GossiTheDog All six of the islanders must be happy.
@GossiTheDog Wouldn't be surprised if customers demanded to keep local goods if restock is available again

@GossiTheDog the thieves could probably show up at the AGM and present themselves as a member, since they have access to all the information the Co-Op has on it's membership...number, address, etc.

Short of checking govt. ID or requiring a hard copy of the meeting invite that was mailed to their address. Even then, the thieves might've gotten away with that too.

@johnefrancis @GossiTheDog
Members who wanted to attend were supposed to indicate this on the agm voting form, which closed midday yesterday. I might have tried, but forgot to go back to it until too late..

I've not had any emails from coop about this, despite being a member. Nor from M&S, though I'm only registered on their app. (I can also continue to ignore Harrods, never having used them!)

@johnefrancis @GossiTheDog
And 45 mins later I get an email from M&S. Nice of them to reassure us that none of the stuff I can change, like bank cards, was stolen. Only the things I can't change, like date of birth.
@robert @GossiTheDog so inconvenient to dig up Mom's remains and rebirth myself