UK retailer Co-op says the April cyber attack cost the company £206M in revenue, marking the first time it has quantified the financial impact of the attack
Context & Ripple Effects
Co-op was among several UK retailers reporting intrusions in spring 2025. Its emergency shutdown prevented the attackers from deploying ransomware, although the group later claimed it had taken customer data.
The disclosure gives a revenue measure to an incident that unfolded alongside M&S’s projected operating-profit hit from its own April attack, making clear that retail cyber disruption can impose material costs even when systems are rapidly contained.
First-order effects
- Co-op now has a disclosed £206M revenue loss tied to the April incident, giving management, investors and stakeholders a concrete measure of the business interruption.
- The figure shows that shutting systems to avert a lockout did not eliminate the commercial cost of disrupted operations and the associated response.
Second-order effects
- The Co-op and M&S disclosures give other retailers nearer-term benchmarks for cyber-incident planning, while also underscoring that revenue and profit impacts are distinct measures.
- Cybersecurity, continuity and insurance decisions are likely to face closer scrutiny as retailers weigh the cost of rapid shutdowns against the potential cost of broader compromise.
Third-order effects
- If similar disclosures become routine, cyber resilience will be assessed less as a technical-control issue and more as an operational-revenue risk with comparable business-interruption metrics.
- The pattern supports a broader shift toward treating retail cyber incidents as supply-chain and economic disruptions, consistent with Howden’s estimate of large UK business revenue losses from cyberattacks, though the scale will vary by incident and response.
The trend: Cyberattacks are increasingly being translated from security events into measurable business-interruption costs, raising the strategic value of operational resilience.