RSS Amplifier

CyberInsights · Jul 17, 2025

Your Loyalty Card is a Liability: Lessons from the Co-op Hack

0
Sign in to vote or save

CyberInsights · CyberInsights

The recent Co-op cyberattack exposed more than just lax security. It revealed two deeper, systematic problems within the retail sector; an overreliance on vulnerable third party technology, and the unchecked collection of personal data through so-called loyalty schemes. Both deserve scrutiny and even regulation.

CEO Shirine Khoury-Haq confirmed that while no financial data (like card numbers) were stolen, the contact details of all of its 6.5 million members. That includes names, email addresses, phone numbers, and home addresses.

At first glance, this might seem like a lucky escape. No bank details, no passwords. But it’s not. The scale of the privacy loss, with millions affected, highlights a fundamental problem in retail; companies are collecting far more personal data than they actually need, and that data is now a liability. The more you store, the more you risk losing.

Why is this an Issue?

The data stolen in this breach (names, addresses, phone numbers, and email addresses) might not seem critical on its own. But in the wrong hands, it becomes a toolkit for further attacks. Criminals can sell this data on the dark web, where is can be used for phishing schemes, identity fraud and even credential stuffing attacks (where leaked personal information is used to guess or reset passwords on other sites).

Many people still use weak or reused passwords, and knowing details like your address or phone number can help attackers bypass basic security questions.

Beyond this, much of the data was gathered not because it was strictly necessary, but because retailers want to profile, personalise, and market to us effectively. This is done at great risk to user privacy and is often not made clear to the customer.

What is the solution?

At first glance, the solution seems obvious: just stop using loyalty card systems.

But it is not that simple.

Retail is a fiercely competitive industry. Supermarkets constantly try to outmanoeuvre one another, and loyalty programs have become weapons in this marketing arms race. They don’t just offer discounts, they build psychological hooks.

We’re all likes moths to the flames.

The consumers are the moths, and the flames are the half price tin of baked beans.

Rewards, points, little yellow discount stickers; they make us feel like we are getting better deals and they encourage us to remain loyal to these companies.

No retailer is going to walk away from this system voluntarily. To do so would mean losing customers, and revenue, to competitors who keep offering these perks.

The Half-Solution: Better Cybersecurity

A more pragmatic, but still limited, fix is to invest heavily in cybersecurity for these systems. Right now, many loyalty systems rely on third-party vendors to build, manage, or secure critical parts of their infrastructure. The Co-op breach didn’t happen through its core IT systems, it happened because a trusted supplier was compromised.

That’s the problem: even if your own systems are secure, your vendors weaknesses become your vulnerabilities.

Retailers should consider:

  • Building in-house security teams - people will have a bigger commitment to the company’s wellbeing and deeper knowledge of its internal systems. These teams are likely to understand the business logic, spot emerging threats, and act proactively. In a major breach, their jobs may be on the line which is a powerful incentive to get things right.

  • Auditing and reducing third party dependencies - not all external software needs deep access to internal systems or customer data. Security teams must be aware of what software they rely on, what permissions its granted, and what data it touches.

  • Adopt zero-trust architectures - this means that no one (not even internal systems) is trusted by default. Every access request is verified, authenticated, and logged. Its harder to implement than traditional perimeter security, but far more resilient.

  • Practicing real data minimisation - not just storing less data but structuring systems so they never ask for it in the first place unless absolutely necessary. This includes rethinking loyalty systems themselves: does a supermarket really need your home address, or just a pseudonymous ID and purchase history?

This would likely reduce the number and impact of attacks. But it doesn’t solve the core issue: companies are still collecting too much unnecessary data, and the attack surface remains large.

Better security helps, but it’s still a game of catch-up.

A Better Solution

The real answer lies in regulation.

Specifically, laws that limit what kind of data retailers can collect through loyalty programs.

We already have GDPR, which protects consumer data in general. But when it comes to loyalty schemes, there’s a loophole: if customers “consent” by signing up, almost anything goes. That “consent” is often buried in fine print, and the power imbalance is clear.

Don’t sign up, and you miss out on savings everyone else gets.

Tighter regulation could deliver key benefits:

  1. Prevent unnecessary data collection

    Companies wouldn’t be allowed to collect data that they don’t truly need, like your home address or phone number, just to get 5p of a loaf of bread.

  2. Level the playing field

    If no one is allowed to collect excessive data, companies won’t feel so pressured to do so just to keep up.

  3. Support smaller businesses

    Independent retailers rarely have the budget or infrastructure to run complex loyalty schemes. Regulation helps ensure that the bigger companies cannot monopolise customer data as a competitive advantage.

  4. Reduce the impact of future breaches

    If companies aren’t storing unnecessary user data in the first place, then a breach (like the one at Co-op) would be far less damaging.

For these reasons I believe that government regulations of these marketing schemes is necessary to prevent future breaches of this scale.

Without regulation companies will not learn from this incident and we will see more and more of these attacks in the future.

Final Thoughts: Why We Need Both

Neither regulation nor cybersecurity alone is enough. If we truly want to stop the next Co-op style breach, we need both a stronger technical foundation and better rules about what data is collected in the first place.

Cybersecurity helps to contain the fire. Regulation helps stop companies from stacking flammable material in the middle of the room.

We need:

  • Regulation to set limits on what customer data is collected and stored.

  • Cybersecurity investment to ensure that what is collected is protected properly.

Without this two-pronged approach, incidents like the Co-op hack will continue to happen.

Authors Note

This piece reflects my own views and opinions and should not be taken as definitive fact.

If you found this article interesting please consider subscribing or sharing it with others. Thank you for reading, your support means a lot.

No posts

Read the original on getcyberinsights.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.