Cyber Incident Victim: Coop Värmland ekonomisk förening
Date:
Dec 2023
Location:
Sweden
Summary
Coop Värmland experienced a cyberattack disrupting card payment systems across 62 stores, marking the second such outage within a week. The attackers demanded financial extortion, which the retailer explicitly refused, though no customer data breaches were confirmed during the incident.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Coop Värmland experienced two payment system disruptions within one week in December 2023, with the most recent incident occurring on or before December 22. The retailer's card payment infrastructure became inoperable across its network, preventing customers from completing transactions. Klas Olsson, a company representative, publicly attributed the outage to a deliberate cyberattack rather than technical malfunction. Attackers deployed malware designed to disable critical payment processing systems, though the specific attack vector remained unspecified in public statements. The threat actors pursued financial extortion by demanding payment to restore system functionality, a common ransomware tactic. Coop Värmland explicitly refused to comply with monetary demands despite operational paralysis affecting all 62 stores within Värmland County.

The retailer initiated incident response procedures to isolate compromised systems and restore payment capabilities, achieving full resolution by December 22. No evidence indicated unauthorized access or exfiltration of customer personal data during the attack. Operational impacts were confined to payment processing disruptions, with no reported physical safety incidents or inventory losses. The organization maintained public transparency through direct communication with SVT Nyheter Värmland but did not disclose technical remediation steps or third-party cybersecurity involvement. This marked the second confirmed cyber incident targeting Coop Värmland's infrastructure within a seven-day period, demonstrating persistent threats against regional retail operations. Business continuity plans enabled the stores to maintain partial operations through alternative transaction methods during the outage period.
