Menu
Browse

Cyber Incident Victim: Coop Värmland ekonomisk förening

Date:

Dec 2023

Location:

Sweden

Summary

Coop Värmland experienced a cyberattack disrupting card payment systems across 62 stores, marking the second such outage within a week. The attackers demanded financial extortion, which the retailer explicitly refused, though no customer data breaches were confirmed during the incident.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

Coop Värmland experienced two payment system disruptions within one week in December 2023, with the most recent incident occurring on or before December 22. The retailer's card payment infrastructure became inoperable across its network, preventing customers from completing transactions. Klas Olsson, a company representative, publicly attributed the outage to a deliberate cyberattack rather than technical malfunction. Attackers deployed malware designed to disable critical payment processing systems, though the specific attack vector remained unspecified in public statements. The threat actors pursued financial extortion by demanding payment to restore system functionality, a common ransomware tactic. Coop Värmland explicitly refused to comply with monetary demands despite operational paralysis affecting all 62 stores within Värmland County.

Cyber Incident Image

The retailer initiated incident response procedures to isolate compromised systems and restore payment capabilities, achieving full resolution by December 22. No evidence indicated unauthorized access or exfiltration of customer personal data during the attack. Operational impacts were confined to payment processing disruptions, with no reported physical safety incidents or inventory losses. The organization maintained public transparency through direct communication with SVT Nyheter Värmland but did not disclose technical remediation steps or third-party cybersecurity involvement. This marked the second confirmed cyber incident targeting Coop Värmland's infrastructure within a seven-day period, demonstrating persistent threats against regional retail operations. Business continuity plans enabled the stores to maintain partial operations through alternative transaction methods during the outage period.

Sources
Sources available to members
1 source