A major food and beverage company has fallen victim to a devastating data breach, with one of its dairy products subsidiaries caught in the crosshairs of a ruthless ransomware gang. Coca-Cola has confirmed that its Fairlife subsidiary was targeted by the Anubis group, resulting in the theft of sensitive data and disruption to operations.
The attack occurred when Fairlife facilities in the United States were hit with the Anubis ransomware, which encrypts files on compromised systems and exfiltrates valuable data to increase the chances of a payout. The gang’s tactics are characteristic of its “double-extortion” model, where victims are threatened with both file deletion and data release unless they pay a hefty ransom.
The exact nature and extent of the data breach remain unclear, but it is understood that Fairlife production was suspended while Coca-Cola investigated and responded to the incident. Fortunately, most production has now been resumed at the four affected facilities in the US. The company’s statement acknowledges that “certain data” was taken, but no further details have been shared.
Retail availability of Fairlife products has reportedly been unaffected due to existing inventory, and product quality and safety have not been compromised. However, the incident raises concerns about the potential impact on Coca-Cola’s financial condition or operations. As a major multinational corporation, the company will undoubtedly face scrutiny over its cybersecurity measures and response to this breach.
The Anubis group has been active since December 2024 and has listed around 100 targeted organizations on its website. Its tactics have caught attention in the cybersecurity community due to a “wiper mode” feature that enables permanent file deletion and prevents recovery. This feature makes it even more challenging for victims to recover from an attack.
The fact that Anubis is now threatening to release stolen data, unless a ransom is paid within two hours, adds urgency to this situation. While the gang often exaggerates the importance of files they have stolen in order to put pressure on their targets, the potential consequences for Coca-Cola and Fairlife are severe. This breach serves as a reminder that no organization is immune to cyber threats, and the importance of robust cybersecurity measures cannot be overstated.
In light of this incident, businesses would do well to review their security protocols and ensure they have adequate measures in place to detect and respond to similar attacks. Regular backups, employee education on cybersecurity best practices, and investment in robust threat detection tools can go a long way in mitigating the impact of such incidents.
Source: SecurityWeek — 2026-07-27