Coca-Cola confirms data theft in Fairlife ransomware attack

Coca-Cola Confirms Data Theft in Fairlife Ransomware Attack, Production Resumes Amid Investigation

A devastating ransomware attack on Coca-Cola’s dairy subsidiary, Fairlife, has left the company scrambling to restore operations and protect its sensitive data. The global beverages giant confirmed that hackers stole data from Fairlife during a high-profile cyberattack earlier this month. While production in the U.S. has largely resumed, the company is still working to fully recover from the disruption.

Fairlife, which produces ultra-filtered milk, protein shakes, and nutritional drinks, operates four production facilities in the U.S. with annual retail sales exceeding $1 billion. The attack, attributed to the Anubis ransomware gang, began when hackers encrypted Fairlife’s Nutanix systems, making it impossible for the company to recover its data without paying a hefty ransom.

According to reports, the attackers claimed that they had stolen over one terabyte of files from Fairlife and threatened to leak them unless a ransom was paid. However, Coca-Cola refused to negotiate with the attackers, opting instead to report the breach to authorities and work on restoring its operations. The company’s statement acknowledged that “a portion” of its systems were accessed by unauthorized third parties, resulting in data theft and a temporary halt to production.

While the attack has caused significant disruptions to Fairlife’s operations, Coca-Cola assures customers that product quality and safety have not been compromised. Existing inventory helped bridge the gap during the temporary shortage, ensuring continuity for customers.

The Anubis ransomware gang’s threat to leak stolen data has yet to materialize, as a timer set by the attackers expired earlier today. However, it is essential to note that the stolen data is now available for download, and its contents are likely to be made public soon.

This incident serves as a stark reminder of the ever-present threat of ransomware attacks on businesses worldwide. As such, companies must prioritize robust cybersecurity measures to prevent similar incidents in the future.

To mitigate the risk of data breaches like Fairlife’s, security teams should test every layer of their defenses regularly. This can be achieved through breach and attack simulation (BAS) tests that validate SIEM and EDR rules to ensure they are effective in detecting threats. By doing so, companies can identify vulnerabilities before attackers exploit them, ultimately reducing the likelihood of a catastrophic data breach.

In conclusion, while Coca-Cola has largely contained the damage caused by the Fairlife ransomware attack, it serves as a wake-up call for businesses to prioritize cybersecurity and invest in robust measures to protect their sensitive data. By doing so, they can minimize the risk of similar incidents in the future and maintain customer trust.


Source: Bleeping Computer — 2026-07-27