Coca-Cola says Fairlife ransomware attack halts US dairy production

A devastating cyberattack has crippled production at Fairlife, a leading dairy brand owned by Coca-Cola. The company’s ultra-filtered milk products, protein shakes, and nutrition drinks are off the shelves across the United States as a result of the ransomware attack, which was detected in one of the subsidiary’s systems.

According to a filing with the US Securities and Exchange Commission (SEC), Fairlife’s production-related systems were compromised by unauthorized access, leading to a temporary halt in production. The company’s incident response team quickly sprang into action, activating protocols to contain the breach and assess its impact. Outside experts have been brought in to assist with the investigation.

It’s not yet clear whether any data was stolen during the attack or if an extortion demand has been made by the attackers. A spokesperson for Coca-Cola declined to comment further on these details, sticking to the company’s public statement. The lack of information from the attackers themselves means that it’s possible we’ll see more developments in this story as time goes on.

The ransomware attack is a significant blow to Fairlife’s operations, but reassuringly, product quality and safety have not been compromised. This is likely thanks to the swift response of the company’s incident response team and their ability to isolate affected systems. However, production at all US facilities has been suspended until further notice while the situation is assessed.

It’s worth noting that Canadian production operations are unaffected by the attack, suggesting that the breach was specific to Fairlife’s US-based infrastructure. As the investigation continues, Coca-Cola will be working with cybersecurity experts and law enforcement to determine the full extent of the damage and what steps need to be taken to prevent such an incident in the future.

As we often see in cases like this, it can take time for the full impact of a ransomware attack to become clear. The attackers may try to extort the company by threatening to publish sensitive data unless a ransom is paid. This could potentially lead to further disruption and reputational damage if not handled carefully.

So what can we learn from this incident? Firstly, it’s a reminder that even well-established companies with robust cybersecurity measures in place are vulnerable to attack. The fact that Fairlife was able to detect the breach quickly is a testament to the effectiveness of their security protocols, but it also highlights the importance of staying vigilant and proactive.

In practical terms, businesses can take away from this incident the need for regular testing and assessment of their systems. By regularly simulating attacks on their own networks, companies can identify vulnerabilities before they’re exploited by malicious actors. This is a crucial step in preventing similar incidents and protecting themselves against potential threats.


Source: Bleeping Computer — 2026-07-16