Anubis Ransomware Gang Claims Responsibility for Coca-Cola Fairlife Attack, Threatens Data Leak
In a high-stakes cyberattack, the Anubis ransomware gang has claimed responsibility for breaching Coca-Cola’s Fairlife dairy subsidiary, leaving behind a trail of encrypted files and allegedly stolen corporate data. The attackers have threatened to publish this sensitive information unless the company pays a hefty ransom.
Fairlife is one of Coca-Cola’s most popular dairy brands, producing ultra-filtered milk products, protein shakes, and nutrition drinks sold across the United States. But on July 16th, the company was forced to shut down production at its US facilities due to a ransomware attack, which allowed attackers to gain unauthorized access to Fairlife’s systems. While Coca-Cola initially kept quiet about whether data was stolen or whether it had received an extortion demand, the Anubis gang has since come forward, claiming responsibility for the attack and alleging that they stole approximately one terabyte of corporate data.
According to the ransomware gang, they attacked Fairlife roughly a week before publicly disclosing the incident. In this time, they claimed to have encrypted the company’s Nutanix infrastructure and stolen sensitive files. “We attacked their systems a week ago,” Anubis alleged in an interview with BleepingComputer. “Just a few days later, they immediately reported the incident without attempting to follow the instructions we left on their network.” The gang also claimed that publishing the stolen data would make it impossible for Fairlife to recover without their encryption key.
The Anubis ransomware operation has been making waves in the cybersecurity community since its emergence in December 2024. As a ransomware-as-a-service (RaaS) gang, they combine data theft with file encryption and use stolen information as leverage to pressure victims into paying a hefty ransom. Last year, the gang added a particularly nasty tool to their arsenal – a data wiper that destroys victim files, making recovery impossible.
While BleepingComputer was unable to verify Anubis’ claims regarding the alleged data theft or encryption of Fairlife’s systems, one thing is clear: this attack highlights the growing threat posed by ransomware gangs like Anubis. These groups are becoming increasingly sophisticated in their tactics and targeting organizations worldwide across multiple industries.
As a security-aware reader, it’s essential to take note of these attacks and understand how they work. In essence, ransomware gangs like Anubis infect an organization’s systems with malware that encrypts files and demands a ransom in exchange for the decryption key. They often combine this with data theft, which gives them leverage to pressure victims into paying up. To protect yourself or your organization from these threats, it’s crucial to stay vigilant and invest in robust cybersecurity measures, including regular backups and penetration testing.
In the face of such attacks, it’s essential to remember that prevention is key. By staying one step ahead of attackers, we can prevent breaches like this one from happening in the first place. So, what can you do? First, ensure your organization has a solid incident response plan in place. Second, invest in robust cybersecurity measures that include regular backups and penetration testing. And finally, stay informed about emerging threats and tactics used by ransomware gangs like Anubis. By doing so, we can all play a role in mitigating the impact of these attacks and keeping our digital environments safe from harm.
Source: Bleeping Computer — 2026-07-21