Coca-Cola Confirms Data Theft in Fairlife Ransomware Attack, Production Mostly Resumed
A ransomware attack on Coca-Cola’s dairy subsidiary, Fairlife, has resulted in the theft of sensitive data, the company confirmed yesterday. The cyberattack, which was first disclosed by the global beverages giant earlier this month, disrupted production operations at Fairlife’s four US facilities, but most have since resumed. The affected company produces ultra-filtered milk, protein shakes, and nutritional drinks, with annual retail sales exceeding $1 billion.
The attack is attributed to the Anubis ransomware gang, which claimed responsibility for the incident on its extortion site and threatened to leak over one terabyte of allegedly stolen files unless a ransom was paid. The hackers reportedly encrypted Fairlife’s Nutanix systems, making recovery impossible without a decryption key. However, it appears that Coca-Cola did not engage with the attackers or pay the demanded ransom.
The Anubis gang’s threat to release the stolen data has now expired, and the compromised files are available for download. While this may seem like a significant development, experts note that the true extent of the damage remains unclear. The attackers’ claims are unsubstantiated, and it is uncertain what type of sensitive information was actually accessed or exfiltrated.
The incident highlights the ongoing threat posed by ransomware attacks, which can have far-reaching consequences for businesses and consumers alike. Ransomware gangs often target companies with robust security measures in place, exploiting vulnerabilities in software or human error to gain access to sensitive systems. In this case, Fairlife’s production facilities were brought to a standstill, causing temporary shortages and disrupting the supply chain.
Fortunately, Coca-Cola was able to mitigate the impact of the attack through existing inventory management practices and by prioritizing product quality and safety. The company’s swift response to the incident, including reporting the breach to authorities, is also commendable. However, the fact remains that sensitive data was compromised, raising concerns about potential future consequences.
For businesses and individuals, this incident serves as a stark reminder of the importance of robust cybersecurity measures. Regularly testing systems and processes can help identify vulnerabilities before attackers do. This is especially crucial for companies with critical infrastructure or sensitive customer data. By prioritizing security and staying vigilant, organizations can minimize the risk of falling victim to similar attacks in the future.
In light of this incident, it’s essential to emphasize the importance of proactive cybersecurity measures, including regular system testing, employee education, and robust incident response planning. By doing so, businesses can better protect themselves against the ever-evolving threat landscape and mitigate the potential consequences of a ransomware attack.
Source: Bleeping Computer — 2026-07-27