CiberLATAMbywhalemate

Fairlife Halts Production After Anubis Ransomware

Coca-Cola confirmed a Fairlife attack that suspended U.S. production and led to a data breach. Anubis claimed the intrusion.

Whalemate Labs · AI-assisted researchPublished:3 min read

Coca-Cola said on July 16 that Fairlife, its dairy subsidiary, suffered a cyber incident after an unauthorized third party accessed part of its systems, including production-related environments. U.S. operations were temporarily suspended, while Canada was not affected.

Coca-Cola disclosed a cybersecurity incident at Fairlife, its dairy subsidiary, on July 16, 2026, after detecting that an unauthorized third party had accessed part of its systems, including environments tied to production.

U.S. production impacted

In its statement and the Form 8-K filed with the SEC that same day, the company described the incident as a ransomware event. As a result, Fairlife production operations in the United States were temporarily suspended. Coca-Cola also said operations in Canada were not affected.

The company added that Fairlife product quality and safety had not been compromised. According to the statement cited by AL.com, law enforcement was notified and an internal investigation was launched after the attack was detected.

Anubis claims responsibility

Around July 20, the Anubis ransomware group added Coca-Cola and Fairlife to its dark web leak site and claimed responsibility for the attack. The group said it had encrypted files on compromised systems and, according to multiple reports, claimed to have stolen about 1 terabyte of confidential data. Coca-Cola did not independently verify that figure.

Other threat intelligence sources said Anubis claimed to have encrypted the Nutanix infrastructure Fairlife used for its U.S. production operations and that the company would not be able to recover its systems without the group’s decryption key. Reports also said the deadline set for negotiations or ransom payment was about a week, although the amount was not made public.

Data breach and partial restoration

Specialized media reported on July 22 that the attack had forced a halt to Fairlife milk production in the United States, while retail supply remained largely stable thanks to existing inventory. On July 27, Coca-Cola publicly confirmed that the incident had resulted in a data breach and that some information had been accessed or exfiltrated during the attack.

In that same update, the company said that, based on the information available at the time, the incident was not reasonably likely to have a material impact on its financial condition or operating results. On July 28, BleepingComputer reported that Coca-Cola explicitly confirmed the data theft, said it was still working to restore some affected systems, and said most U.S. production had already resumed.

At the same time, other reports said the timer Anubis had set for publishing the stolen data expired and that some Fairlife information was made available for download on the group’s extortion site. There were also unconfirmed reports about a possible 671 GB data leak and a claimed initial access vector tied to CitrixBleed, but those details do not appear in Coca-Cola’s official statements or in the SEC Form 8-K.

Sources

View all