The Coca-Cola Company disclosed in an SEC filing that a ransomware attack hit systems at its wholly owned dairy subsidiary Fairlife, giving attackers unauthorized access to part of the company’s environment, including production-related systems. The incident forced Fairlife to temporarily suspend production of its products across U.S. facilities, while the company said Canadian operations were not affected and that product quality and safety were not impacted.
Coca-Cola said it activated incident response and business continuity procedures, engaged outside advisors and cybersecurity experts, and notified law enforcement as it investigates the full scope and business impact of the breach. The company has not said whether data was stolen, whether an extortion demand was made, or when U.S. production will resume, and no ransomware group had publicly claimed responsibility at the time of reporting.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
The Anubis ransomware gang publicly claimed responsibility for the Fairlife attack and threatened to publish allegedly stolen data unless the company negotiates. The group also alleged it encrypted Fairlife's Nutanix infrastructure and stole about 1 TB of corporate data, though those claims were not independently verified.
A new report attributed the ransomware attack affecting Fairlife/Coca-Cola to the Anubis threat group and characterized the incident as a ransomware-linked data breach. This adds threat actor attribution not present in the existing timeline.
In a July 16 SEC filing, Coca-Cola publicly disclosed the ransomware attack affecting its Fairlife subsidiary and said it had activated incident response and business continuity protocols. The company also said law enforcement had been notified and outside advisors were assisting the investigation.
Following the ransomware incident, Fairlife temporarily suspended production operations at its U.S. facilities. Coca-Cola said Canadian production was unaffected and product quality and safety were not impacted.
Coca-Cola disclosed that a ransomware attack resulted in unauthorized access to a portion of Fairlife's systems, including production-related systems. The company said the full scope and impact were still under investigation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
21 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcesecurityweek.com
Open sourceteiss.co.uk
Open sourcethecyberthrone.in
Open sourcesec.gov
Open sourcesec.gov
Open sourcetechcrunch.com
Open sourceinvestors.coca-colacompany.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.