The Coca-Cola Company disclosed in an SEC filing that a ransomware attack hit systems at its wholly owned dairy subsidiary Fairlife, giving attackers unauthorized access to part of the company’s environment, including production-related systems. The incident forced Fairlife to temporarily suspend production of its products across U.S. facilities, while the company said Canadian operations were not affected and that product quality and safety were not impacted.
Coca-Cola said it activated incident response and business continuity procedures, engaged outside advisors and cybersecurity experts, and notified law enforcement as it investigates the full scope and business impact of the breach. The company has not said whether data was stolen, whether an extortion demand was made, or when U.S. production will resume, and no ransomware group had publicly claimed responsibility at the time of reporting.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
The Anubis ransomware gang publicly claimed responsibility for the Fairlife attack and threatened to publish allegedly stolen data unless the company negotiates. The group also alleged it encrypted Fairlife's Nutanix infrastructure and stole about 1 TB of corporate data, though those claims were not independently verified.
A new report attributed the ransomware attack affecting Fairlife/Coca-Cola to the Anubis threat group and characterized the incident as a ransomware-linked data breach. This adds threat actor attribution not present in the existing timeline.
In a July 16 SEC filing, Coca-Cola publicly disclosed the ransomware attack affecting its Fairlife subsidiary and said it had activated incident response and business continuity protocols. The company also said law enforcement had been notified and outside advisors were assisting the investigation.
Following the ransomware incident, Fairlife temporarily suspended production operations at its U.S. facilities. Coca-Cola said Canadian production was unaffected and product quality and safety were not impacted.
Coca-Cola disclosed that a ransomware attack resulted in unauthorized access to a portion of Fairlife's systems, including production-related systems. The company said the full scope and impact were still under investigation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
21 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcesecurityweek.com
Open sourcethecyberthrone.in
Open sourceteiss.co.uk
Open sourcesec.gov
Open sourcebleepingcomputer.com
Open sourceinvestors.coca-colacompany.com
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.