Coca-Cola confirmed that a ransomware attack on its dairy subsidiary Fairlife led to a data breach and temporary production disruption at four U.S. facilities. The company had disclosed the cybersecurity incident in a July 16 SEC filing after suspending some operations, and later said most production had resumed while restoration work continued. Coca-Cola reported the intrusion to authorities and said retail availability, product quality, and safety were largely unaffected, with no expected material impact on its financial condition or operating results.
The Anubis ransomware group claimed responsibility, alleging it stole 1 TB of confidential data and encrypted Fairlife systems, including claimed access to Nutanix infrastructure. After listing Coca-Cola and Fairlife on its leak site, the gang reportedly released the stolen files when its countdown expired. Anubis, a double-extortion operation active since late 2024, is also known for a wiper-mode capability that can permanently delete victim files; Coca-Cola said it did not negotiate with the attackers.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Coca-Cola confirmed that the ransomware attack on Fairlife resulted in data theft, said it had reported the intrusion to authorities, and stated it did not negotiate with the attackers.
Coca-Cola later stated that most production at Fairlife's four U.S. facilities had resumed, though some systems and operations were still being restored.
The references describe Anubis as a double-extortion ransomware group that has been active since December 2024 and note it is known for a wiper-mode capability that can permanently delete victims' files.
After the Anubis leak-site timer expired, the data the gang claimed to have stolen from Fairlife was made available for download.
On July 20, 2026, the Anubis ransomware group claimed responsibility for the attack by posting Coca-Cola and Fairlife on its leak site and alleging it had stolen 1 TB of confidential data in addition to encrypting systems.
On July 16, 2026, Coca-Cola disclosed in an SEC filing that a cybersecurity intrusion affecting its Fairlife dairy subsidiary had led to suspended production at Fairlife facilities in the United States while the company responded to the incident.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
8 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcetechrepublic.com
Open sourcexakep.ru
Open sourcehelpnetsecurity.com
Open sourcehookphish.com
Open sourcesecurityweek.com
Open sourceinvestors.coca-colacompany.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.