Coca-Cola disclosed that its dairy subsidiary Fairlife suffered a ransomware-related cyber incident that led to data theft and temporary production outages across its four U.S. facilities. Fairlife identified unauthorized third-party access on July 16 and, according to a U.S. SEC filing, activated incident response and business continuity measures while Coca-Cola brought in external cybersecurity specialists. The intrusion affected parts of Fairlife’s network, including production-related systems, forcing a temporary shutdown of U.S. production operations.
The Anubis ransomware group claimed responsibility, with reports attributing to it the theft of between 671GB and 1TB of data, including HR records, engineering and technical documentation, and production data, though Coca-Cola did not confirm the attackers’ figures. Most production was later restored, retail availability was largely maintained through existing inventory, and Fairlife said product quality and safety were not affected. Coca-Cola also said it did not expect the incident to have a material financial impact, while the breach underscored how ransomware is increasingly disrupting operational technology and physical manufacturing processes as well as stealing data.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
Coca-Cola said that by July 27, Fairlife had resumed the majority of production at its four U.S. facilities. The company also said retail availability was largely unaffected and product quality and safety were not impacted.
Fairlife identified unauthorized third-party access to part of its systems on July 16. Coca-Cola said the company activated incident response and business continuity measures, engaged external experts, and temporarily shut down U.S. production at Fairlife facilities.
Coca-Cola disclosed the Fairlife ransomware-related incident in a U.S. SEC Form 8-K, stating that the breach involved unauthorized access, data theft, and temporary production outages. The filing said the company did not expect the incident to have a material financial impact.
Screenshots posted to X indicated that the Anubis ransomware group claimed responsibility for the Fairlife incident. Anubis alleged it stole Fairlife data and threatened or claimed to publish it, though Coca-Cola did not confirm the group's data-theft claims.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.