The Anubis ransomware group claimed it compromised dairy producer Fairlife, affecting 500 hosts and stealing about 1 TB of data, according to reporting that also highlighted differences between the gang’s account and statements attributed to parent company Coca-Cola. Anubis said the intrusion was opportunistic rather than targeted, describing its method as opening “all doors with weak locks” before determining what it had accessed.
Anubis further claimed there was no real negotiation after the intrusion, saying it waited just over a week, attempted to contact the victim by telephone, and then deleted the decryption keys before starting to publish stolen data when no response arrived. The reporting underscores how quickly ransomware operators now move from intrusion to extortion and public leaks, compressing the timeline for incident response, executive decision-making, and disclosure.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
Marco De Felice's reporting, cited by both references, presented Anubis's claims about the Fairlife incident alongside Coca-Cola's statements and noted discrepancies between the two accounts.
Anubis claimed that after receiving no response to its demands, it deleted the decryption keys and started publishing stolen data from Fairlife.
According to Anubis, there was never a real negotiation with Fairlife, and the group attempted to establish contact by telephone after waiting just over a week.
Anubis said the Fairlife incident was not a targeted attack and described its method as opportunistically exploiting weakly secured environments before determining what it had accessed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.