Coca-Cola's Fairlife Dairy Production Halted by Ransomware Attack
Coca-Cola disclosed that a ransomware attack on its Fairlife dairy subsidiary has disrupted US production, temporarily suspending operations and raising concerns about food supply chain security.

The Coca-Cola Company has announced that a significant ransomware attack has impacted its Fairlife dairy subsidiary, leading to a temporary halt in production across all of its U.S. facilities. The incident, detailed in a Form 8-K filing with the U.S. Securities and Exchange Commission (SEC), involved unauthorized access to Fairlife's systems, including those critical for production.
Upon detecting the intrusion, Fairlife promptly initiated its incident response and business continuity protocols. The company is currently engaged in an ongoing investigation with the assistance of external cybersecurity experts to fully assess the scope and impact of the attack. Law enforcement agencies have also been notified.
While Coca-Cola has assured that product quality and safety have not been compromised, the operational disruption is substantial. Production has been temporarily suspended to allow the company to manage the incident and restore affected systems. Notably, Canadian production operations for Fairlife remain unaffected by this cyberattack.
The full extent of the incident's impact on Coca-Cola's overall business operations is still under investigation. The company has not yet determined if the cyberattack is reasonably likely to materially affect its financial performance. This uncertainty underscores the potential for significant business disruption even when direct data theft or extortion demands are not immediately apparent.
Fairlife, a prominent dairy brand under the Coca-Cola umbrella, specializes in ultra-filtered milk products, protein shakes, and nutrition drinks. Its product lines include well-known brands such as Ultra-Filtered Milk and Core Power Protein Shakes, which are widely distributed throughout the United States.
At present, Coca-Cola has not disclosed whether any sensitive data was exfiltrated during the attack, nor has any ransomware group claimed responsibility. The absence of a public claim could indicate that the attackers are still assessing stolen data for extortion purposes or that they intend to remain anonymous. Such attacks often lead to subsequent ransom demands if valuable data is confirmed to have been compromised.
This incident highlights the growing vulnerability of critical food and beverage supply chains to sophisticated cyber threats. The disruption at Fairlife serves as a stark reminder that ransomware attacks can have far-reaching consequences, impacting not only corporate operations but also the availability of essential consumer goods.
Cybersecurity experts are closely monitoring the situation for further developments, including potential attribution to specific ransomware gangs and any subsequent ransom demands. The lack of immediate disclosure regarding data theft or extortion leaves a degree of uncertainty, but the operational halt itself represents a significant blow to the brand and its production capabilities.
The article provides further details on the ransomware attack impacting Coca-Cola's Fairlife subsidiary, confirming that production has been suspended at US facilities. While the specific ransomware strain and threat actor remain undisclosed, the company has notified law enforcement and is working with cybersecurity experts to assess the full scope and impact. Fairlife's Canadian operations are unaffected, and product quality and safety have not been compromised.
The new article provides further details on the incident, including Coca-Cola's disclosure via an SEC filing on July 16, 2026. It confirms that while product quality and safety remain unaffected, US milk production is temporarily suspended, though Canadian operations are reportedly continuing. Coca-Cola has activated its incident response plans and engaged external cybersecurity experts and law enforcement, but the full scope and impact of the attack are not yet known.
The cyber incident impacting Fairlife's U.S. production facilities has been identified as a ransomware attack. While the full scope and the specific ransomware group responsible remain undisclosed, Coca-Cola confirmed that product quality and safety have not been affected, and operations in Canada were not impacted. Law enforcement has been notified as an internal investigation continues.
The ransomware attack on Coca-Cola-owned Fairlife has led to a temporary halt in production across all United States facilities, as confirmed by a recent SEC filing. While Canadian operations remain unaffected, the incident highlights the critical integration of IT and OT systems in manufacturing and the potential for widespread disruption. The company is actively investigating with cybersecurity experts and has notified law enforcement, though the specific strain of ransomware and whether data exfiltration occurred are still under assessment.
The Anubis ransomware group has claimed responsibility for the attack on Coca-Cola's Fairlife subsidiary, threatening to leak approximately one terabyte of stolen corporate data if a ransom is not paid. Anubis alleges they attacked Fairlife a week before the public disclosure and encrypted the company's Nutanix infrastructure, though BleepingComputer could not independently verify these claims.
The Anubis ransomware group has claimed responsibility for the attack on Coca-Cola's Fairlife subsidiary and is now threatening to leak approximately 1 TB of exfiltrated confidential data if a ransom is not paid within a week. This development escalates the incident beyond a production disruption to a potential data breach, adding a double-extortion tactic to the already disclosed ransomware attack.
The Anubis ransomware gang has claimed responsibility for the attack on Fairlife, stating they exfiltrated 1 terabyte of data and are demanding a ransom. The gang has set a deadline for negotiations and is threatening to leak the stolen data, which includes production-related systems, unless their demands are met. Anubis, a Russian-speaking ransomware-as-a-service operation, has been active since late 2024 and is known for its dual execution model that includes an optional destructive wipe mode.
Coca-Cola has now confirmed that the ransomware attack on its subsidiary, Fairlife, resulted in a data breach. The Anubis ransomware group claimed responsibility, stating they exfiltrated 1TB of data and threatened to leak it. While production has largely resumed and product quality is unaffected, the company acknowledges that certain data was taken, though the full scope remains under investigation.
Coca-Cola has now confirmed that the Anubis ransomware gang not only encrypted Nutanix systems at its Fairlife subsidiary but also exfiltrated data, which has since been released by the attackers. The company stated that while production was temporarily suspended, most operations have resumed, and product quality and safety were not compromised. Coca-Cola also confirmed it did not negotiate with the attackers.
Coca-Cola has now confirmed that the ransomware attack on its subsidiary Fairlife also involved the theft of company data, in addition to the production disruptions previously reported. The Anubis ransomware group claimed to have stolen 1 terabyte of data and threatened to leak it unless negotiations were entered, though Coca-Cola has not confirmed the volume or nature of any stolen data.
The ransomware group Anubis has claimed responsibility for the attack, stating they exfiltrated 671GB of data including HR records, engineering documentation, and production data, which they have since leaked. While Coca-Cola downplayed the long-term impact, experts warn that the stolen internal business data could be used for future targeted attacks, impersonation, or payment redirection.