Ransomware Gang Halts US Production at Coca-Cola's Fairlife Dairy Brand
The Anubis ransomware group has claimed responsibility for a cyberattack that forced Coca-Cola's Fairlife dairy subsidiary to suspend production at its US facilities, and is now threatening to leak roughly 1 terabyte of stolen corporate data unless a ransom is paid.
Coca-Cola disclosed on July 16 that attackers had gained unauthorized access to a portion of Fairlife's systems, including production-related systems, prompting the company to activate its incident response plan. The breach is believed to have occurred the week before that disclosure. Fairlife's Canadian operations continued unaffected, and Coca-Cola says product quality and safety were not compromised.
Anubis listed Fairlife on its dark web leak site on July 20, claiming to have encrypted the company's infrastructure and exfiltrated the data before Coca-Cola went public with the incident. The gang says it left ransom instructions inside the network that Fairlife never engaged with, and has given the company roughly a week to pay before the stolen files are published.
Fairlife, known for Core Power protein shakes and ultra-filtered milk, generated close to $4 billion in revenue last year, making it one of Coca-Cola's fastest-growing brands. Coca-Cola's stock dipped around 4 percent following news of the breach. Neither company has confirmed the attackers' claims about the volume of data taken or whether encryption succeeded.
Anubis, active since December 2024, has hit close to 100 organizations globally and added a data-wiping capability last year that can destroy a victim's files outright, giving it a notably more destructive profile than typical ransomware-as-a-service operations. It's the second time in roughly a year a Coca-Cola-affiliated business has been targeted by ransomware; a different group claimed an attack on a Middle East bottling partner in 2025.