Skip to content

fairlife ransomware production disruption

Summary

fairlife logo

Coca-Cola confirmed that ransomware caused unauthorized access, data theft and a temporary suspension of fairlife production in the United States. Most production resumed July 27 while restoration continued, and no later operational impact was documented by August 26. Anubis claimed it released engineering, production and HR material, but Coca-Cola has not verified the actor, alleged files, claimed encryption scope or one-terabyte volume.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

  • Unauthorized access

    Unauthorized access to systems, accounts, networks, or data.

Data impacts

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

Operational impacts

Extortion indicators

  • Encryption-based extortion

    The extortion activity involved unauthorized encryption of systems or data, with restoration or decryption conditioned on payment.

  • Data-theft extortion

    The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.

  • Public leak threat

    The actor explicitly threatened to publish or publicly release victim data or incident details.

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

  • Full data publication

    The actor published or released a substantial or complete set of allegedly stolen victim data.

  • Countdown or payment deadline

    The actor imposed a deadline or public countdown before increasing the demand, publishing data, deleting keys, or taking another threatened action.

Incident narrative

Analyst assessment

fairlife temporarily suspended U.S. production after identifying unauthorized third-party access to part of its systems, including production-related infrastructure. Coca-Cola’s Form 8-K and fairlife’s initial notice connected the access to a ransomware event and said the company activated incident-response and business-continuity procedures, engaged outside specialists and notified law enforcement.

Coca-Cola’s July 27 update confirmed that the intruder took certain data. The company said most production had resumed across four U.S. facilities while restoration continued. DysruptionHub assesses with high confidence that the incident involved ransomware, material production disruption and data theft.

Anubis claimed responsibility, alleging that it encrypted fairlife’s Nutanix infrastructure, stole about 1 TB of corporate data and would publish the material unless negotiations began by a July 27 deadline. The Atlanta Business Chronicle later reported that the group claimed to have released engineering, production and human-resources material. Coca-Cola has not corroborated the actor, claimed encryption scope, data volume or publication.

Operational significance

The incident interrupted fairlife’s U.S. manufacturing footprint for ultra-filtered milk and protein beverages. Canadian production and product quality and safety were unaffected. Coca-Cola said existing inventory largely protected retail availability and that the event was not expected to materially affect its financial condition or results.

The resumption of most production substantially reduced the disruption but was not a complete all-clear. The company continued restoring impacted systems and operations and did not identify which production capabilities remained limited.

Disclosure posture

Coca-Cola directly established ransomware, unauthorized access, data theft, the production suspension and partial operational recovery through an SEC filing and fairlife-hosted statements. The disclosures do not identify an actor, ransom demand, affected data categories, record count, notification population or final recovery date.

The Anubis publication claim and related civil allegations increase the significance of unresolved data-exposure questions but do not authenticate the alleged files or establish that they came from the confirmed theft.

Current status

The incident is presumed resolved. Coca-Cola’s July 27 statement remains the latest authoritative operational update and said most production had resumed while restoration of impacted systems and operations continued. No later source documented continuing production or service-delivery impact by Aug. 26, 30 days after the last confirmed impact observation. The status does not establish a precise full-restoration date or the conclusion of the investigation.

Confidence and uncertainty

Cyber, ransomware and operational-impact confidence are high because Coca-Cola directly confirmed the ransomware connection, unauthorized access, production suspension and partial recovery. Data theft is also confirmed, but its categories and scale remain unresolved.

Threat-actor confidence remains low. Anubis made a specific claim consistent with the confirmed event and later claimed to release data, but Coca-Cola did not corroborate the actor and the reviewed reporting did not independently authenticate the alleged files, Nutanix encryption or one-terabyte volume.

Analytic gaps

The public record does not establish when malicious activity began, the initial-access vector, exploited vulnerability, compromised account, dwell time, malware build, affected hosts, backup impact or whether operational technology was directly compromised. It also does not establish the verified contents of the stolen or allegedly published data, the number of affected people or records, notification obligations, ransom amount, payment decision, fourth impacted facility represented in the official count, full restoration date or final investigative findings.

Threat actor and claim

Listed as: Fairlife / Coca-ColaSource: ransomware.livePublished: Discovered:

Claim details

Anubis initially claimed it encrypted fairlife’s Nutanix infrastructure, stole about 1 TB of corporate data and would publish the data unless negotiations began by a July 27 deadline. The Atlanta Business Chronicle later reported that the group was claiming to have released engineering, production and HR material, with alleged files including driver’s-license and salary information. Coca-Cola confirmed that some data was taken but has not verified Anubis attribution, the alleged publication, file authenticity, encryption scope or data volume.

Screenshot documenting Anubis claim

Organizations involved

Impacted locations

Sources

Fairlife ransomware attack halts U.S. production

Coca-Cola said fairlife temporarily suspended U.S. production after unauthorized third-party access affected systems including production-related infrastructure. Product safety and quality were unaffected, Canadian production continued, and the full scope remained under investigation.

Coca-Cola says fairlife halts US production after cyber attack

Reuters reported that Coca-Cola confirmed unauthorized access to fairlife systems, including production-related systems, and temporarily suspended U.S. production while restoring affected operations. Canadian facilities remained operational and law enforcement was notified.

The Coca-Cola Company Announces Technology Disruption Involving fairlife Operations

Coca-Cola said fairlife identified unauthorized third-party access to systems including production-related systems in connection with ransomware, activated response and continuity protocols, notified law enforcement and temporarily suspended U.S. production. Product safety and Canadian production were unaffected, and the full scope remained unknown.

The Coca-Cola Company Form 8-K: fairlife ransomware event

Coca-Cola’s Form 8-K said fairlife identified unauthorized access to systems including production-related systems in connection with ransomware. U.S. production was temporarily suspended, Canada was unaffected, product safety was unaffected and the company had not determined the full scope or materiality.

Fairlife pauses US production after cyberattack breached systems

The Associated Press reported that Coca-Cola described unauthorized access to fairlife systems as connected to a ransomware event and confirmed temporary suspension of U.S. production. Product quality and safety were not affected.

Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak

BleepingComputer observed Anubis list Fairlife and claim it encrypted Nutanix infrastructure, stole about 1 TB of corporate data and would publish it unless negotiations began by the deadline. The outlet could not verify the attribution, encryption or theft, and Coca-Cola declined to comment.

Hackers claim attack on Coca-Cola's Fairlife, threaten to leak data

AJC observed Anubis claim responsibility, server encryption and possession of 1 TB of confidential data with a July 27 deadline, while noting that the group posted no proof. The report said all four U.S. manufacturing plants had been shut and recovery timing remained unclear.

The Coca-Cola Company Announces Significant Progress in Restoring fairlife Operations Following Technology Disruption

Coca-Cola said fairlife resumed the majority of production at its four U.S. facilities. It confirmed that the ransomware event involved unauthorized access and the taking of certain data, said restoration of impacted systems and operations continued, and reported that retail availability and product safety were largely unaffected.

Hacking group claims to leak Coke data as former Fairlife employee files suit

The Atlanta Business Chronicle reported that the hacking group claiming responsibility for the fairlife incident was now claiming to have released confidential engineering, production and human-resources data. It said the alleged files included driver’s-license and salary information and that a former employee filed suit claiming Coca-Cola failed to protect sensitive data.

See something that needs correction?

Signed-in members can report an error, update, or missing source.