Skip to content

Ransomware suspends fairlife U.S. production

Summary

fairlife logo

Coca-Cola confirmed that ransomware caused unauthorized access, data theft and a temporary suspension of fairlife’s U.S. production; most production resumed July 27 while restoration continued. Anubis later claimed it released engineering, production and HR material, but Coca-Cola has not verified the actor, the alleged files, the claimed encryption scope or the one-terabyte volume.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

  • Unauthorized access

    Unauthorized access to systems, accounts, networks, or data.

Data impacts

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

Operational impacts

Extortion indicators

  • Encryption-based extortion

    The extortion activity involved unauthorized encryption of systems or data, with restoration or decryption conditioned on payment.

  • Data-theft extortion

    The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.

  • Public leak threat

    The actor explicitly threatened to publish or publicly release victim data or incident details.

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

  • Full data publication

    The actor published or released a substantial or complete set of allegedly stolen victim data.

  • Countdown or payment deadline

    The actor imposed a deadline or public countdown before increasing the demand, publishing data, deleting keys, or taking another threatened action.

Incident narrative

Analyst assessment

fairlife temporarily suspended production operations across the United States after identifying unauthorized third-party access to part of its systems, including production-related infrastructure. Coca-Cola’s Form 8-K and fairlife’s initial notice connected the access to a ransomware event and said the company activated incident-response and business-continuity procedures, engaged outside cybersecurity specialists and notified law enforcement.

Coca-Cola’s July 27 update confirmed that the intruder took certain data. The company said most production had resumed across fairlife’s four U.S. facilities, but restoration of impacted systems and operations was continuing. DysruptionHub therefore assesses with high confidence that this was a ransomware-related cyber incident involving both material operational disruption and data theft.

Anubis claimed responsibility and initially alleged that it encrypted fairlife’s Nutanix infrastructure, stole about 1 TB of corporate data and would publish the material unless negotiations began by a July 27 deadline. The Atlanta Business Chronicle later reported that the group was claiming to have released engineering, production and human-resources data; the alleged files included driver’s-license and salary information. The publication also reported that a former employee filed suit alleging that Coca-Cola failed to protect sensitive data.

These developments document a later actor claim and civil allegation, not independent authentication of the files or confirmation that Anubis was responsible. Coca-Cola’s acknowledgement that some data was taken does not verify the group’s claimed volume, encryption scope, possession of the data or publication claim.

Operational significance

The incident interrupted fairlife’s U.S. manufacturing footprint for ultra-filtered milk and protein beverages. Canadian production and product quality and safety were unaffected. Coca-Cola said existing inventory largely protected retail availability, and the company did not expect the event to materially affect its financial condition or results.

The July 27 resumption of most production substantially reduced the confirmed disruption, but it was not a complete all-clear. The company continued restoring impacted systems and operations and did not identify which production capabilities remained limited.

Disclosure posture

Coca-Cola provided direct public acknowledgement through an SEC filing and fairlife-hosted notices. The disclosures establish ransomware, unauthorized access, data theft, the production suspension and partial operational recovery. They do not identify an actor, ransom demand, affected data categories, record count, encryption finding, notification population or final recovery date.

The later lawsuit and Anubis publication claim increase the significance of unresolved data-exposure questions but do not replace an official breach notice or forensic finding. The public record does not establish whether any allegedly released file is authentic, complete or connected to the confirmed stolen data.

Current status

The latest official operational update remained Coca-Cola’s July 27 statement that most production had resumed while restoration of affected systems and operations continued. No later authoritative all-clear was located. Fourteen calendar days had elapsed by August 10, so the incident is presumed active under the operational-status lifecycle; July 27 remains the latest confirmed impact date.

Confidence and uncertainty

Cyber, ransomware and operational-impact confidence are high because Coca-Cola directly confirmed the ransomware connection, unauthorized access, production suspension and partial recovery. Data theft is also confirmed, but its categories and scale remain unresolved.

Threat-actor confidence remains low. Anubis made a specific claim consistent with the confirmed event and later claimed to release data, but Coca-Cola did not corroborate the actor and the reviewed reporting did not independently authenticate the alleged files, claimed Nutanix encryption or one-terabyte volume. A separate low-quality report asserted that Coca-Cola refused payment and that CitrixBleed 2 provided access, but no reliable incident-specific evidence reviewed here supports those statements.

Analytic gaps

The reviewed sources do not establish when malicious activity began, the initial-access vector, exploited vulnerability, compromised account, dwell time, malware build, affected hosts, backup impact or whether operational technology was directly compromised. They also do not establish the verified contents of the stolen or allegedly published data, the number of people or records affected, notification obligations, ransom amount, payment decision, full restoration date or final investigative findings.

Threat actor and claim

Listed as: Fairlife / Coca-ColaSource: ransomware.livePublished: Discovered:

Claim details

Anubis initially claimed it encrypted fairlife’s Nutanix infrastructure, stole about 1 TB of corporate data and would publish the data unless negotiations began by a July 27 deadline. The Atlanta Business Chronicle later reported that the group was claiming to have released engineering, production and HR material, with alleged files including driver’s-license and salary information. Coca-Cola confirmed that some data was taken but has not verified Anubis attribution, the alleged publication, file authenticity, encryption scope or data volume.

Screenshot documenting Anubis claim

Organizations involved

Impacted locations

Sources

Fairlife ransomware attack halts U.S. production

Coca-Cola said fairlife temporarily suspended U.S. production after unauthorized third-party access affected systems including production-related infrastructure. Product safety and quality were unaffected, Canadian production continued, and the full scope remained under investigation.

Coca-Cola says fairlife halts US production after cyber attack

Reuters reported that Coca-Cola confirmed unauthorized access to fairlife systems, including production-related systems, and temporarily suspended U.S. production while restoring affected operations. Canadian facilities remained operational and law enforcement was notified.

The Coca-Cola Company Announces Technology Disruption Involving fairlife Operations

Coca-Cola said fairlife identified unauthorized third-party access to systems including production-related systems in connection with ransomware, activated response and continuity protocols, notified law enforcement and temporarily suspended U.S. production. Product safety and Canadian production were unaffected, and the full scope remained unknown.

The Coca-Cola Company Form 8-K: fairlife ransomware event

Coca-Cola’s Form 8-K said fairlife identified unauthorized access to systems including production-related systems in connection with ransomware. U.S. production was temporarily suspended, Canada was unaffected, product safety was unaffected and the company had not determined the full scope or materiality.

Fairlife pauses US production after cyberattack breached systems

The Associated Press reported that Coca-Cola described unauthorized access to fairlife systems as connected to a ransomware event and confirmed temporary suspension of U.S. production. Product quality and safety were not affected.

Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak

BleepingComputer observed Anubis list Fairlife and claim it encrypted Nutanix infrastructure, stole about 1 TB of corporate data and would publish it unless negotiations began by the deadline. The outlet could not verify the attribution, encryption or theft, and Coca-Cola declined to comment.

Hackers claim attack on Coca-Cola's Fairlife, threaten to leak data

AJC observed Anubis claim responsibility, server encryption and possession of 1 TB of confidential data with a July 27 deadline, while noting that the group posted no proof. The report said all four U.S. manufacturing plants had been shut and recovery timing remained unclear.

The Coca-Cola Company Announces Significant Progress in Restoring fairlife Operations Following Technology Disruption

Coca-Cola said fairlife resumed the majority of production at its four U.S. facilities. It confirmed that the ransomware event involved unauthorized access and the taking of certain data, said restoration of impacted systems and operations continued, and reported that retail availability and product safety were largely unaffected.

Hacking group claims to leak Coke data as former Fairlife employee files suit

The Atlanta Business Chronicle reported that the hacking group claiming responsibility for the fairlife incident was now claiming to have released confidential engineering, production and human-resources data. It said the alleged files included driver’s-license and salary information and that a former employee filed suit claiming Coca-Cola failed to protect sensitive data.

See something that needs correction?

Signed-in members can report an error, update, or missing source.