Ransomware Group Threatens to Leak Fairlife Data

Anubis claims to have exfiltrated 1 TB from Coca-Cola’s Fairlife and demands payment within a week to avoid publication of the files.

On July 20 the Anubis ransomware group listed Coca-Cola and its dairy unit Fairlife on the group’s leak site, claiming the attackers had “locked” servers and exfiltrated about 1 TB of “confidential data.” The post offered to restore systems within hours if a ransom is paid and warned the files would be released after seven days if Coca-Cola did not comply.

Coca-Cola disclosed last week that Fairlife production was suspended following a ransomware incident and that the company is assessing the full impact. The company has not provided public details on the types of data taken or whether customer or employee information was affected.

Anubis has been active since December 2024 and has listed roughly 100 victims on its leak site. The group uses a double-extortion approach, encrypting files on compromised systems and removing data to increase leverage for payment.

Security researchers have identified a “wiper mode” within Anubis’s toolkit that can permanently erase files and hinder recovery efforts.

The leak site listing did not include where the stolen material is stored, the specific ransom demand, or sample files. There is no public confirmation that any data has been published.

Fairlife halted production after the incident. Coca-Cola is working to assess damage and restore operations but has not announced a timeline for when production will resume.

Anubis’s posting gives Coca-Cola seven days from the July 20 listing to meet the demand before the group says it will publish the files.

Articles by this author