Coca-Cola Confirms Fairlife Data Breach After Ransomware

Coca-Cola confirmed a ransomware attack at its Fairlife dairy unit caused a data breach and briefly halted production at U.S. Fairlife plants during the investigation.

Coca-Cola confirmed a ransomware attack on its Fairlife dairy subsidiary resulted in a data breach and briefly halted production at Fairlife facilities in the United States while the company investigated.

The company first disclosed the cybersecurity incident on July 16, announcing it had suspended production at Fairlife plants while responding to and investigating the intrusion. On July 20 the Anubis ransomware group listed Coca-Cola and Fairlife on its leak site, claiming to have encrypted systems and to have stolen about 1 terabyte of data. In a statement released Monday, Coca-Cola confirmed the incident involved “the taking of certain data” and said a majority of production has since resumed at the four U.S. Fairlife facilities.

The company stated retail availability of Fairlife products has been largely unaffected because of existing inventory and confirmed product quality and safety were not impacted. The statement also noted, “Based on the information currently available, the company believes the incident has not had, and is not reasonably likely to have, a material impact on the company’s financial condition or results of operations.”

A countdown timer on Anubis’s leak site showed the stolen files would be made public within hours unless a ransom is paid. Coca-Cola has not confirmed the volume or contents of the files the group claims to hold.

Security researchers tracking Anubis report the group has been active since December 2024 and has listed roughly 100 targets. The group uses a double-extortion model that combines encrypting victims’ systems with exfiltrating data. Researchers have also warned Anubis can operate in a “wiper mode” that permanently deletes files and makes recovery difficult.

Coca-Cola did not disclose how the initial intrusion occurred, which specific systems were affected, or whether any customer, employee or supplier information was exposed. The company is continuing its investigation and restoring operations at the Fairlife facilities and has not provided a timeline for completing the probe or notifying potentially affected parties.

Articles by this author