← All security news

Coca-Cola's Fairlife Confirms Data Theft After Refusing to Pay Ransomware Gang

A production line icon stopped mid-conveyor next to a stack of files breaking open, representing the Anubis ransomware attack that halted US production at Coca-Cola's Fairlife dairy subsidiary and led to a terabyte of stolen data being leaked

Coca-Cola has confirmed that attackers stole data from Fairlife, its ultra-filtered milk and protein-shake subsidiary, after a ransomware group threatened to leak roughly a terabyte of files taken during the intrusion. The company first disclosed the breach to US regulators on 16 July, describing unauthorised access to part of its systems and a temporary suspension of production — its four US Fairlife plants paused output while Canadian operations continued as normal, and Coca-Cola says product safety was never affected.

The Anubis ransomware gang claimed responsibility, saying it had locked down parts of Fairlife's production infrastructure and copied roughly a terabyte of confidential data before setting a ransom deadline for the morning of 27 July. Coca-Cola brought in outside incident-response specialists, notified law enforcement, and declined to negotiate. When the deadline passed, Anubis followed through and published the stolen files — and rather than dispute the claim, Coca-Cola confirmed the theft.

What this means for your business

  • Ransomware can stop physical operations, not just steal data. Fairlife's US lines went down because the attackers reached systems tied to production, not just office files. If any part of your business depends on machinery, a production schedule, or logistics, find out whether that equipment sits on the same network as everyday IT — and if it does, that's a segmentation project worth starting now.
  • Attackers often go in through the less-hardened part of a bigger structure. Fairlife is a subsidiary, not Coca-Cola's own corporate IT estate. The same logic applies to any smaller supplier, franchise, or business unit plugged into a larger partner's systems — being small doesn't make you less of a target; it can make you the easier way in.
  • A backup that ransomware can reach and lock isn't a real backup. Encrypting production infrastructure directly is only possible when backups sit reachable on the same network they're supposed to protect. Ask whoever manages your backups whether a copy exists that's genuinely offline or otherwise isolated from anything a compromised machine could touch.
  • Decide your position on paying before you're forced to decide it in a day. Coca-Cola refused and absorbed a production disruption instead — a call that's only defensible when it's backed by a rehearsed incident-response plan, not made cold under a countdown.

None of this needs a household name to apply. The mechanics — network segmentation, backups that are actually isolated, and a plan you've walked through before you need it — cost far less to put in place ahead of time than to explain afterwards.

Questions about your own setup? contact@techleetsolutions.com
Sources: BleepingComputer, SecurityWeek