Ransomware Attack on Fairlife: Coca-Cola Under Siege by the Anubis Group, 1 TB of Data Stolen
A ransomware attack by the Anubis group targeted Coca-Cola's Fairlife subsidiary, stealing 1 TB of data and forcing temporary production shutdowns.
Illustrative image generated with AI
Introduction
Dairy production at Fairlife, a Coca-Cola subsidiary, was abruptly halted on July 16 following a cyber intrusion. On July 20, the Anubis ransomware group claimed responsibility for the attack, stating they had encrypted systems and stolen approximately 1 TB of confidential information. Only today, July 27, 2026, Coca-Cola officially confirmed the exfiltration of "some data," without specifying the type or exact volume. Meanwhile, the threat of a full release of the files remains real, with a countdown already active on the criminal group's leak site.
Technical Analysis
The attack follows the classic double extortion pattern: after encrypting data, Anubis threatens to make it public unless a ransom is paid. Additionally, the group – active since December 2024 – has a "wiper" module capable of permanently deleting victims' files, amplifying the psychological and operational pressure on the target.
At this time, no specific technical information has been released about the entry vector, the defense tools bypassed, or the extent of internal compromise. Coca-Cola reacted by quickly halting production at its four Fairlife facilities in the United States, a containment measure that limited the malware's spread and enabled the gradual restoration of operations starting the following days.
Impact
- Operational: The production suspension, though temporary, affected the entire Fairlife supply chain. However, accumulated stockpiles cushioned the impact on retail supplies, and most lines are already back online. Coca-Cola rules out any repercussions on product quality or safety.
- Confidentiality: This is the most critical aspect. A terabyte of potentially exposed corporate data could include contracts, intellectual property, employee information, and financial details. The lack of official confirmation on the data type keeps uncertainty high.
- Financial and Reputational: The company considers the event not material to its financial condition, but the reputational damage from the brand's notoriety and the generated media attention are inevitable. Any data leak would further erode partner and consumer trust.
Mitigation
Coca-Cola's immediate response relied on activating incident response procedures: halting production to isolate systems, containing the infection, and gradually restoring operations. The company states that product safety was preserved throughout the crisis.
No indicators of compromise, patches, or specific technical solutions have been disclosed; nor is there information about restoring from backups or law enforcement involvement. The threat persists until the leak countdown is disarmed or expires.
FAQ
1. What exactly caused the Fairlife production halt?
The cyber intrusion discovered at Fairlife facilities led Coca-Cola to precautionarily suspend production on July 16 to prevent the ransomware from spreading. Lines were restarted as soon as checks and remediation were completed.
2. Did the Anubis group really steal 1 TB of data?
The group claimed to have stolen 1 TB of data and published a countdown for its release. Coca-Cola confirmed the exfiltration of "some data," but without quantifying it or confirming the amount claimed by the attackers. Therefore, the exact figure remains unverifiable at this time.
3. Are personal data of consumers or employees at risk?
It is not known, as the company has not specified the nature of the stolen data. It could be corporate documents, contracts, or employee information. In the absence of official clarification, the risk to consumers and workers cannot be ruled out.
Sources
This article is an original reworking based on the sources below.
- BleepingComputer
- SecurityWeek
- Security Affairs




