Jul 28
/
Latest News
Coca-Cola Confirms Data Theft in Ransomware Attack on Fairlife
Coca-Cola has confirmed that its dairy subsidiary Fairlife suffered data theft during a ransomware attack that temporarily halted production at several U.S. facilities. Fairlife, known for its ultra-filtered milk and protein drinks and generating more than $1 billion in annual retail sales, has since restored most operations across its four manufacturing sites.
In a statement released Monday, Coca-Cola said the incident involved unauthorized access to a portion of Fairlife’s systems, the taking of certain company data, and a temporary suspension of production. The company noted that store shelves remained stocked thanks to existing inventory and emphasized that product quality and safety were not affected.
Coca-Cola disclosed the attack on July 16, 2026, in a Form 8-K filing with the U.S. Securities and Exchange Commission, confirming that ransomware disrupted Fairlife’s production operations. After detecting the breach, the company halted production, activated incident response and business continuity plans, engaged external cybersecurity specialists, and notified law enforcement.
Four days later, the Anubis ransomware group added Fairlife to its dark web leak site, claiming it had encrypted servers and stolen 1 terabyte of confidential data. The group threatened to publish the files unless negotiations began. Coca-Cola has not verified the volume or nature of any stolen data, and Anubis’s claims remain unconfirmed.
Anubis operates as a Ransomware-as-a-Service platform, allowing affiliated actors to carry out attacks involving data theft, file encryption, and optional destructive features. The group emerged in late 2024 as a rebrand of the earlier Sphinx ransomware operation, marked by a shift from the .sphinx to the .anubis file extension on encrypted files.
Coca-Cola said it does not expect the incident to have a material impact on its financial results, though restoration of affected systems is still underway.
In a statement released Monday, Coca-Cola said the incident involved unauthorized access to a portion of Fairlife’s systems, the taking of certain company data, and a temporary suspension of production. The company noted that store shelves remained stocked thanks to existing inventory and emphasized that product quality and safety were not affected.
Coca-Cola disclosed the attack on July 16, 2026, in a Form 8-K filing with the U.S. Securities and Exchange Commission, confirming that ransomware disrupted Fairlife’s production operations. After detecting the breach, the company halted production, activated incident response and business continuity plans, engaged external cybersecurity specialists, and notified law enforcement.
Four days later, the Anubis ransomware group added Fairlife to its dark web leak site, claiming it had encrypted servers and stolen 1 terabyte of confidential data. The group threatened to publish the files unless negotiations began. Coca-Cola has not verified the volume or nature of any stolen data, and Anubis’s claims remain unconfirmed.
Anubis operates as a Ransomware-as-a-Service platform, allowing affiliated actors to carry out attacks involving data theft, file encryption, and optional destructive features. The group emerged in late 2024 as a rebrand of the earlier Sphinx ransomware operation, marked by a shift from the .sphinx to the .anubis file extension on encrypted files.
Coca-Cola said it does not expect the incident to have a material impact on its financial results, though restoration of affected systems is still underway.
Executive IT Forums, Inc.
Educational Programs on Information Technology, Governance, Risk Management, & Compliance (GRC).
Our Newsletter
Get regular updates on CPE programs, news, and more.
Thank you!
Copyright © 2026 Executive IT Forums, Inc. All Rights Reserved.
Get started
Let us introduce our school
Write your awesome label here.