The Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month.
In a short statement earlier today, the global beverages giant says that it is still working to restore some of the impacted systems and operations, but most of the production in the U.S. has been resumed.
Coca-Cola disclosed the cyberattack in a filing with the U.S. Securities and Exchange Commission (SEC) on July 16, revealing that a ransomware attack had disrupted production operations at Fairlife.
Fairlife is a producer of ultra-filtered milk, protein shakes, and nutritional drinks. It operates four production facilities in the U.S., and has more than $1 billion in annual retail sales.
At the time, BleepingComputer sent a request for comments regarding the attack, but we received no reply.
A few days later, the Anubis ransomware gang claimed the attack and added Fairlife to the list of victims on its extortion site. The hacker group threatened to leak one terabyte of files allegedly stolen from the company, unless Fairlife paid a ransom.
The threat actor told BleepingComputer that they had encrypted the firm’s Nutanix systems, leaving no possibility of recovery.
As soon as Coca-Cola discovered the breach, the company reported the intrusion to the authorities and did not follow the attacker’s instructions to negotiate.
BleepingComputer contacted Coca-Cola again to validate the threat actor’s allegations, but a spokesperson declined to comment.
“The company previously disclosed that Fairlife experienced a ransomware event,” reads the Coca-Cola statement.
“This event involved access by an unauthorized third party to a portion of the company’s systems and taking of certain data, and a temporary suspension of production operations.”
Regarding Fairlife product availability, Coca-Cola says existing inventory helped cover temporary shortages caused by the production disruption, while product quality and safety were never jeopardized.
The timer that Anubis ransomware had previously set for the public release of the stolen data expired earlier today, and the data is now available for download.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak
Coca-Cola says Fairlife ransomware attack halts US dairy production
NAIC says public data stolen in ShinyHunters’ PeopleSoft breach
Ernst & Young data breach claimed by ShinyHunters extortion gang
DentaQuest data breach exposed info of 2.6 million accounts
OpenAI confirms ChatGPT is down worldwide
Malicious sites use JavaScript to build malware in browser memory
ShinyHunters data leaks fuel $2,000 sextortion email scam
Rev5 is ending. See what your FedRAMP 20x transition really requires
Your Scanners Are Green. Your Pipeline Might Not Be. Here’s How to Close the Gap.
Overdue a password health-check? Audit your Active Directory for free
AI agents can speed up ransomware attacks. See how Acronis helps reduce the risk.
Uncover shadow AI apps, agents, and risky data sharing. Get started in 5 min.
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.



