The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola’s Fairlife dairy subsidiary, threatening to publish allegedly stolen corporate data unless the company pays a ransom.
Fairlife is one of Coca-Cola’s dairy brands and produces a range of ultra-filtered milk products, protein shakes, and nutrition drinks sold throughout the United States. The company’s product lineup includes Ultra-Filtered Milk, Core Power Protein Shakes, and Nutrition Plan.
On July 16, The Coca-Cola Company disclosed that a ransomware attack had disrupted Fairlife’s operations, forcing the company to suspend production at its U.S. facilities.
The company said attackers gained unauthorized access to a portion of Fairlife’s systems, including production-related systems, prompting it to activate its incident response and business continuity plans. Coca-Cola also said product quality and safety were not affected and that Canadian production operations continued as normal.
At the time, Coca-Cola had not disclosed whether data was stolen, whether it had received an extortion demand, or which ransomware operation was responsible for the attack.
On Monday, the Anubis ransomware gang added Fairlife to its dark web data leak site, claiming responsibility for the attack and alleging it stole approximately one terabyte of corporate data. The ransomware gang warned it would publish the stolen data unless the company enters negotiations by the end of the week.
The ransomware gang claimed it attacked Fairlife roughly a week before the company publicly disclosed the incident and encrypted the company’s Nutanix infrastructure.
“We attacked their systems a week ago. Just a few days later, they immediately reported the incident without attempting to follow the instructions we left on their network,” Anubis claimed to BleepingComputer.
“We have fully encrypted their Nutanix systems. They have no chance of recovering without our encryption key.”
The ransomware gang also claimed to have stolen 1 TB of corporate data during the attack.
BleepingComputer could not independently verify the gang’s claims regarding the alleged theft of data, the encryption of Fairlife’s systems, or the amount of data purportedly stolen.
When contacted about these claims, Coca-Cola declined to comment.
Anubis is a ransomware-as-a-service (RaaS) operation that emerged in December 2024 and has since targeted organizations worldwide across multiple industries.
The operation is known for combining data theft with file encryption and using stolen information as leverage to pressure victims into paying a ransom.
Last year, Anubis added a data wiper to its arsenal that destroys the victim’s files to make recovery impossible.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Coca-Cola says Fairlife ransomware attack halts US dairy production
Ukrainian national pleads guilty to role in Conti ransomware operation
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
JadePuffer agentic attacks now target AI model data with ransomware
JadePuffer ransomware used AI agent to automate entire attack
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
Hugging Face warns an autonomous AI agent hacked its network
Critical ServiceNow code execution flaw now exploited in attacks
Calculate what you’d save by replacing your MDR.
Privacy by policy or privacy by architecture? See how age checks work when the face never leaves the device.
See how Pixellot discovered and secured hundreds of unmanaged AI agent identities in weeks, not months. Read the case study.
Pentest your web apps on-demand. Find what humans miss. Scope and launch a pentest in minutes.
Overdue a password health-check? Audit your Active Directory for free
Do you have what it takes to challenge DARKROOM? Signup for an exclusive DEFCON CTF!
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.



