The Anubis ransomware group has claimed responsibility for the Fairlife ransomware attack. The gang alleges that it encrypted company systems and stole around 1TB of corporate data.

Fairlife is a dairy subsidiary of The Coca-Cola Company. It sells ultra-filtered milk, protein shakes, and nutrition drinks across the United States.

Coca-Cola disclosed the cyberattack on July 16. At the time, the company said the incident had disrupted Fairlife’s US production facilities. It did not identify the attackers or confirm whether they had taken data.

Production Stopped at US Facilities

The attack forced Fairlife to suspend production at its US facilities. Coca-Cola said attackers had gained unauthorised access to part of the company’s systems, including systems connected to production.

In response, the company activated its incident response and business continuity plans. It also stressed that product quality and safety remained unaffected.

Meanwhile, Fairlife’s Canadian production operations continued normally. Coca-Cola did not disclose how long the disruption would last.

Anubis Threatens to Publish Data

Anubis later listed Fairlife on its data leak site. The group claimed it had stolen about 1TB of corporate information during the attack.

It also warned that it would release the material unless Fairlife entered negotiations before the end of the week. However, the group has not provided public evidence that confirms the alleged data theft.

The attackers further claimed that they encrypted Fairlife’s Nutanix infrastructure. According to Anubis, the company cannot recover the affected systems without its decryption key.

Coca-Cola has declined to comment on the gang’s latest claims. Therefore, the alleged encryption, data theft, and amount of stolen information remain unverified.

Anubis Uses Double Extortion

Anubis operates as a ransomware-as-a-service group. It emerged in late 2024 and has targeted organisations in several industries.

The group combines file encryption with data theft. This approach lets attackers pressure victims in two ways. They can demand money for a decryption tool and threaten to publish stolen files.

Last year, Anubis reportedly added a data-wiping capability to its toolkit. A data wiper can permanently destroy files, making recovery far more difficult.

Conclusion

The Fairlife ransomware attack has already disrupted US production, although the company says its products remain safe. Anubis now claims it also stole corporate data and encrypted critical systems. Until investigators verify those claims, the full scale of the incident remains unclear.


0 responses to “Fairlife Ransomware Attack Claimed by Anubis Gang”