Coca-Cola has confirmed that hackers stole data during the Fairlife ransomware attack, which disrupted production at the company’s dairy subsidiary earlier this month.
The drinks giant said an unauthorised third party accessed part of Fairlife’s systems and took certain data. The incident also forced a temporary suspension of production operations.
Most US production has now resumed, although Coca-Cola says some systems and operations are still being restored.
Ransomware attack disrupted Fairlife production
Coca-Cola first disclosed the cyberattack in a filing with the US Securities and Exchange Commission on 16 July. At the time, the company said the ransomware incident had affected Fairlife’s production operations.
Fairlife makes ultra-filtered milk, protein shakes and nutritional drinks. It operates four production facilities in the United States and generates more than $1 billion in annual retail sales.
Coca-Cola said existing inventory helped cover temporary product shortages caused by the disruption. It also stressed that product quality and safety were never affected.
Anubis claimed responsibility for the attack
A few days after Coca-Cola disclosed the incident, the Anubis ransomware group listed Fairlife on its extortion site.
The group claimed it had stolen 1TB of company files and threatened to publish them unless Fairlife paid a ransom. It also alleged that it encrypted Fairlife’s Nutanix systems, leaving the company unable to recover its data.
However, Coca-Cola did not confirm the group’s technical claims or disclose the type and volume of data stolen.
The company said it reported the intrusion to authorities after discovering the breach. It also did not follow the attackers’ instructions to negotiate.
Stolen data has reportedly been published
Coca-Cola has now confirmed that the Fairlife ransomware attack involved data theft, although it has not said whose information was affected or what the stolen data contains.
The deadline set by Anubis for public disclosure of the alleged files has expired. The group has made material it claims to have taken from Fairlife available for download.
It remains unclear whether the published data is authentic, complete or connected to the confirmed breach. Coca-Cola has not commented on the release.
Recovery continues after the Fairlife ransomware attack
Fairlife’s US production has largely resumed, according to Coca-Cola. The company continues to restore the systems and operations that were affected by the attack.
The Fairlife ransomware attack shows how quickly a cyber incident can affect production at a consumer goods business. Even when companies hold enough stock to manage short-term disruption, recovery can still take time when core operational systems are compromised.


0 responses to “Fairlife Ransomware Attack: Coca-Cola Confirms Data Theft”