
The ransomware attack against Fairlife, Coca-Cola’s premium dairy subsidiary, is another reminder that ransomware has evolved beyond IT disruptions. The attack temporarily halted production across Fairlife’s U.S. manufacturing facilities, demonstrating how cyber incidents can directly impact operational technology (OT), supply chains, and business continuity. Days later, the Anubis ransomware group publicly claimed responsibility, alleging it stole 1 TB of corporate data and encrypted critical systems. Coca-Cola has confirmed the ransomware incident and production disruption but has not verified the group’s claims regarding data theft or the volume allegedly exfiltrated.
Incident Timeline
July 16, 2026
Coca-Cola disclosed that Fairlife detected unauthorized access involving a ransomware event affecting portions of its environment, including production-related systems. The company activated incident response procedures, engaged external cybersecurity experts, notified law enforcement, and suspended U.S. production as a precaution. Canadian operations continued normally, and the company stated that product quality and safety were unaffected.
July 21, 2026
The Anubis ransomware group listed Fairlife on its dark web leak site, claiming responsibility for the attack. The group alleged that it:
- Stole approximately 1 TB of data
- Encrypted Fairlife’s infrastructure
- Would publish the stolen data if ransom negotiations were not initiated
These claims remain unverified by Coca-Cola.
Why This Attack Matters
Unlike many ransomware incidents that primarily impact office IT systems, this attack affected systems associated with manufacturing operations.
The immediate consequences included:
- Suspension of U.S. production
- Manufacturing disruption
- Potential supply chain delays
- Increased operational recovery costs
- Reputational exposure
This reinforces an important cybersecurity lesson:
Availability is often the most valuable asset in manufacturing environments.
Even without confirmed data leaks, operational downtime can result in significant financial losses.
Understanding Anubis Ransomware
Anubis emerged as a Ransomware-as-a-Service (RaaS) operation in late 2024.
Researchers describe the group as employing:
- Double-extortion tactics
- Data exfiltration before encryption
- Enterprise-wide encryption
- Aggressive negotiation pressure
- Optional destructive file-wiping capabilities that can make recovery significantly harder if enabled.
Initial Attack Chain (Likely)
Although Fairlife has not disclosed the initial access vector, ransomware operations such as Anubis commonly follow this sequence:
- Initial compromise
- Stolen credentials
- VPN compromise
- Phishing
- Exploitation of internet-facing vulnerabilities
- Privilege escalation
- Active Directory enumeration
- Lateral movement
- Credential harvesting
- Backup discovery
- Data exfiltration
- Encryption
- Ransom demand
The exact intrusion path in this incident has not been publicly confirmed.
Manufacturing OT Risk
Manufacturing organizations increasingly integrate:
- ERP
- MES
- Production planning
- Quality systems
- Industrial control environments
Even when PLCs or industrial controllers are not directly encrypted, supporting IT services can become unavailable, leading organizations to pause production for safety and operational reasons.
This incident illustrates how ransomware can disrupt production through dependencies rather than direct compromise of industrial equipment.
MITRE ATT&CK Mapping
Likely ATT&CK techniques involved in ransomware operations include:
- Initial Access
- Valid Accounts
- External Remote Services
- Command and Scripting Interpreter
- Credential Dumping
- Remote Services
- Network Share Discovery
- Data Staged
- Exfiltration Over C2 Channel
- Data Encrypted for Impact
The specific techniques used against Fairlife have not been publicly disclosed.
Business Impact Analysis
The incident affected multiple business dimensions:
Operational
- Production suspension
- Manufacturing delays
Financial
- Revenue interruption
- Incident response costs
- Recovery expenses
Cyber
- Potential confidential data exposure
- Possible intellectual property risks
Regulatory
- Disclosure obligations
- Law-enforcement coordination
Reputational
- Customer confidence
- Partner trust
Defensive Lessons
This incident highlights several strategic priorities:
- Segment IT and OT environments.
- Enforce multi-factor authentication for privileged and remote access.
- Continuously monitor identity abuse and lateral movement.
- Maintain immutable, offline backups and regularly test restoration.
- Deploy endpoint detection and response across enterprise systems.
- Harden Active Directory and remove unnecessary administrative privileges.
- Patch internet-facing infrastructure promptly.
- Exercise ransomware playbooks through tabletop and live recovery drills.
- Monitor for data exfiltration in addition to encryption activity.



