"We attacked their systems a week ago. Just a few days later, they immediately reported the incident without attempting to follow the instructions we left on their network," the Anubis ransomware gang told BleepingComputer, claiming it had encrypted Fairlife's systems and stolen roughly one terabyte of corporate data.
Anubis's public claim and the data-leak deadline
On Monday the Anubis ransomware operation added Fairlife — the dairy subsidiary of The Coca‑Cola Company — to its dark web data leak site and publicly claimed responsibility for the incident. The group said it would publish the allegedly stolen data unless Coca‑Cola "enters negotiations by the end of the week." Anubis claimed to have stolen approximately one terabyte of corporate data and to have fully encrypted Fairlife's Nutanix systems.
BleepingComputer reported the group's statements and noted it could not independently verify the claims of data theft, the amount taken, or the alleged encryption. When contacted about Anubis's assertions, Coca‑Cola declined to comment.
Coca‑Cola and Fairlife: operational impact reported July 16
On July 16 The Coca‑Cola Company disclosed that a ransomware attack had disrupted Fairlife's operations and forced the company to suspend production at its U.S. facilities. Coca‑Cola said attackers gained unauthorized access to "a portion of Fairlife's systems, including production‑related systems," prompting the company to activate incident response and business continuity plans.
The company also stated that product quality and safety were not affected and that Canadian production operations continued as normal. At the time of that disclosure, Coca‑Cola had not said whether data had been stolen, whether it had received an extortion demand, or which ransomware operation was responsible for the attack.
Technical claims: Nutanix encryption and the scale of alleged theft
Anubis specifically told BleepingComputer it had encrypted Fairlife's Nutanix infrastructure and had exfiltrated about one terabyte of corporate data. The group emphasized that, in its view, Fairlife had "no chance of recovering without our encryption key." Those claims — both the Nutanix encryption and the volume of data exfiltrated — remain unverified in the public reporting.
The gang also asserted the attack occurred roughly a week before Coca‑Cola publicly disclosed the incident, suggesting a gap between the initial intrusion and the company's disclosure date.
Anubis's operational profile: RaaS, data theft, and a destructive wiper
According to the reporting, Anubis is a ransomware‑as‑a‑service (RaaS) operation that first emerged in December 2024 and has since targeted organizations worldwide across multiple industries. The operation is described as combining data theft with file encryption and using stolen information as leverage to coerce payment.
Last year, Anubis reportedly added a data wiper to its toolkit — a destructive capability intended to permanently erase victim files and make recovery impossible. That combination — extortion through publication of stolen data together with the potential for irreversible file destruction — forms the pattern Anubis has employed in its prior attacks, per the source.
What this means for technologists, Coca‑Cola leadership, and consumers
- Technologists and security teams: The group's explicit claim of encrypting Nutanix systems and exfiltrating ~1 TB of data will focus defenders on verifying backups, assessing Nutanix environment integrity, and confirming whether data egress occurred. BleepingComputer's inability to independently validate the claims underscores the immediate need for forensic confirmation.
- Coca‑Cola leadership and operations teams: The disclosure that U.S. Fairlife production was suspended while Canadian operations continued points to an already‑activated incident response and business continuity posture. The company must weigh operational recovery against any extortion pressure, while investigators determine whether the alleged stolen data exists and what it contains.
- Consumers and retail partners: Coca‑Cola has asserted product quality and safety were not affected, and Canadian production remained normal. Still, public claims of stolen corporate data and a ransom deadline create reputational and supply‑chain questions that buyers and partners are likely to monitor closely.
The immediate factual record contains a set of competing public claims: a corporate disclosure that production was disrupted and that safety was unaffected, and a threat actor's declaration of deep access, encryption of Nutanix infrastructure, and roughly one terabyte of exfiltrated data with a near‑term publication deadline. Whether Anubis follows through on its publication threat, and whether independent forensic analysis confirms the operation's technical assertions, are the concrete next moments the reporting leaves to be resolved.
Source: BleepingComputer — "Anubis ransomware claims Coca‑Cola Fairlife attack, threatens data leak"




