Skip to main content
Emerging ThreatsData Breaches

Coca-Cola Discloses Data Theft in Fairlife Ransomware Attack

Dairy production facility with stainless steel equipment and milk bottles on a conveyor belt.

"The company previously disclosed that Fairlife experienced a ransomware event," reads the Coca‑Cola statement.

Coca‑Cola acknowledges data theft at Fairlife

The Coca‑Cola Company confirmed that hackers accessed and stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month. In a brief statement released earlier today, Coca‑Cola said the incident “involved access by an unauthorized third party to a portion of the company’s systems and taking of certain data, and a temporary suspension of production operations.” The company added it is still working to restore some impacted systems and operations while noting that most U.S. production has resumed.

What Coca‑Cola disclosed to the SEC on July 16

Coca‑Cola first disclosed the cyberattack in a filing with the U.S. Securities and Exchange Commission on July 16, saying the ransomware event disrupted production operations at Fairlife. Fairlife manufactures ultra‑filtered milk, protein shakes, and nutritional drinks; the subsidiary operates four production facilities in the United States and has more than $1 billion in annual retail sales.

Anubis gang claims responsibility and posts Fairlife data

Days after the SEC filing, the Anubis ransomware gang claimed responsibility, added Fairlife to its extortion site, and threatened to publish one terabyte of files unless Fairlife paid a ransom. The group set a timer for public release; that timer expired earlier today and the data is now available for download, according to BleepingComputer’s reporting.

Allegation: Nutanix systems encrypted, “no possibility of recovery”

In communications with BleepingComputer, the threat actor said they had encrypted Fairlife’s Nutanix systems and left “no possibility of recovery.” BleepingComputer reported the claim and sought validation from Coca‑Cola; a company spokesperson declined to comment when contacted.

Company response: notified authorities, declined to negotiate

Coca‑Cola told investigators it reported the intrusion to authorities as soon as the breach was discovered and that it did not follow the attacker’s instructions to negotiate. BleepingComputer said it sought comment at multiple points during its reporting: an earlier request regarding the attack received no reply, and a later request to validate Anubis’s allegations drew a declined‑to‑comment from a Coca‑Cola spokesperson.

What this means for technologists, regulators, and consumers

  • Technologists and security teams: the public claim that Nutanix systems were encrypted and that one terabyte of files was stolen will focus attention on recovery posture, backup integrity, and the contents of the released data as teams work to restore impacted systems and validate what was taken.
  • Regulators and investors: the July 16 SEC filing formalizes the disruption and positions regulators and investors to track operational and financial fallout tied to Fairlife’s temporary suspension of production, given the brand’s scale and more than $1 billion in annual retail sales.
  • Consumers and retailers: Coca‑Cola says existing inventory helped cover temporary shortages and that product quality and safety were never jeopardized, even as production resumed at most U.S. facilities.

The record now contains concrete, opposing claims: Anubis says it encrypted Nutanix systems and released roughly one terabyte of stolen files; Coca‑Cola says it reported the intrusion to authorities, refused to negotiate, and has restored most U.S. production while some systems remain under recovery. The incident leaves open a specific, immediate question: what is in the released terabyte — operational data, employee and customer records, proprietary formulas — and how much of it will meaningfully affect Fairlife’s business, partners, or individuals whose information may be included?

Original story