"resumed the majority of production," Coca-Cola said on July 27, describing Fairlife's status after a ransomware attack that the company now says involved unauthorized access and the taking of certain data.
What Coca‑Cola disclosed and when
On July 27 Coca‑Cola issued a brief statement revealing that its Chicago‑based dairy subsidiary, Fairlife, had “resumed the majority of production” at its four U.S. facilities following an incident earlier in the month. The company explained in an SEC Form 8‑K filing that Fairlife identified unauthorized access on July 16, and that incident response and business continuity protocols were activated and external experts were engaged.
Coca‑Cola stressed that “retail availability of Fairlife products has been largely unimpacted, due to the availability of existing inventory,” and that “product quality and safety have not been impacted.” The company added: “Based on the information currently available, the company believes the incident has not had, and is not reasonably likely to have, a material impact on the company’s financial condition or results of operations.”
Production outages, recovery, and the immediate business impact
Although Coca‑Cola reports the majority of production has resumed, the filing and statement confirm there were production outages significant enough to require temporary shutdowns of U.S. operations while response actions were underway. Fairlife generates more than $1bn in annual revenue from its ultra‑filtered milk and protein shakes, a fact underscoring why any interruption drew fast operational and corporate attention.
Data theft claim: Anubis posts alleged haul
Screenshots posted to X show the ransomware group Anubis claiming responsibility and asserting it had exfiltrated a 671GB trove of data. According to those posts, the collection includes human resources records, engineering and technical documentation, and production data. The group said it has leaked those materials on its ransomware blog.
Security analysis from Ross Filipek and the risk of long shelf life
Ross Filipek, chief information security officer at Corsica Technologies, warned that the data theft may carry consequences beyond the temporary production outage. “That information creates options,” he said, listing plausible criminal uses drawn from the categories named by Anubis: impersonating executives or vendors, redirecting payments, or targeting employees with convincing phishing messages.
Filipek also noted operational risk: “Operational details could also reveal which suppliers are essential and where future disruption would create the most pressure.” He argued for stronger internal controls over non‑customer‑facing business information and said: “Organizations need to know where that information lives. Access should be limited, monitored, and separated so one compromised system doesn’t expose the company’s entire playbook.”
What this means for technologists, employees, and retailers
- Technologists and security teams: The incident underscores a focus on internal data governance. Filipek’s remarks highlight the need to map where HR, technical and production data reside and to enforce access controls, monitoring, and segmentation to limit lateral exposure.
- Employees (HR records subjects): With HR data among the materials Anubis claims to have taken, employees should expect increased phishing and impersonation attempts, as the security analyst explicitly identified employees as likely targets.
- Retailers and supply partners: Coca‑Cola’s statement that retail availability has been “largely unimpacted” due to existing inventory suggests near‑term shelf supply remained stable, but the theft of production and supplier details raises the prospect of future operational leverage for adversaries according to security commentary.
The public record presented by Coca‑Cola and the screenshots posted to X shows a dual narrative: the company emphasizes containment, product safety and a belief that the breach will not be material to results, while external claims and expert analysis warn that stolen internal data may inflict harm over a much longer timeline than a temporary production shutdown. Fairlife’s production lines may be running again, but the question Filipek posed is practical and precise — internal business data “shouldn’t be treated as harmless simply because it isn’t customer‑facing” — and that unresolved tension will shape whether the incident is remembered as a brief operational disruption or a source of ongoing fraud and disruption.
Original story: https://www.infosecurity-magazine.com/news/coca-cola-subsidiary-fairlife-data/




