Coca-Cola Confirms Data Breach Following Fairlife Ransomware Attack
- CVE ID
- N/A
- Affected Products / Orgs
- Coca-Cola, Fairlife
Production halts across four US processing plants have given way to confirmed data exfiltration after Coca-Cola acknowledged a data breach stemming from a ransomware attack against its Fairlife dairy subsidiary.
The soft drinks giant disclosed the initial cybersecurity intrusion on July 16, taking the preemptive measure of suspending operational facilities across the United States to contain the threat and launch a forensic investigation. On Monday, Coca-Cola issued an updated statement confirming that while the majority of processing operations at the four affected Fairlife facilities have now resumed, the attackers succeeded in exfiltrating internal data.
Despite the disruption to manufacturing lines, retail supply chains for Fairlife products remained stable due to existing warehouse inventory buffers. Coca-Cola stated that product safety and quality were completely unaffected, and based on currently available forensic information, the company does not anticipate the incident having a material impact on its financial condition or overall operational results.
The Threat Actor: Anubis Ransomware Tactics
Responsibility for the Fairlife ransomware attack was claimed on July 20 by the Anubis cybercrime group, which added both Coca-Cola and Fairlife to its public leak site. The extortion gang claimed to have encrypted internal systems and stolen 1 TB of confidential corporate data. At the time of publication, Anubis had published a countdown timer giving the company two hours to satisfy ransom demands before the stolen files are made public.
First emerging around December 2024, the Anubis group operates a double-extortion ransomware model. Like most modern human-operated ransomware operators, the group focuses heavily on pre-encryption data exfiltration, leveraging stolen records to maintain leverage even if a victim possesses clean system backups. To date, Anubis has listed roughly 100 targeted organizations on its extortion blog.
What distinguishes Anubis from standard ransomware-as-a-service (RaaS) operations is its integrated “wiper mode” functionality. In addition to standard file encryption routines (typically using hybrid AES/RSA or ChaCha20 scheme implementations), the malware includes routines designed to systematically overwrite master boot records (MBR), file system tables, or shadow copies to render recovery impossible. Threat actors deploy wiper routines as an escalation tactic when victims refuse negotiation, or as destructive cover during anti-forensic cleanup.
Supply Chain and Subsidiary Blast Radius
The attack highlights the unique operational risks faced by global enterprise conglomerates that manage specialized subsidiaries. Processing facilities in the food and beverage industry rely heavily on converged Information Technology (IT) and Operational Technology (OT) environments. Industrial automation systems, batch monitoring, automated bottling, and logistics dispatch scheduling depend on enterprise resource planning (ERP) systems hosted on core corporate networks.
When an intrusion occurs within a subsidiary’s administrative network, organizations frequently execute emergency shutdown protocols across physical plant operations to prevent lateral movement. Attackers often target active directory domains or network bridges connecting corporate networks to industrial control system (ICS) demilitarized zones (DMZs). If adversaries establish persistent access within enterprise IT networks, the risk of malware spilling over into supervisory control and data acquisition (SCADA) networks or programmable logic controllers (PLCs) forces defenders to isolate manufacturing facilities completely.
While extortion groups frequently exaggerate the sensitivity or volume of exfiltrated data to compel payment, a 1 TB data theft in a manufacturing subsidiary typically exposes sensitive categories, including:
- Proprietary recipes, batch parameters, and processing IP
- Logistics contracts, distributor pricing models, and vendor agreements
- Internal operational metrics, quality assurance logs, and safety audits
- Employee personally identifiable information (PII) and internal HR records
Defense and Mitigation Considerations
Organizations operating high-throughput manufacturing plants or multi-subsidiary networks must design operational resilience around the assumption that administrative IT networks will suffer breaches.
- IT/OT Network Segmentation: Ensure strict network boundaries between enterprise administrative networks and plant floor OT networks. Implement unidirectional security gateways or zero-trust network architectures (ZTNA) with strict microsegmentation at the Purdue Model Level 2/3 interfaces. Operational processes should be capable of running in “island mode” during IT network isolations.
- Defending Against Wiper Capabilities: Because threat groups like Anubis incorporate data wiping capabilities, standard online backups are insufficient. Security teams must enforce air-gapped, immutable write-once-read-many (WORM) backup architectures that cannot be deleted or modified via compromised domain administrative credentials.
- Egress Monitoring for Large-Scale Data Theft: Ransomware groups routinely spend days or weeks inside a target network exfiltrating hundreds of gigabytes before executing encryption binaries. Security Operations Center (SOC) teams should deploy network traffic analysis (NTA) and anomaly detection rules specifically configured to alert on sustained high-volume outbound data transfers over non-standard ports, cloud storage APIs (e.g., Mega, Rclone), or encrypted SSH/SFTP tunnels.
Related content
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call