Coca-Cola-owned dairy company fairlife has suffered a ransomware attack that disrupted production across its United States operations and exposed company data to cybercriminals. The incident forced fairlife to temporarily suspend manufacturing while cybersecurity specialists investigated unauthorized access to systems connected with production.
The attack was initially disclosed on July 16, 2026, when Coca-Cola confirmed that an unauthorized third party had accessed part of fairlife’s technology environment. Although the company stated that product quality and safety were not affected, the disruption demonstrated how ransomware can move beyond office computers and interfere directly with manufacturing operations.
Most production has since resumed at four US facilities, but some systems and business functions were still being restored when Coca-Cola provided its latest public update. The company also confirmed that information was taken during the incident, increasing the potential legal, financial, and reputational consequences of the attack.
Coca-Cola Disclosed the Attack Through an SEC Filing
Coca-Cola formally reported the incident through a Form 8-K filed with the US Securities and Exchange Commission. The filing stated that fairlife had discovered unauthorized third-party access to a portion of its systems, including technology associated with production operations.
After identifying the breach, the company activated its incident-response and business-continuity procedures. Outside cybersecurity experts and advisers were brought in to assess the intrusion, restore systems and determine the full scope of the damage. Coca-Cola also notified law-enforcement authorities.
The company suspended fairlife’s US production operations as a precaution while affected systems were isolated and examined. Canadian production remained operational and was not identified as part of the compromised environment. Coca-Cola initially said it could not yet determine whether the event would have a material effect on the company’s financial condition or business performance.
Fairlife Production Was Temporarily Suspended Across the US
Fairlife produces ultra-filtered milk, lactose-free dairy drinks, protein shakes and nutritional beverages. Its portfolio includes fairlife ultra-filtered milk, Core Power protein shakes and fairlife Nutrition Plan products.
The temporary suspension was significant because fairlife has become one of Coca-Cola’s most valuable growth brands. The Chicago-based dairy company generates more than $3 billion in annual retail sales, making an extended interruption potentially costly for manufacturing output, retailer inventory and product availability.
Products that had already entered the market were not recalled as a result of the cyberattack. Coca-Cola repeatedly stated that the incident had not affected product quality or safety. The precautionary production pause was connected to the security and availability of manufacturing-related systems rather than evidence of contaminated or unsafe dairy products.
By July 27, most production had resumed at four fairlife facilities in the United States. Coca-Cola said restoration work was continuing for some affected technology and operations, indicating that recovery was progressing but had not been fully completed.
Hackers Claimed They Stole One Terabyte of Data
The Anubis ransomware group claimed responsibility for the attack through its dark-web leak site. The group alleged that it had stolen approximately one terabyte of data from fairlife and threatened to publish the information unless its demands were met.
At the time the claim first appeared, Coca-Cola had not independently verified the amount of data cited by the attackers. However, the company later confirmed that data had been taken during the breach. Details about the specific files, affected individuals or categories of exposed information had not been fully disclosed publicly.
The distinction is important because ransomware attacks frequently involve more than file encryption. Many groups first copy valuable information and then attempt to disable systems. This double-extortion strategy gives attackers two forms of leverage: operational disruption and the threat of releasing confidential data.
Information potentially targeted in a corporate breach can include employee records, internal communications, supplier documentation, contracts, operational data or other commercially sensitive material. No complete public inventory of the information taken from fairlife had been released, so the actual privacy and business impact remains under investigation.
Anubis Ransomware Carries a Destructive Reputation
Anubis is an emerging ransomware operation associated with data theft, encryption and unusually destructive capabilities. Cybersecurity researchers have identified a file-wiping function that can permanently erase file contents rather than simply encrypting them for possible restoration.
A Trend Micro analysis of Anubis ransomware describes a “wipe mode” capable of deleting the contents of targeted files. This feature can make recovery substantially more difficult because paying for a decryption key would not restore information that had already been destroyed.
It has not been publicly confirmed that the wiping capability was used against fairlife. The production shutdown may have resulted from encrypted systems, precautionary isolation, unavailable applications or a combination of operational security measures. Coca-Cola has not released a detailed technical explanation of how the attackers initially entered the network or which systems were directly affected.
The absence of that information is common during an active investigation. Companies frequently limit technical disclosures while specialists collect evidence, search for additional unauthorized access and prevent attackers from using public details to interfere with recovery.
Why Ransomware Can Stop Food and Beverage Production
Modern food and beverage plants depend on interconnected technology for processing, quality monitoring, packaging, warehousing, inventory management and distribution. Even when physical machinery remains functional, production may be unable to continue safely or efficiently if supporting applications become unavailable.
A ransomware infection affecting production-related systems can prevent employees from accessing schedules, recipes, quality records, maintenance information or automated manufacturing controls. Companies may therefore suspend operations until they can verify that systems are trustworthy and that production can restart without creating safety or quality risks.
The National Institute of Standards and Technology’s manufacturing cybersecurity guidance explains that increasingly connected operational technology can expose factory operations, property and safety processes to cyber threats. Effective recovery requires more than restoring office email or replacing employee laptops because industrial environments must also maintain operational reliability and system integrity.
The fairlife incident illustrates how cyber risk can become a supply-chain problem. A successful attack may disrupt manufacturing, reduce available inventory, delay shipments and place additional pressure on retailers and logistics partners, even when the consumer product itself remains safe.
Data Theft Could Extend the Impact Beyond Production
Restarting production does not automatically end the incident. Coca-Cola must still determine what information was removed, whether personal data was involved and which employees, suppliers, customers or business partners may require notification.
Data breaches can create regulatory obligations depending on the type of information exposed and the locations of affected individuals. They may also lead to legal claims, identity-protection expenses, cybersecurity upgrades and further investigations by government agencies.
The attackers’ threat to publish stolen files creates an additional challenge. If confidential information appears online, the company may need to assess intellectual property exposure, privacy consequences and possible risks to employees or commercial partners. Coca-Cola has not publicly stated whether any ransom was demanded or paid.
The Incident Highlights the Need for Manufacturing Resilience
The fairlife ransomware attack reinforces the importance of separating critical manufacturing systems from ordinary corporate networks. Strong access controls, network segmentation, offline backups, multifactor authentication and carefully tested recovery procedures can help reduce both the probability and impact of a successful intrusion.
The federal CISA StopRansomware Guide recommends that organizations prepare for both ransomware and data-extortion scenarios. Its guidance focuses on reducing common entry points, protecting backups, detecting unusual activity and maintaining a documented response process that can be activated quickly.
For manufacturing companies, recovery plans must also account for production continuity. Restoring a server is not enough when a facility depends on interconnected quality, packaging and operational systems. Each restored environment must be validated before full manufacturing can safely resume.
Fairlife’s rapid return to most production operations suggests that its business-continuity measures limited the duration of the disruption. Nevertheless, the confirmed data theft means the consequences may continue long after factories return to normal output.
Investigation Continues as Fairlife Restores Operations
Coca-Cola has not yet disclosed the attack’s full financial impact, the initial access method or the complete nature of the stolen information. The investigation remains important because those findings will determine whether the incident was limited to fairlife or whether any connected corporate systems were also exposed.
The attack demonstrates that even major global companies with extensive cybersecurity resources can experience serious operational disruption. It also shows why ransomware has become a board-level business risk rather than simply an information-technology problem.
Fairlife has resumed most US production, Canadian operations were unaffected and no product safety problem has been identified. However, the combination of manufacturing interruption and confirmed data theft makes the incident a significant cybersecurity event for Coca-Cola and the wider food and beverage industry.