Back to Industry

Industry - Data Breach

moderateAnti-PrivacyData Breach

Executive Summary

Coca-Cola confirmed that hackers stole data from its dairy subsidiary Fairlife during a ransomware attack that temporarily halted U.S. production operations. The Anubis ransomware gang claimed responsibility, threatening to leak one terabyte of stolen files, and has now released the data publicly after Coca-Cola refused to pay the ransom and reported the incident to authorities. While the company is still restoring some systems, most production has resumed and product safety was not affected.

What Happened

The Coca-Cola Company confirmed that the Anubis ransomware gang breached its dairy subsidiary Fairlife earlier in July 2026, stealing approximately one terabyte of data and encrypting the company's Nutanix systems. Coca-Cola disclosed the attack to the SEC on July 16 and immediately reported it to authorities, refusing to negotiate with the attackers. After the ransom deadline expired on July 27, the stolen data was released publicly for download.

Who Is Affected

The breach directly impacts Fairlife, a U.S.-based producer of ultra-filtered milk and protein drinks with over $1 billion in annual sales and four production facilities. While the specific contents of the stolen terabyte of data have not been detailed, the breach potentially affects Fairlife employees, business partners, and anyone whose information was stored in the compromised systems. Production disruptions temporarily affected product availability across U.S. markets, though existing inventory covered shortages.

Why It Matters

This incident demonstrates that even subsidiaries of major global corporations remain vulnerable to ransomware attacks that can simultaneously disrupt physical operations and result in data theft. Coca-Cola's decision to refuse ransom payment and report to authorities, while transparent, resulted in the public release of stolen data - illustrating the difficult position organizations face when attackers employ double-extortion tactics. The attack on critical food production infrastructure also highlights vulnerabilities in supply chains that can affect consumer goods availability.

What You Should Do

If you are a Fairlife employee, contractor, or business partner, monitor your financial accounts and credit reports for suspicious activity, as your personal or business information may be in the leaked dataset. Consider placing fraud alerts with credit bureaus and remain vigilant against phishing attempts that may use the stolen data to appear legitimate. If you receive any communications claiming to be from Fairlife regarding the breach, verify their authenticity through official company channels before responding or clicking links.

Summary generated from verified sources and reviewed before publication. How we summarize.

Coca-Cola confirmed that hackers stole data from its dairy subsidiary Fairlife... - Industry | PrivacyWire