
ANUBIS ransomware struck Coca‑Cola’s Fairlife subsidiary in July 2026, deleting the decryption keys after a week and then publishing over one terabyte of stolen data, as reported by SuspectFile. The attack forced a temporary halt to production at several US facilities and exposed HR files, technical documentation and other internal records.
The attackers gained initial access through weak or reused credentials, moved laterally across the network and deployed ransomware that encrypted files while simultaneously exfiltrating sensitive archives. Anubis then erased the decryption keys after seven days, leaving victims with no recovery option unless they paid, and began leaking the stolen material to pressure compliance. Details of the key deletion tactic were outlined in a databreaches.net analysis.
The intrusion affected roughly five hundred workstations and servers, resulting in the theft of about one terabyte of data that included human‑resources records, technical specifications and internal communications. Fairlife reported a temporary production pause at several US plants, though most lines have since resumed normal operations. Infosecurity Magazine noted the exposure of HR and technical data.
Anubis has become known for its rapid shift from encryption to data leakage, often abandoning negotiation once the decryption keys are destroyed. Security researchers note that the group’s double‑extortion model now includes a wiper function that can permanently delete files, complicating restoration efforts. SecurityWeek reported that the ransomware group threatened to leak the data unless a ransom was paid.
Defenders should ensure that multi‑factor authentication is enforced on all privileged accounts and that password policies prohibit reuse across systems. Network segmentation must limit lateral movement, isolating critical production environments from corporate IT. Regular, offline backups that are tested for integrity provide the only reliable recovery path when ransomware destroys keys. Monitoring for unusual outbound traffic and large data transfers can help detect exfiltration before attackers trigger their leak phase.
Incident response plans should be updated to reflect shorter timelines for data leakage, with predefined steps for communicating with law enforcement and legal counsel. Organisations should also review third‑party risk, as many ransomware intrusions begin through trusted vendors or compromised credentials.