
COCA‑Cola has confirmed that its Fairlife subsidiary fell victim to a ransomware attack carried out by the Anubis group, with the attackers claiming to have exfiltrated roughly one terabyte of confidential data. The company said it paused production at several Fairlife facilities in the United States while it investigated the incident, although most lines have since been brought back online. Coca‑Cola added that the breach is not expected to affect product availability or quality in any meaningful way and that the financial impact appears limited.
The Anubis ransomware strain operates with a double‑extortion model, encrypting victims’ files while simultaneously stealing sensitive data to pressure payment through the threat of public disclosure. Researchers note that the group also bundles a wiper component capable of permanently deleting files, which complicates recovery efforts even if backups are available. According to a separate report, the gang claimed to have taken approximately one terabyte of information from Fairlife’s networks and warned that it would leak the data unless a ransom was satisfied within a week.
Although Coca‑Cola said that most Fairlife production has resumed, the initial shutdown forced the company to halt processing lines and divert resources to containment and forensic analysis. The firm stressed that product safety and quality remain unaffected, and it does not anticipate any noticeable disruption to supply chains or retail shelves. Financially, Coca‑Cola characterised the incident as modest, noting that any potential ransom payment or remediation cost is unlikely to materially affect its quarterly results.
Anubis has been active since 2022 and is known for targeting organisations across multiple sectors, often leveraging phishing emails and exposed remote‑desktop services to gain initial access. Its recent focus on food and beverage manufacturers highlights a broader trend in which ransomware operators pursue firms that rely on just‑in‑time logistics, betting that the threat of leaked proprietary formulas or customer data will increase the likelihood of a quick payout. The Fairlife incident illustrates how even large, well‑resourced corporations can be caught off guard when attackers combine encryption with data theft.
Defenders should begin by isolating any suspect systems and preserving volatile memory for forensic review, while ensuring that recent, offline backups are verified and ready for restoration. Network segmentation ought to be tightened so that lateral movement from a compromised workstation to production servers is hindered, and privileged access accounts must be reviewed for unnecessary permissions.
Endpoint detection and response tools should be tuned to recognise the behavioural indicators associated with Anubis, such as rapid file encryption patterns and outbound connections to known command‑and‑control infrastructure.
Organisations are also encouraged to refresh employee awareness programmes, focusing on phishing recognition and safe handling of attachments, and to test incident‑response playbooks against a scenario involving data‑theft ransomware. Engaging law‑enforcement and threat‑intelligence partners early can help determine whether the stolen data is already appearing on leak sites and may support efforts to negotiate or resist extortion demands. Continuous monitoring of dark‑web markets for mentions of the exfiltrated data will allow a quicker public‑relations response if a leak does occur.