The Anubis ransomware gang has claimed responsibility for a cyberattack on fairlife, Coca-Cola’s dairy subsidiary, adding the company to its dark web leak site and threatening to publish roughly one terabyte of allegedly stolen corporate data unless fairlife enters negotiations by the end of the week, according to BleepingComputer. The claim follows Coca-Cola’s disclosure on July 16 that a ransomware incident had forced fairlife to suspend production at its United States facilities, a disruption to a brand that generated close to four billion dollars in 2024 sales, according to Cyber Daily. Fairlife said product quality and safety were not affected and that it has engaged external cybersecurity experts and notified law enforcement.
| What happened | The Anubis ransomware gang listed fairlife, Coca-Cola’s dairy subsidiary, on its dark web leak site and threatened to publish allegedly stolen corporate data |
|---|---|
| Scale claimed | Approximately one terabyte of corporate data; the group also claims it encrypted fairlife’s Nutanix infrastructure |
| Timeline | Intrusion believed around July 9; Coca-Cola disclosed the incident July 16; Anubis posted its threat July 21 |
| Business impact | Production suspended at fairlife’s United States facilities, a brand with close to four billion dollars in 2024 sales |
| Company response | External cybersecurity experts engaged, law enforcement notified; fairlife says product quality and safety were not affected |
| The attacker | Anubis, a ransomware as a service operation active since December 2024 |
What did Anubis say it stole from fairlife?
Anubis, a ransomware-as-a-service operation that emerged in December 2024, posted fairlife to its dark web leak site and claimed to have stolen approximately one terabyte of corporate data, BleepingComputer reported. Based on the timing of Coca-Cola’s July 16 disclosure, the intrusion is believed to date back to around July 9, and Anubis did not post its leak site threat until July 21, a gap of roughly two weeks between the breach and the public extortion attempt. The group also claimed to have fully encrypted fairlife’s Nutanix infrastructure, writing in its leak site post that fairlife has \”no chance of recovering without our encryption key.\” BleepingComputer said it could not independently verify the gang’s claims about the volume of data stolen or the extent of the encryption, and Cyber Daily separately reported that Anubis had provided no proof of exfiltration. Rather than threatening an immediate public leak, the gang framed its message as a business proposition, writing, according to Cyber Daily, \”why cause a public scene and lose millions in downtime? We are offering you a simple, confidential business solution.\”
How has the attack disrupted fairlife’s operations?
Fairlife has confirmed that unauthorized access to a portion of its systems, including production-related systems, forced it to temporarily suspend manufacturing at its United States facilities, while Canadian operations have continued without interruption. The company said it activated its incident response and business continuity plans and, in a statement reported by Newsweek, said it \”is working diligently to complete the investigation and restore the systems and impacted operations.\” Fairlife has not given a timeline for resuming full US production. When asked directly about Anubis’s specific claims, Coca-Cola declined to comment, according to BleepingComputer, leaving the scale of the intrusion an open question even as the operational impact plays out in public.
Who is the Anubis ransomware group, and why does this fit a pattern?
Anubis runs a double extortion model that has become standard across the ransomware-as-a-service groups active through 2026: encrypt whatever can be encrypted, exfiltrate whatever can be exfiltrated, and use the threat of publication as leverage that does not depend on whether a victim can restore from backup. The fairlife claim landed in the same week that other extortion crews were pressing separate corporate victims, including the source code and Azure credential theft claimed against Accenture in July 2026 and the schools and government fallout that followed ShinyHunters’ breach of Instructure. Across all three cases the sequence is identical: a claim appears on a leak site well before any independent party can confirm it, and the named company is forced to manage reputational fallout for an allegation it cannot fully verify one way or the other.
Why does this matter to Coca-Cola’s shareholders?
fairlife is a meaningful business line for Coca-Cola, generating close to four billion dollars in revenue in 2024, and Coca-Cola’s stock fell roughly four percent in the week surrounding the disclosure, Cyber Daily reported. This is not the first time a Coca-Cola-affiliated business has been targeted; separate threat actors claimed attacks on Coca-Cola bottling partners in the Middle East and in Europe during 2025, according to Cyber Daily. For a US-listed company, a ransomware event that halts manufacturing crosses into territory regulators increasingly treat as material, a dynamic we have covered in our breakdown of US cybersecurity policy and the SEC’s expectations of executive liability.
What should security leaders take away from the fairlife attack?
The most uncomfortable part of the fairlife story for a CISO is not the ransom demand, it is the verification gap. Neither BleepingComputer nor Cyber Daily could confirm the scale of data Anubis claims to hold, yet fairlife and Coca-Cola still have to manage the reputational and operational fallout of the claim itself. That gap belongs on the same watch list as the other incidents we have tracked in this year’s biggest data breaches so far. Security leaders overseeing manufacturing or production environments should treat the fairlife incident as a prompt to revisit three things:
- Segmentation between corporate IT and production or operational technology systems, so a ransomware foothold on one side does not stall the factory floor on the other.
- Incident communications that can hold up before a claim is verified, since a leak site post can outrun a company’s own investigation by days or weeks.
- Backup and recovery testing specific to infrastructure platforms such as Nutanix, given Anubis’s specific claim to have encrypted that layer.
None of this is exotic advice, but ransomware crews keep succeeding against well-resourced targets because initial access still frequently starts with a person rather than a firewall. That is the throughline connecting fairlife to the broader case we have made for treating security awareness training as human risk management rather than a compliance checkbox, and for why CISOs need a 2026 playbook that assumes attackers will keep testing the seam between corporate IT and operations. Coca-Cola and fairlife have not confirmed any of Anubis’s specific claims about data volume or system compromise, and neither company has said whether it intends to negotiate before the gang’s stated deadline. Until fairlife or Coca-Cola issues a further update, or Anubis follows through on its threat to publish data, the scope of the breach remains an unverified claim rather than a confirmed fact.
Frequently asked questions
What did the Anubis ransomware gang claim about the Coca-Cola fairlife attack?
Anubis, a ransomware as a service group active since December 2024, claimed on its dark web leak site that it stole about one terabyte of corporate data from fairlife and fully encrypted the company’s Nutanix systems. BleepingComputer reported it could not independently verify the volume of data or the extent of encryption.
How did the ransomware attack affect fairlife’s production?
Fairlife confirmed unauthorized access to a portion of its systems, including production related systems, forcing a temporary suspension of manufacturing at its United States facilities. Canadian operations continued without interruption. Fairlife said product quality and safety were not affected and that it engaged outside cybersecurity experts and notified law enforcement.
Has Coca-Cola confirmed the Anubis ransomware group’s claims?
No. Coca-Cola declined to comment when asked directly about Anubis’s claims, according to BleepingComputer, and fairlife has not confirmed the amount of data taken or whether its systems were encrypted as described. The company has given no timeline for restoring full production or said whether it will negotiate.

Leave a Reply