Coca-Cola has officially confirmed that the ransomware attack on its dairy subsidiary Fairlife involved unauthorized access to systems and data theft. The company refused to enter into negotiations with the Anubis group, which reportedly published the stolen files on its leak site after its July 27 deadline expired. The incident led to a temporary production halt at all four Fairlife facilities in the United States, although operations have now been almost fully restored.
Incident timeline
The attack became publicly known in mid-July 2026, when Coca-Cola submitted a notification to the U.S. Securities and Exchange Commission (SEC). The attack affected systems tied to production processes, forcing the company to temporarily suspend operations at all four Fairlife plants in the United States.
Soon after, the Anubis ransomware group claimed responsibility for the breach. According to BleepingComputer, the attackers claimed to have encrypted Nutanix infrastructure owned by Fairlife and to have stolen roughly 1 TB of confidential files. It should be emphasized that the alleged volume of stolen data and the claim that Nutanix specifically was compromised are based solely on the group’s own statements and have not been confirmed by Coca-Cola.
After discovering the attack, the company notified law enforcement but categorically refused to meet the attackers’ demands or begin ransom negotiations. Initially, Coca-Cola did not comment on Anubis’s claims at all and did not confirm that any information had been stolen.
Now, according to the company’s official statement, Coca-Cola has acknowledged that the attackers gained access to part of Fairlife’s systems and stole data. However, the company still has not disclosed what specific information was compromised or the actual scale of the leak.
According to reports, the deadline set by Anubis expired on July 27, after which the stolen files were published on the group’s website.
The Anubis group: threat context
Anubis is a relatively new player in the ransomware ecosystem. Notably, in this incident the group emphasized the encryption of Nutanix infrastructure — a hyperconverged platform widely used in enterprise environments for virtualization and data management. If this claim is accurate, it points to a targeted attack carried out with an understanding of the victim’s architecture, rather than opportunistic encryption.
The double extortion tactic — encrypting data while simultaneously stealing it and threatening publication — has become standard practice for most ransomware groups. However, Coca-Cola’s decision not to engage in negotiations and the subsequent dump publication create a noteworthy precedent: a large corporation accepted the reputational risks of a leak but chose not to finance a criminal group.
Impact assessment
The incident affected several key aspects of Fairlife’s operations:
- Production: all four plants in the United States were temporarily shut down. At this point, production has almost completely resumed, although recovery of certain systems is still ongoing.
- Supply chain: the company stated that existing inventory allowed it to avoid serious shortages, and the attack had almost no impact on product availability in retail chains.
- Product safety: Coca-Cola stressed that the incident did not affect the quality or safety of the products being manufactured.
- Financial impact: company leadership stated that the incident did not have, and likely will not have, a material effect on Coca-Cola’s financial position.
Nevertheless, the lack of clarity regarding the nature of the stolen data leaves open questions about potential risks to Fairlife employees, partners, and counterparties. If the stolen information includes personal data, trade secrets, or supplier information, the consequences may surface later.
Practical recommendations
This incident offers several important lessons for organizations that use hyperconverged infrastructure and industrial systems:
- Network segmentation: operational technology (OT) systems should be isolated from the corporate IT infrastructure. Compromise of one segment should not result in a complete production shutdown.
- Protection of hyperconverged platforms: Nutanix environments and similar platforms require dedicated attention — restrictions on administrative access, monitoring of privileged operations, and regular configuration audits.
- Backups: having isolated backups (air-gapped backups) is critical for recovery without depending on attackers’ decryption keys. Judging by its ability to restore production without paying a ransom, Coca-Cola appears to have had such backups in place.
- Incident response plan: define the company’s position on negotiations with extortionists in advance. Coca-Cola’s decision not to pay the ransom aligns with recommendations from the FBI and most regulators.
- Inventory and resilience: for manufacturing companies, maintaining buffer stocks of finished products is a component of cyber resilience, not just logistics.
The Fairlife case shows that refusing to negotiate with ransomware operators is possible even in the face of a large-scale attack on production infrastructure, but it requires advance preparation: isolated backups, a recovery plan, and sufficient product inventory. Organizations that use hyperconverged platforms in production environments should audit segmentation between IT and OT networks and ensure that administrative access to the virtualization infrastructure is protected with multi-factor authentication and privileged session monitoring.