Coca-Cola Confirms Data Theft in Fairlife Ransomware Attack; Stolen Data Now Public
Coca-Cola confirmed that a ransomware attack on its Fairlife dairy subsidiary led to data theft, and the stolen data is now publicly available after the Anubis gang's deadline expired.
This article was drafted with AI assistance from multiple sources and was reviewed and approved by a human editor before publication.
Coca-Cola has confirmed that a ransomware attack on its dairy subsidiary Fairlife resulted in the theft of data, and the stolen information is now publicly available after the attackers' deadline expired.
The company disclosed the incident in a filing with the U.S. Securities and Exchange Commission on July 16, 2026. According to Coca-Cola, an unauthorized third party accessed Fairlife's systems and took certain data, prompting a temporary suspension of production. "Existing inventory covered temporary shortages; product quality and safety not affected," the company stated.
The Anubis ransomware gang claimed responsibility for the attack on July 20, threatening to leak 1 terabyte of stolen data. Coca-Cola said it did not negotiate with the attackers and reported the incident to authorities. The stolen data timer expired on July 27, and the information is now available for download on the group's leak site.
Fairlife operates four production facilities in the United States and generates annual retail sales exceeding $1 billion. As of July 27, the majority of production at those facilities had resumed. Fairlife's Canadian operations were not affected.
Coca-Cola stated that it believes the incident is "not material to financial condition or operations."
The Anubis ransomware group has been active since December 2024 and has listed approximately 100 organizations on its leak site. The group uses a double-extortion model and includes a wiper mode that can permanently delete files.
According to the Food and Agriculture ISAC, there have been 205 ransomware incidents in the sector in 2026, accounting for 4.9% of all attacks.