HackMyIP
← Back to News
2026-07-27 SecurityWeek

Coca-Cola Confirms Fairlife Data Breach After Anubis Ransomware Attack

RansomwareData BreachIncident Response

Coca-Cola has confirmed that the recent ransomware attack on its dairy subsidiary Fairlife resulted in a data breach, with the Anubis ransomware group claiming to have stolen approximately 1 TB of confidential data. The soft drinks giant initially disclosed the cybersecurity incident on July 16, suspending production at all four Fairlife facilities in the United States while investigating the intrusion. On July 20, Anubis listed both Coca-Cola and Fairlife on its dark web leak site, indicating that files had been encrypted on compromised systems and threatening to publish the stolen data unless a ransom is paid. Organizations concerned about credential exposure can verify their emails using an email breach checker to determine whether employee or customer data has surfaced in known leaks.

In a statement issued on Monday, Coca-Cola confirmed that "the taking of certain data" had occurred, though it declined to specify what types of information were compromised. The company reported that the majority of production has since resumed and that retail availability of Fairlife products has been largely unaffected due to existing inventory. Coca-Cola also stated that it does not believe the incident will have a material impact on its financial condition or results of operations. At the time of writing, a countdown timer on the Anubis leak site indicated the stolen data would be released publicly within hours if no payment was made.

Active since December 2024, Anubis has targeted roughly 100 organizations and operates under a double-extortion model, encrypting victim files while exfiltrating sensitive data to increase leverage in ransom negotiations. The group has drawn particular attention from security researchers for its wiper mode capability, which can permanently delete files and prevent recovery even if victims attempt restoration from backups. Affected individuals should rotate any reused credentials immediately—security professionals recommend testing password strength with a password checker and enabling multi-factor authentication across all accounts that may share credentials with Fairlife-affiliated services.

The Fairlife incident underscores the growing threat ransomware poses to operational technology environments and consumer-facing supply chains, where production halts can trigger cascading commercial and reputational damage. Coca-Cola's response—rapid containment, transparent disclosure, and resumption of operations—reflects mature incident response practices, though the full scope of exposed data may not be known until Anubis completes its publication or the company completes forensic analysis. Users can also run a privacy checkup to audit their digital exposure and reduce the risk of further compromise.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →