HackMyIP
← Back to News
2026-07-17 The Record

Fairlife Halts US Production After Ransomware Attack on Coca-Cola Unit

RansomwareIncident ResponseThreat Intel

Coca-Cola's premium dairy subsidiary Fairlife has suspended operations at its US processing plants following a ransomware intrusion detected on Thursday. The company confirmed the incident in an official filing, noting that production facilities in Michigan, New York, and Arizona have been temporarily shuttered while an internal investigation is underway. Fairlife's Canadian operations remain unaffected, and Coca-Cola emphasized that product quality and safety have not been compromised. Law enforcement has been notified, though the beverage giant has not disclosed the ransomware affiliate or group responsible for the attack, nor confirmed whether corporate or consumer data was exfiltrated. Organizations concerned about exposure in similar incidents can verify compromised credentials using an email breach checker.

The intrusion adds Fairlife to a growing list of food and beverage manufacturers targeted by cybercriminals in 2025. Japanese brewer Sapporo reported unauthorized network access at two subsidiaries in late June, while a separate attack on a major refrigerated logistics provider disrupted ordering systems at Kentucky Fried Chicken locations across Japan earlier this week. Russian dairy firms, US grocery distributor United Natural Foods, and South Africa's largest chicken producer have all reported operational disruptions from cyber incidents this year. The pattern underscores how threat actors are increasingly targeting the global food supply chain for financial leverage.

Fairlife, founded in 1994 and rebranded nationally in 2015, became a wholly owned Coca-Cola subsidiary in 2020 and surpassed $1 billion in annual retail sales by 2022. With the full scope of the breach still under assessment, incident responders are working to contain lateral movement and restore encrypted systems. Coca-Cola has not announced a ransom demand or any timeline for resuming production. Security teams investigating similar intrusions are advised to audit exposed network services with a port scanner to identify potential entry points exploited by attackers. As ransomware groups continue to prioritize operational technology environments in the food sector, the Fairlife incident highlights the urgent need for segmented network architectures and tested backup recovery procedures across the industry.

Source: The Record →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →