The Anubis ransomware gang has targeted Coca-Cola’s dairy subsidiary, Fairlife, claiming responsibility for a significant cyberattack. They are threatening to release stolen data unless a ransom is paid, raising serious concerns about data security.
Fairlife is a prominent brand under Coca-Cola, known for its innovative ultra-filtered dairy products, protein shakes, and energy drinks available across the United States. Popular offerings include Ultra Filtered Milk, Core Power Protein Shakes, and various Nutrition Plans.
On July 16, The Coca-Cola Company confirmed that this ransomware attack had severely disrupted Fairlife’s operations, resulting in a temporary halt of production at its U.S. facilities.
Coca-Cola reported unauthorized access to several of Fairlife’s systems, including critical production-related operations, prompting the activation of incident response and business continuity plans. Fortunately, the company assured that product quality and safety remain unaffected, and Canadian production continues without interruption.
At this time, Coca-Cola has not disclosed if any data has been stolen or confirmed whether an extortion request has been made.
Anubis Claims Responsibility for Ransomware Attack
On the same day, the Anubis ransomware group listed Fairlife on its dark web data breach site. They claimed to have stolen approximately 1 terabyte of sensitive corporate data and issued a warning that the stolen information would be released unless negotiations commenced before the week’s end.

The Anubis gang asserted that the attack occurred about a week before Coca-Cola publicly acknowledged it, stating, “We attacked their systems a week ago. They reported the incident without following our instructions left in their network.”
They claimed to have fully encrypted Fairlife’s Nutanix infrastructure, leading to a dire situation where recovery is impossible without the encryption keys.
Bleeping Computer could not independently verify the gang’s claims regarding the data theft, encryption status, or the alleged amount of stolen data.
Attempts to obtain comments from Coca-Cola regarding these claims were unsuccessful.
Anubis operates as a ransomware-as-a-service (RaaS) business, first surfacing in December 2024. This group has shown a pattern of targeting organizations globally across various sectors, notorious for combining data theft with file encryption to extort payments from their victims.
Last year, Anubis further escalated its tactics by introducing a data wiper into its arsenal, which irreparably damages victims’ files, complicating recovery efforts.
Security professionals have documented that only 54% of successful attacks are noted, with warnings issued in a mere 14% of cases, allowing the rest to go unnoticed.
Picus’ whitepaper outlines how to effectively test your SIEM and EDR rules through breach and attack simulations to mitigate undetected threats.
This optimized content maintains the original structure while improving SEO by incorporating relevant keywords and maintaining clear headings, emphasizing the importance of the issue surrounding the Anubis ransomware gang’s attack on Fairlife.
Source: www.bleepingcomputer.com




