The Coca-Cola Company
Incident posture
Linked entities
- Victim
- The Coca-Cola Company
- Threat actors
- 1 actor
- Sources
- 11 sources
Timeline
Summary
Coca-Cola disclosed that its dairy subsidiary was hit by a ransomware attack that encrypted systems and stole about one terabyte of confidential data, prompting a temporary halt of U.S. production operations while Canadian facilities remained unaffected. The attackers threatened to leak the stolen data unless a ransom was paid, and the company reported the incident to law enforcement and engaged external cybersecurity experts to restore operations. Despite the disruption, the company later stated that most production had resumed and that product quality and safety were not compromised.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On July 16, 2026, Coca-Cola filed a Form 8-K with the U.S. Securities and Exchange Commission disclosing that an unauthorized third party had gained access to part of Fairlife's systems, including those related to production, and characterized the incident as a ransomware event. The company stated that product quality and safety were not impacted but that production operations at Fairlife in the United States were temporarily suspended, while Canadian operations remained unaffected. Coca-Cola said it had notified law enforcement, engaged external cybersecurity experts, and activated its incident response and business continuity plans. The filing noted that the full scope, nature and impacts of the incident were not yet known and that the company had not yet determined whether the incident was reasonably likely to materially affect the company. Subsequent news reports on July 17 and 18 confirmed that Fairlife’s U.S. production had been halted and that the company was working to restore operations.
On July 20, the ransomware group Anubis claimed responsibility for the attack on Fairlife, posting the victim on its dark web leak site and asserting that it had encrypted the company’s Nutanix systems and exfiltrated approximately one terabyte of confidential data. Anubis stated that it had attacked Fairlife’s systems a week earlier, that Coca-Cola had reported the intrusion without following the attackers’ instructions, and that the victim had no chance of recovering its data without the decryption key. The group gave Fairlife a deadline, saying it would release the stolen data if a ransom was not paid by the end of the week. On July 22, Anubis reiterated its demand, saying it could restore Fairlife’s systems within hours upon payment and that the stolen data would be leaked if the ransom was not met. On July 27, Coca-Cola confirmed that data had been stolen during the attack and said it was still working to restore some impacted systems while most U.S. production had resumed. The company noted that it had reported the intrusion to authorities and had not followed the attacker’s negotiation instructions. Later on July 27, the timer set by Anubis for the public release of the stolen data expired, and the data became available for download.
Despite the data leak threat, Coca-Cola announced that it had made significant progress in restoring Fairlife’s production and had resumed the majority of U.S. operations by late July. The company said that retail availability of Fairlife products had been largely unimpacted because existing inventory covered temporary shortages caused by the production disruption. Coca-Cola stated that product quality and safety had not been affected by the incident and that it did not expect the cyberattack to meaningfully hurt its sales. The company did not disclose how it restored operations, whether it paid any ransom, or the specific method used by the attackers to gain initial access. Coca-Cola continued to work with law enforcement and cybersecurity experts to fully restore production operations and to assess the full scope of the incident.
Sources
Sources available to members: 11 sources.