Anubis Ransomware Attack on Coca-Cola and Fairlife
The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola’s Fairlife dairy subsidiary. Consequently, the company was forced to suspend production at its U.S. facilities after attackers gained unauthorized access to production-related systems.
What Happened: Anubis Ransomware Hits Coca-Cola Fairlife Dairy Operations
On July 16, 2026, The Coca-Cola Company disclosed in an SEC filing that Fairlife had suffered a ransomware attack. The company said attackers gained unauthorized access to a portion of Fairlife’s systems, including production-related infrastructure. Therefore, Coca-Cola activated its incident response and business continuity plans.
The attack forced Fairlife to temporarily halt production of its ultra-filtered milk products, protein shakes, and nutrition drinks across the United States. However, product quality and safety were not affected. Moreover, Canadian production operations continued as normal.
On Monday, July 21, the Anubis ransomware gang added Fairlife to its dark web data leak site. Furthermore, the gang claimed it had stolen approximately one terabyte of corporate data. The gang also warned it would publish the stolen data unless the company entered negotiations by the end of the week.
Technical Details of the Anubis Ransomware Attack
Anubis is a ransomware-as-a-service (RaaS) operation that emerged in December 2024. Moreover, it has since targeted organizations worldwide across multiple industries.
The gang claimed it attacked Fairlife roughly a week before the company publicly disclosed the incident. In addition, Anubis stated it had fully encrypted Fairlife’s Nutanix infrastructure. The ransomware operators also claimed there was no chance of recovery without their encryption key.
The key technical aspects of the Anubis operation include:
- Initial access via unknown vector (possibly phishing or exploited vulnerability)
- Encryption of Nutanix virtualized infrastructure
- Data exfiltration of approximately 1 TB of corporate data
- Use of a dark web leak site for extortion pressure
- Deployment of data wipers to destroy files beyond recovery (added in late 2025)
Business and Operational Impact
The attack on Fairlife carries significant business consequences. Coca-Cola is one of the world’s largest beverage companies. Therefore, disruption to its dairy subsidiary affects both supply chains and consumer markets.
The key impacts include:
- Production halt: U.S. manufacturing of Fairlife products suspended indefinitely
- Revenue disruption: Lost sales during peak summer demand period
- Data exposure risk: Up to 1 TB of corporate data potentially leaked
- Reputational damage: Consumer confidence in product safety and brand integrity
- Recovery costs: Extensive incident response, system restoration, and potential ransom payment
Coca-Cola has not disclosed whether it received an extortion demand. Moreover, the company declined to comment on the Anubis gang’s specific claims.
Mitigation and Recommendations
Immediate Actions for Defenders
- Audit and segment Nutanix and virtualization infrastructure access controls
- Deploy endpoint detection and response (EDR) across all production systems
- Monitor for Anubis ransomware indicators of compromise (IOCs)
- Ensure offline backups are current, tested, and isolated from production networks
- Review and strengthen identity and access management (IAM) policies
Long-Term Hardening Measures
Organizations should also consider broader ransomware defense strategies. For example, implementing zero-trust architecture can limit lateral movement. In addition, regular tabletop exercises and employee phishing simulations reduce the risk of initial compromise.
Bottom line: The Anubis attack on Coca-Cola Fairlife demonstrates that even major brands with extensive security resources are vulnerable to ransomware. Therefore, organizations must prioritize offline backups, network segmentation, and rapid incident response to withstand similar attacks.
Incident Summary
| Incident: | Anubis ransomware attack on Coca-Cola Fairlife |
| Threat Actor: | Anubis ransomware gang (RaaS) |
| Target: | Fairlife dairy subsidiary of The Coca-Cola Company |
| Disclosure Date: | July 16, 2026 (company); July 21, 2026 (gang claim) |
| Attack Vector: | Unknown; resulted in Nutanix infrastructure encryption |
| Data Stolen: | Approximately 1 TB claimed by Anubis |
| Impact: | U.S. production suspended; data leak threatened |
References
- Lawrence Abrams, BleepingComputer, “Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak,” July 21, 2026, https://www.bleepingcomputer.com/news/security/anubis-ransomware-claims-coca-cola-fairlife-attack-threatens-data-leak/
- BleepingComputer, “Coca-Cola says Fairlife ransomware attack halts US dairy production,” July 16, 2026, https://www.bleepingcomputer.com/news/security/coca-cola-says-fairlife-ransomware-attack-halts-us-dairy-production/
- The Coca-Cola Company, SEC Form 8-K Filing, July 16, 2026, https://www.sec.gov/Archives/edgar/data/21344/000162828026048466/ko-20260716.htm
- BleepingComputer, “Anubis ransomware adds wiper to destroy files beyond recovery,” December 2025, https://www.bleepingcomputer.com/news/security/anubis-ransomware-adds-wiper-to-destroy-files-beyond-recovery/