Coca-Cola Confirms Data Theft in Fairlife Ransomware Attack
The beverage giant suspended U.S. dairy production for days before acknowledging exfiltration in the July 2026 incident.
Coca-Cola confirmed that data was stolen from its Fairlife dairy subsidiary during a ransomware attack that suspended all U.S. production operations in mid-July 2026.
The company disclosed the incident in a Form 8-K filing with the Securities and Exchange Commission on July 16, 2026, stating that Fairlife detected unauthorized third-party access to a portion of its systems, including production-related infrastructure. The attack halted operations at all four U.S. Fairlife facilities; Canadian production remained unaffected.
Approximately 11 days after the initial disclosure, around July 27, Coca-Cola acknowledged that the intrusion involved the "taking of certain data." The company has not provided specifics on the volume or type of information compromised.
A ransomware group identifying itself as Anubis claimed responsibility for the attack, alleging it exfiltrated approximately 1 terabyte of corporate data. This figure has not been verified by Coca-Cola or independent investigators.
The incident underscores a broader shift in ransomware tactics observed throughout 2026, where threat groups increasingly target operational technology and physical production systems rather than relying solely on data encryption. By disrupting supply chains and manufacturing operations, attackers gain additional leverage for extortion demands.
Fairlife, which Coca-Cola fully acquired in 2020, produces ultra-filtered milk, protein shakes, and other dairy products. The temporary production suspension affected U.S. distribution, though the company did not disclose the duration of the outage or whether it paid any ransom demand.
Security researchers note that industrial control systems in food and beverage manufacturing have become priority targets for ransomware operators. The Fairlife incident demonstrates how quickly cyber intrusions can cascade from IT networks into physical operations, forcing major corporations to halt production lines.
Coca-Cola stated it engaged third-party cybersecurity experts to support its investigation and remediation efforts. The company has not indicated when it expects to provide additional details on the scope of the data compromise.
The attack joins a growing list of 2026 ransomware incidents targeting consumer goods manufacturers, highlighting vulnerabilities in operational technology security and business continuity planning across the industry.