Just Earth News | @justearthnews | 28 Jul 2026, 10:11 pm Print
Coca-Cola Coca-Cola-owned Fairlife resumes production days after cyberattack. Photo: Unsplash
Coca-Cola has announced that fairlife, LLC, its dairy subsidiary, has resumed the majority of production at its four manufacturing facilities in the United States after recovering from a cybersecurity incident involving unauthorized third-party access to some of its systems.
The company had earlier disclosed that fairlife was hit by a ransomware attack.
Providing details about the incident, the company said in a statement: "This event involved access by an unauthorized third party to a portion of the company’s systems and taking of certain data, and a temporary suspension of production operations."
Fairlife said it is continuing to work diligently to restore the remaining impacted systems and operations.
"Retail availability of fairlife products has been largely unimpacted, due to the availability of existing inventory. Product quality and safety have not been impacted," the company said.
The company also noted that, based on the information currently available, it believes the incident has not had, and is not reasonably likely to have, a material impact on its financial condition or results of operations.
Meanwhile, the ransomware group Anubis has claimed responsibility for the cyberattack on fairlife.
According to cybersecurity researchers at Arctic Wolf, cited by Cybersecurity Dive, the threat group claims it encrypted Fairlife's servers and exfiltrated approximately 1TB of data during the attack.
Anubis has reportedly threatened to publish the stolen data if its ransom demands are not met within a week. Researchers also shared screenshots from the group's data leak site, according to the report.
Arctic Wolf describes Anubis as a Ransomware-as-a-Service (RaaS) operation that relies on affiliates for attacks and supports data theft, file encryption, and optional destructive data-wiping capabilities. The group emerged in late 2024 as a rebranding of the Sphinx ransomware operation, marked by a change in the encrypted file extension from .sphinx to .anubis.
Commenting on the group's tactics, Stefan Hostetler, Staff Threat Intelligence Researcher at Arctic Wolf, told Cybersecurity Dive: "Anubis affiliates have repeatedly secured initial access by exploiting internet-facing vulnerabilities and abusing stolen VPN credentials. In our investigations, we've seen attackers take advantage of vulnerabilities that were not new or especially sophisticated, underscoring a persistent reality that threat actors often succeed by exploiting known weaknesses that organizations haven't fully remediated."
- 'Money won't matter': Elon Musk makes stunning 2036 prediction about future
- Samsung unveils Galaxy Watch Ultra2 and Galaxy Watch9 with AI-powered health features
- Massive data breach rocks Australia's Origin Energy; hacker issues ultimatum
- SK Group, NVIDIA make major AI power move with expanded partnership
- Samsung unveils Galaxy Z Fold8 Ultra, Fold8 and Flip8 with enhanced AI

