Overview
- Coca‑Cola first disclosed a Fairlife cybersecurity incident in an SEC filing on July 16 and said it temporarily halted production at four U.S. plants to investigate.
- The Anubis ransomware group publicly claimed responsibility on July 20 and said it had encrypted systems and exfiltrated roughly 1 terabyte of data.
- Coca‑Cola told reporters on Monday that the intrusion involved the taking of certain data and that the majority of U.S. Fairlife production has now resumed.
- Security outlets report the attacker’s leak‑site timer expired and the stolen files were made available for download, although Coca‑Cola has not confirmed the volume or sensitivity of the posted data.
- The company engaged outside cybersecurity advisers, notified law enforcement, declined to negotiate with attackers, and says product safety, retail availability, and material financial impact are not expected to be harmed; the case underscores growing ransomware risk to food supply chains.