Coca-Cola Ransomware Attack Analysis: The Fairlife Attack, Timeline, and What Was Actually Confirmed

Key takeaways
- The Coca-Cola ransomware event struck fairlife, LLC, a wholly owned dairy subsidiary, and halted all United States production while Canadian operations continued.
- The Fairlife ransomware attack was disclosed by The Coca-Cola Company through a securities filing on the day it was detected, before any group had claimed responsibility.
- The Anubis ransomware group claimed the intrusion days later, and The Coca-Cola Company has never publicly confirmed that attribution.
- Most of what circulates about the Coca-Cola ransomware incident originates with the cyberattackers rather than with the company or investigators.
- The Coca-Cola Company declined to negotiate, notified law enforcement, and restored the majority of production before the extortion deadline expired.
- How cyberattackers first reached fairlife's systems has never been disclosed and remains unestablished.
The Coca-Cola Company disclosed on July 16, 2026 that fairlife, LLC, its wholly owned dairy subsidiary, suffered a ransomware event that halted all United States production. The Anubis ransomware group later claimed responsibility. The Coca-Cola Company refused to negotiate, restored most production by July 27, 2026, and confirmed that data was taken.

Coverage of the Coca-Cola ransomware incident settled quickly into a fixed set of figures, most of which originate from the intrusive group rather than The Coca-Cola Company or any investigator. Separating the confirmed record from the claimed one changes what security leaders can actually learn from the case. This analysis covers:
- What The Coca-Cola Company confirmed about the Coca-Cola ransomware event, and what it declined to say;
- A dated account separating the intrusion, the detection, the disclosure, and the Anubis ransomware group claim;
- Why the entry point behind the Fairlife ransomware attack remains unestablished despite widespread reporting to the contrary;
- What the Fairlife data breach exposed, presented as claimed material alongside confirmed material;
- The financial, regulatory, and Coca-Cola data breach lawsuit consequences that followed.
Published breach data circulates indefinitely once a leak site releases it. Adaptive Security monitors external exposure so security teams learn what surfaced about their organization before criminals weaponize it.
Quick Facts: The Coca-Cola Ransomware Attack
The table below provides a consolidated overview of the Coca-Cola ransomware incident. Each entry is assigned a confidence label to differentiate public narrative claims from confirmed company disclosures and unverified claims from the group that claimed responsibility. Entries labeled “claimed” rely exclusively on statements made by the Anubis ransomware group.
| Field | Detail | Confidence |
|---|---|---|
| Victim | fairlife, LLC, a wholly owned subsidiary of The Coca-Cola Company | Confirmed |
| Parent disclosure | SEC Form 8-K, Item 8.01, July 16, 2026 | Confirmed |
| Threat actor | Anubis ransomware-as-a-service group, formerly Sphinx | Claimed by the group; not confirmed by the company |
| Attack date | Approximately July 9, 2026, roughly one week before disclosure | Claimed by the Anubis ransomware group |
| Detection date | July 16, 2026 | Confirmed |
| Initial access vector | Not disclosed | Unknown |
| Systems affected | Production-related systems; the Anubis ransomware group claims Nutanix infrastructure across roughly 500 hosts | Confirmed in part; the remainder claimed |
| Data taken | Confirmed that data was taken; volume and categories not disclosed | Confirmed that theft occurred |
| Volume claimed | Approximately 1 terabyte, per the Anubis ransomware group | Claimed; never verified |
| Ransom demanded | No figure stated publicly | Claimed by the Anubis ransomware group |
| Ransom paid | No; The Coca-Cola Company did not negotiate | Confirmed |
| Facilities affected | Four United States production facilities; Canadian operations unaffected | Confirmed |
| Downtime | July 16 to July 27, 2026, approximately 11 days to majority restoration | Confirmed |
| Data published | July 27, 2026, after the deadline expired | Confirmed |
| Free decryptor | None available for this strain | Confirmed |
The Form 8-K filed with the US Securities and Exchange Commission on July 16, 2026 remains the primary record for every confirmed row above.
What Happened in the Coca-Cola Ransomware Attack
The Coca-Cola ransomware incident became public on the same day The Coca-Cola Company detected it, which is unusually fast for an incident of this scale. The filing described unauthorized third-party access to production-related systems and an immediate suspension of United States manufacturing. Product quality and food safety were not affected, which places this incident in corporate systems in preference to process control. Readers new to the category may find background on how ransomware attacks work useful context.
What fairlife Is and Why the Outage Mattered
fairlife, LLC is a Chicago-based ultra-filtered dairy producer whose portfolio includes Ultra-Filtered Milk, Core Power protein shakes, and Nutrition Plan. The Coca-Cola Company acquired the remaining stake in 2020, following a joint venture with Select Milk Producers, making fairlife a wholly owned subsidiary.
Two different measures of the brand's scale circulate in coverage and are frequently conflated. fairlife surpassed $1 billion in annual revenue starting in 2022, a company-level figure. According to The Motley Fool's A Ransomware Attack Just Halted Coca-Cola's Fairlife Production and Knocked the Stock Down 4% 2026, fairlife generated approximately $4 billion in retail sales in 2024, which measures consumer spending and not revenue booked by the subsidiary.
The brand operates four United States production facilities alongside Canadian operations, so a halt across the United States footprint stopped domestic manufacturing entirely.
What the Form 8-K Disclosed
The Coca-Cola Company filed under Item 8.01, Other Events. The filing stated that fairlife identified unauthorized access by a third party to a portion of its systems, including production-related systems, in connection with a ransomware event.
The company reported that it activated incident response and business continuity protocols, engaged outside advisors, and notified law enforcement. It suspended United States fairlife production while Canadian operations continued without interruption.
What the Disclosure Left Out
The filing named no threat actor. It did not acknowledge data theft at that stage, and it identified no entry point, no scope of compromise, and no impact assessment.
The Coca-Cola Company stated directly that the full scope, nature, and impacts of the incident were not yet known. That absence of detail itself is a durable fact about this case, since much of it has still not been filled in.
Regulatory disclosure obligations reach every subsidiary a parent company owns. Adaptive Security gives security leaders visibility into exposure across the wider corporate group, before a filing deadline forces the question.
Timeline of the Coca-Cola Ransomware Attack
Four separate dates govern the Coca-Cola ransomware incident, and coverage routinely collapses them into one. The date cyberattackers claim they gained access, the date fairlife detected the intrusion, the date The Coca-Cola Company disclosed it, and the date the Anubis ransomware group claimed responsibility are all distinct. Only some of them are established, and the difference affects how much importance each carries.
Four Dates That Are Often Collapsed Into One
The earliest date rests entirely on assertion. The Anubis ransomware group claims it gained access around July 9, 2026, roughly one week before disclosure, and no source has independently confirmed that dwell time.
Detection and disclosure fall together on July 16, 2026. fairlife identified unauthorized access, The Coca-Cola Company suspended all United States production, and the Form 8-K reached the US Securities and Exchange Commission the same day.
Attribution arrived four days after that. The group listed fairlife on its leak site on July 20, 2026, claiming 1 terabyte of data and encryption of Nutanix infrastructure while posting a countdown, then confirmed responsibility publicly on July 21, 2026.
The fourth date closed the extortion window. On July 27, 2026 the deadline expired, The Coca-Cola Company confirmed that data had been taken and that the majority of production had resumed, and the group published the cache it claimed to hold.
What Followed the Coca-Cola Ransomware Attack Extortion Deadline
Three developments followed the July 27, 2026 deadline:
- The Coca-Cola Company reported second-quarter results on July 28, 2026 covering a period that ended July 3, 2026, before the incident occurred;
- A class action was filed in August 2026, with former fairlife employee Christina Montalvo as lead plaintiff;
- The Anubis ransomware group issued further statements on August 16, 2026 about scope and about the absence of negotiation, all of which remain claims rather than confirmed detail.
Cyberattackers often hold access for days before anyone notices. Adaptive Security shortens that window by surfacing exposed credentials and leaked corporate data as soon as they appear externally.
Coca-Cola Ransomware Attack: Who Is the Anubis Ransomware Group?
The Anubis ransomware group operates as a ransomware-as-a-service business, meaning the core operators build and maintain the malware while affiliates carry out intrusions and share proceeds. That structure matters when weighing its statements, because everything the group has said about fairlife comes from an interested party seeking payment. The Coca-Cola Company has never confirmed the attribution.
Origins and Operating Model
The operation emerged publicly in December 2024 as a rebrand of the earlier Sphinx strain, and was advertised on Russian-language cybercrime forums in February 2025. Its affiliate program pays 80% to affiliates for standard ransomware work, with reduced splits for data-extortion-only arrangements and for selling access to other criminals.
No public indictments, sanctions, arrests, or takedowns of the operation existed as of August 19, 2026. Background on ransomware-as-a-service operations and affiliate models explains how that division of labor shapes victim selection.
The Optional Wipe Capability
The strain includes an optional mode that overwrites file contents outright, leaving files present at zero bytes. Where that mode runs, recovery becomes impossible even after payment, because no decryption key can restore contents that no longer exist.
The capability changes the calculation for any organization weighing payment, since paying cannot guarantee restoration. Its presence in the toolkit does not establish that it ran in any particular intrusion, including this one.
Victims, Geography, and Sectors
Targeting skews toward the United States, the United Kingdom, Australia, France, and Canada, across healthcare, manufacturing, technology, business services, and financial services. According to Tech Times's Anubis Ransomware Hits 91 Victims: Citrix Bleed 2 Bypasses MFA Before Encryption 2026, the operation had claimed 91 victims on its leak site, with 11 added in June 2026. That spread across unrelated sectors and geographies is consistent with opportunistic selection instead of deliberate targeting of any one industry.
How Much Weight the Group's Claims Carry in the Coca-Cola Ransomware Attack
The group told reporters that fairlife had no chance of recovering without its decryption key. The Coca-Cola Company restored the majority of production within roughly 11 days without paying, which contradicts that assertion directly. Leak-site victim counts also drift between trackers, ranging from 83 to roughly 100 depending on the snapshot date.
Ransomware-as-a-service operations recruit affiliates faster than most defenses adapt. Adaptive Security tracks the external exposure those affiliates buy and sell, giving security teams warning ahead of intrusion.
How the Coca-Cola Ransomware Attack Unfolded and What Remains Unknown

The entry point behind the Fairlife ransomware attack has never been established. That absence is the most consequential fact in this section, because several outlets have filled the gap with material that does not describe this incident. What follows sets out what The Coca-Cola Company disclosed, what the Anubis ransomware group asserted, and where reporting went wrong.
What The Coca-Cola Company Has Disclosed About Entry
The Coca-Cola Company disclosed no initial access vector at any point. Cybersecurity Dive reported on July 21, 2026 that the company had not provided details about how cyberattackers gained access to systems, and Food Dive repeated on July 27, 2026 that the company did not explain the entry point. The trade press has therefore confirmed the absence rather than filling it.
Why Strain-Level Tradecraft Is Not Incident Evidence
The vectors circulating in coverage describe behavior observed in other intrusions attributed to the same operation, rather than findings about fairlife. Two vendor accounts of that behavior disagree with each other.
One account leads with stolen virtual private network credentials and exploitation of internet-facing devices. The other, from SOCRadar via GovInfoSecurity on July 21, 2026, states that affiliates most commonly gain access through spear-phishing emails carrying malicious documents or compressed executables. Neither account has been applied to fairlife by any source, which means neither can be presented as this incident's vector.
Where the Coca-Cola Ransomware Attack Reporting Went Wrong
Two errors recur across coverage:
- A widely shared July 28, 2026 headline asserts that a specific vulnerability opened the door at fairlife, while the article body establishes only that affiliates exploited it in other intrusions;
- Four outlets print the CitrixBleed 2 identifier incorrectly with an extra digit; the correct identifier is CVE-2025-5777.
What Anubis Claims About Encryption and Scale
The Anubis ransomware group claimed it fully encrypted fairlife's Nutanix infrastructure, and stated on August 16, 2026 that roughly 500 hosts were affected. Both figures are claims by the group and have not been confirmed by The Coca-Cola Company or by any investigator.
An unknown entry point leaves defenders guessing which control failed. Adaptive Security narrows that uncertainty by mapping the credential and data exposure an organization already carries in public.
Coca-Cola Ransomware Attack: Operational Impact Across Four US Facilities
The Coca-Cola ransomware incident stopped manufacturing at a brand generating billions in annual retail sales, yet the consequence customers noticed was minimal. That gap between operational damage and commercial damage is the most instructive part of the impact record. It was closed by inventory rather than security capability.
The Production Halt Due to Coca-Cola Ransomware Attack and Its Duration
All four United States fairlife production facilities halted on July 16, 2026, including a facility in the Rochester, New York area. Canadian production continued without interruption throughout the outage.
The Coca-Cola Company reported on July 27, 2026 that the majority of United States production had resumed, an approximately 11-day window from suspension to majority restoration. The company also stated that teams were continuing work to restore remaining affected systems and operations, so full restoration extended past the production milestone.
Why Retail Shelves Stayed Stocked
Retail availability held because existing finished inventory covered the outage. That buffer sits outside the security function entirely. It absorbed the disruption that would otherwise have reached consumers.
The Coca-Cola Company stated that product quality and safety were not impacted at any point. According to The Motley Fool's A Ransomware Attack Just Halted Coca-Cola's Fairlife Production and Knocked the Stock Down 4% 2026, shares in The Coca-Cola Company fell approximately 4% the day after disclosure, a short-lived move instead of a lasting revaluation.
Production lines stop when corporate systems do, even when process control stays untouched. Adaptive Security helps manufacturers reduce the external exposure that draws opportunistic cyberattackers toward them.
Coca-Cola Ransomware Attack: What Was Taken, Claimed Versus Confirmed
The most repeated number attached to the Fairlife data breach originates with the party that took the data. The Coca-Cola Company has confirmed that theft occurred while declining to state volume, categories, or the number of individuals affected. Keeping those two records apart is the only accurate way to describe what was lost.
What the Anubis Group Claims About the Coca-Cola Ransomware Attack
On volume, the Anubis ransomware group claims it took approximately 1 terabyte of confidential data. The Coca-Cola Company has confirmed only that data was taken, and has published no figure of its own.
On systems, the group claims full encryption of Nutanix infrastructure across roughly 500 hosts. The Coca-Cola Company has confirmed that production-related systems were accessed, which is a narrower statement covering access in preference to encryption or host counts.
On content, the group claims the cache holds HR records, engineering and technical documentation, and production data. The Coca-Cola Company has disclosed no categories, no volume, and no count of affected individuals against that description.
Help Net Security stated on July 28, 2026 that The Coca-Cola Company had not confirmed the volume or nature of any data stolen, and that the group's claims remain independently unverified. SecurityWeek separately noted that extortion groups routinely exaggerate stolen file counts, since the perceived value of a cache drives the pressure to pay.
What The Coca-Cola Company Has Confirmed
The Coca-Cola Company confirmed on July 27, 2026 that the incident involved the taking of certain data. It disclosed no category, no volume, and no count of affected individuals alongside that confirmation.
The exposure created by publication persists regardless of how large the cache actually is. Any published corporate material supports impersonation of executives and suppliers, and it can be used to build convincing approaches to named employees. Organizations facing that situation benefit from continuous exposure monitoring that establishes what has surfaced.
Why the Class Action Language Is Not a Data Category
The detail describing names and Social Security numbers originates in the class action complaint as an allegation. It is a pleading rather than a finding, and The Coca-Cola Company has not confirmed it.
Pleadings routinely assert the broadest plausible set of categories before discovery narrows them. ClassAction.org stated on July 17, 2026 that fairlife had not confirmed whether any personal information was accessed, stolen, or compromised.
What Remains Uncounted and Unnotified
No affected-individual count had been published as of August 19, 2026. No state attorney general breach notification had been filed by that date either, across the Vermont, Washington, Texas, and California directories.
Stolen corporate records fuel impersonation campaigns long after an incident closes. Adaptive Security identifies what has surfaced publicly, so security teams can prepare employees for the follow-on cyberattacks.
How Fairlife Restored Production Without Paying After the Coca-Cola Ransomware Attack

The Anubis ransomware group stated that recovery was impossible without its decryption key, and the record contradicts that claim. The Coca-Cola Company restored the majority of United States production within roughly 11 days without negotiating. How it did so has never been explained, which limits what other organizations can copy from the outcome.
The Decision Not to Negotiate
The Coca-Cola Company did not negotiate with the group and reported the intrusion to law enforcement. The group subsequently published the cache when the July 27, 2026 deadline passed.
The group's assertion that no recovery was possible without its key was falsified by the restoration that followed. That is one of the few points in this case where a claim can be tested against a confirmed outcome.
Why the Wiper Was Almost Certainly Not Deployed
The group claimed it had fully encrypted the affected systems and that recovery required its key. That assertion is inconsistent with the destructive wipe mode, because a decryption key holds no value against files whose contents have been overwritten and nothing remains to sell.
The speed of restoration corroborates that reading. Bringing four United States facilities back within roughly 11 days would have been substantially harder against a wiped environment.
What Has Never Been Explained in the Coca-Cola Ransomware Attack
The restoration method remains undisclosed. Food Dive noted on July 27, 2026 that The Coca-Cola Company did not explain how it restored production, and nothing published establishes whether recovery came from immutable backups, unaffected redundant systems, segmentation, or rebuilds. Assuming backups is inference in preference to established fact.
No free decryptor exists for this strain, and No More Ransom lists none for this family.
Recovery without payment depends on preparation made long before the ransom note arrives. Adaptive Security strengthens the human layer that surrounds every recovery decision an incident response team makes.
Financial, Legal, and Regulatory Fallout From the Coca-Cola Ransomware Attack
Three consequences of the Coca-Cola ransomware incident are running on separate clocks. The securities disclosure resolved within days, the Coca-Cola data breach lawsuit will run for years, and the question of consumer notification has not started moving publicly at all. Each is governed by different triggers and should not be read as a single process.
Item 8.01 Versus Item 1.05
The Coca-Cola Company filed under Item 8.01, Other Events, in preference to Item 1.05, which covers material cybersecurity incidents. The first flags an event without conceding materiality; the second asserts it.
The company then stated affirmatively on July 27, 2026 that the incident has not had, and is not reasonably likely to have, a material impact on its financial condition or results of operations. According to The Coca-Cola Company's Form 10-Q for the Quarterly Period Ended April 3, 2026, the company generated $12.5 billion in revenue in the first quarter of 2026, which frames the scale against which materiality is judged.
The second-quarter results reported on July 28, 2026 covered a period ending July 3, 2026, before the incident occurred, so the first periodic filing carrying a full quarter of impact falls later in 2026. Further detail sits in quarterly filings from The Coca-Cola Company.
The Class Action and Its Allegations
A class action was filed in Atlanta in August 2026. The lead plaintiff is Christina Montalvo, a former Michigan-based fairlife employee, and the complaint alleges that the breach exposed material amounting to a resource for data thieves.
The allegations are pleadings in preference to findings. Nothing in the complaint has been established by a court, and The Coca-Cola Company has not confirmed the categories the complaint describes.
Why No State Notification Has Appeared Yet
State notification clocks generally run from the determination that personal information was involved, rather than from the discovery of an incident. That distinction explains why no filing had appeared as of August 19, 2026 without implying concealment.
Two outcomes remain open. Notifications may follow once forensic work concludes, or The Coca-Cola Company may determine that the material taken was corporate in nature and triggered no consumer notification obligation.
Litigation and regulatory filings follow a breach for years after operations recover. Adaptive Security documents cybersecurity awareness training and exposure monitoring that support an organization's compliance position.
Coca-Cola Ransomware Extortion Claims Before Fairlife

Several distinct events are routinely merged under the Coca-Cola ransomware search term, and most were never confirmed by any Coca-Cola entity. Some involved bottlers or franchise partners rather than The Coca-Cola Company itself. Others involved no encryption at all, which places them outside the ransomware category entirely.
The 2022 Stormous Claim
The Stormous group claimed on approximately April 25, 2022 that it had taken 161 GB from The Coca-Cola Company. Scott Leith, then Vice President of external and financial communications, said the company was investigating the validity of the claim and coordinating with law enforcement.
BleepingComputer noted no evidence of file-encrypting malware, which makes the episode data extortion in preference to ransomware. Researchers at Digital Shadows and Netenrich doubted the claim, citing the group's history of recycled data. It was never validated.
The 2025 Claims Against Bottlers and Partners
Three claims from 2025 involve entities other than The Coca-Cola Company:
- The Everest group listed "Coca-Cola" on May 22, 2025, though samples showed the actual victim was Coca-Cola Al Ahlia Beverages Company, the Dubai-based bottler trading as Gulf Coca-Cola Beverages;
- The Gehenna group offered a Coca-Cola Europacific Partners Salesforce database in early May 2025, an incident involving stolen credentials and no encryption;
- Separate claims named Coca-Cola FEMSA and Viking Coca-Cola, both relayed through leak-site posts rather than confirmed by the organizations.
Coverage of earlier extortion claims involving major brands shows how often a parent brand name attaches to a bottler's incident.
Earlier Incidents Miscategorized as Coca-Cola Ransomware Attack
Two further episodes appear in ransomware chronologies without belonging there. A January 2014 disclosure concerned unencrypted laptops taken by a former employee, exposing data on 74,000 people. A May 2018 disclosure, following a September 2017 discovery, concerned a former employee of a Coca-Cola subsidiary who took an external hard drive holding data on about 8,000 workers.
Both were physical and insider incidents involving no ransomware and no extortion demand.
Extortion groups recycle old data and claim fresh breaches to pressure large brands. Adaptive Security verifies real exposure from opportunistic noise before teams commit resources.
Lessons for Enterprises From the Coca-Cola Ransomware Attack
The lessons below are drawn only from what is established about the Coca-Cola ransomware incident. Control status at fairlife has never been disclosed, so any control described as absent or failed is inference rather than fact. What can be stated is what happened and what it demonstrates about corporate structure, manufacturing dependency, and the durability of stolen data.
Subsidiary Risk Becomes Parent-Company Disclosure Risk
fairlife is a wholly owned subsidiary, yet The Coca-Cola Company as the registrant carried the securities disclosure obligation and filed the Form 8-K, signed by Monica Howard Douglas, Executive Vice President and Global General Counsel.
Disclosure procedures therefore need to span corporate boundaries, since an intrusion at a subsidiary produces a filing obligation at the parent.
An IT Compromise Can Stop Physical Production
All United States production stopped while The Coca-Cola Company simultaneously confirmed that product quality and safety were unaffected. That combination locates the disruption in the connective tissue between corporate systems and production systems in preference to process control itself. Segmentation status at fairlife is unknown, so describing this as a segmentation failure would be inference.
Refusing to Pay Was Viable
The Coca-Cola Company declined to negotiate, notified law enforcement, and restored the majority of production within roughly 11 days. The group's claim of unrecoverable encryption was falsified by that outcome.
The mechanism that made recovery possible remains undisclosed, so the transferable lesson is that refusal was viable here rather than that any specific control delivered it.
Data Theft Outlives the Outage
Production recovered in under two weeks. The cache published on July 27, 2026 is permanent, and no recovery timeline reverses publication. Exposure therefore continues after operational recovery completes, extending into impersonation, fraud, and competitive-intelligence risk.
Lessons drawn from one incident fade unless employees rehearse them. Adaptive Security turns documented cyberattack patterns into cybersecurity awareness training that measurably changes how staff respond under pressure.
How Adaptive Security Helps Organizations Protect Themselves From Ransomware Attacks

The outcome a security leader needs after an incident like the Coca-Cola ransomware event is not a theory about the entry point, which in this case was never disclosed. It is an accurate picture of what now sits outside the organization: which credentials have surfaced, which corporate material has been published, and which employees have become plausible impersonation targets as a result.
Adaptive Security delivers that picture through continuous monitoring exposure after a data leak, tracking leaked credentials and published organizational data across external sources. The platform component responsible for this work surfaces exposure as it appears, giving security teams an evidence-based starting position rather than an assumption about which control failed. That evidence also supports the disclosure and compliance decisions that follow any confirmed data theft.
Published caches sustain risk against employees long after operations recover, because criminals mine them for names, reporting lines, and supplier relationships to build convincing approaches. Adaptive Security connects that exposure to cybersecurity awareness training and phishing simulations, so the people named in a leak receive preparation matched to the way they will actually be approached.
Exposure that sits unmonitored becomes the raw material for the next cyberattack. Adaptive Security surfaces leaked credentials and published corporate data continuously, giving security teams a defensible starting position.
Frequently Asked Questions About Coca-Cola Ransomware
Was Coca-Cola Hit by Ransomware?
Yes. The Coca-Cola Company disclosed on July 16, 2026 that fairlife, LLC, its wholly owned dairy subsidiary, suffered a ransomware event affecting production-related systems. All United States fairlife production was suspended while Canadian operations continued. The company confirmed on July 27, 2026 that the incident also involved the taking of certain data.
Who Is Behind the Fairlife Ransomware Attack?
The Anubis ransomware group claimed responsibility, listing fairlife on its leak site on July 20, 2026 and confirming the claim publicly on July 21, 2026. The Coca-Cola Company has never publicly confirmed that attribution. The group operates as a ransomware-as-a-service business and emerged in December 2024 as a rebrand of the earlier Sphinx strain.
Did Coca-Cola Pay the Ransom?
No. The Coca-Cola Company did not negotiate with the Anubis ransomware group and reported the intrusion to law enforcement. The group published the cache it claimed to hold after the July 27, 2026 deadline expired without payment. The company restored the majority of United States production within roughly 11 days.
What Data Was Stolen From Fairlife?
The Coca-Cola Company confirmed that certain data was taken but disclosed no volume, no categories, and no count of affected individuals. The Anubis ransomware group claims approximately 1 terabyte including HR records, engineering documentation, and production data. That claim originates with the group alone and has never been independently verified.
Is Fairlife Milk Safe After the Ransomware Attack?
Yes. The Coca-Cola Company stated in its July 16, 2026 securities filing that product quality and safety were not impacted by the incident. The intrusion affected corporate and production-related systems rather than process control. Retail availability was largely maintained through existing finished inventory during the production suspension.
How Long Was Fairlife Production Down?
United States fairlife production was suspended on July 16, 2026, and The Coca-Cola Company reported on July 27, 2026 that the majority had resumed, an approximately 11-day window. Canadian operations continued throughout. The company noted that work continued to restore remaining affected systems, so full restoration extended beyond the production milestone.
Is There a Coca-Cola Data Breach Lawsuit?
Yes. A class action was filed in Atlanta in August 2026, with former fairlife employee Christina Montalvo as lead plaintiff. The complaint alleges that personal information including names and Social Security numbers was exposed. Those allegations are pleadings rather than findings, and The Coca-Cola Company has not confirmed which data categories were involved.
Can Files Encrypted by Anubis Ransomware Be Recovered?
No free decryptor exists for this strain, and No More Ransom lists none for this family. Recovery is realistic only from backups or unaffected redundant systems. The strain also includes an optional mode that overwrites file contents, meaning payment cannot guarantee restoration. How fairlife restored production has never been disclosed by The Coca-Cola Company.
Questions about one incident rarely stay academic once similar exposure appears internally. Adaptive Security helps organizations answer them with evidence drawn from their own external risk picture.
As experts in cybersecurity insights and AI threat analysis, the Adaptive Security Team is sharing its expertise with organizations.
Get started with Adaptive Security
Get started


