Skip to main content
Rethinking Email Security for the AI Era, August 25th
Blog

Fairlife: When a Ransomware Claim Became a Confirmed Breach

AUGUST 23, 20265 MIN READ
Marshall BennettMarshall Bennett
Chat with a real personno Slack required
Fairlife: When a Ransomware Claim Became a Confirmed Breach

Key takeaways

  • In early July 2026, an intruder entered Fairlife’s production systems; Coca-Cola disclosed the incident in a July 16 SEC filing after production had stopped at all four U.S. Fairlife plants, while Canadian operations continued and product quality and safety were not affected.
  • The intrusion was tied to CitrixBleed 2 (CVE-2025-5777) in Citrix NetScaler appliances, which could leak session tokens from memory; a stolen valid token could let an attacker impersonate a logged-in employee and bypass MFA without needing a password.
  • The article stresses that patching CitrixBleed 2 alone is not enough: if a token was stolen before the fix, it remains usable until it is manually revoked, leaving attackers with persistent access even after updates are applied.
  • After Coca-Cola’s SEC filing, the Anubis ransomware operation claimed responsibility, said it exfiltrated about 1 TB of data, and later posted Fairlife on its leak site; Coca-Cola refused to negotiate, reported the incident to law enforcement, and Anubis published the files on July 27.
  • Anubis, active since December 2024 and run by operators using the names superSonic and Anubis__media, had grown into a ransomware-as-a-service operation with affiliates and an optional wipe mode that can permanently destroy files instead of only encrypting them.
  • The attack hit a sector already under heavy pressure: the Food and Agriculture ISAC counted 205 ransomware incidents in the industry in the first several months of 2026, nearly 5% of all ransomware attacks tracked that year, underscoring the time-sensitive risk researchers Louise Manning and Aleksandra Kowalska highlighted for food supply chains.

How a stolen login session shut down Coca-Cola's dairy production, and why a ransom that was never paid still cost the company its data.

An Adaptive Security series on the ransomware attacks that shaped modern cyber defense. Hub: A History of Notable Ransomware Attacks. Previously: Coca-Cola.

Four years after Stormous’s unverified claim against Coca-Cola dissolved into nothing, a second ransomware attack tied to the same company left no room for that kind of ambiguity. In early July 2026, an intruder got into the systems running production at Fairlife, the Coca-Cola-owned brand behind ultra-filtered milk and protein shakes. By the time Coca-Cola disclosed the incident in a July 16 filing with the Securities and Exchange Commission, production had already stopped at all four of Fairlife’s United States plants. Fairlife’s Canadian operations kept running the whole time, and Coca-Cola said the disruption never touched the quality or safety of any product on a shelf.

A Way In That Outlasted the Patch

The attacker’s entry point traces back to a flaw in Citrix NetScaler appliances known as CitrixBleed 2, tracked as CVE-2025-5777. A session token is the small piece of data a website or app gives your device after you log in, so it can recognize you as already signed in without asking for your password on every click. The CitrixBleed 2 flaw let an attacker send a deliberately broken request to the appliance and get back fragments of its memory in response, including other people's session tokens, tokens that were never supposed to leave the building. With one of those tokens, an attacker could impersonate an already logged-in employee and walk past multi-factor authentication entirely, since the system had no reason to question a session it believed was already verified.

The complication runs deeper than a missed patch. Installing the fix closes the hole in the appliance, but it does nothing to cancel a session token an attacker already stole before the patch went in. That token keeps working until someone manually revokes it, which means a company can apply every update correctly and still leave a stolen key sitting in an attacker’s pocket.

The Group Renting the Access

Days after Coca-Cola’s SEC filing, a ransomware operation called Anubis claimed responsibility and said it had pulled about a terabyte of data out of Fairlife's systems. Anubis had only existed since December 2024, when its operators, going by the names superSonic and Anubis__media, started advertising on cybercrime forums. In under two years it built a full ransomware-as-a-service operation, complete with affiliate programs for partners who wanted to sell stolen access rather than run an attack themselves. Its most aggressive feature is optional: a wipe mode that permanently destroys a victim’s files rather than merely encrypting them, removing the fallback of decrypting later even for a victim who eventually finds the attacker’s key. Coca-Cola never confirmed whether that mode was used against Fairlife.

A Ransom Coca-Cola Did Not Pay

Anubis listed Fairlife on its dark web leak site on July 20 and gave Coca-Cola a deadline to negotiate. Coca-Cola reported the intrusion to law enforcement and declined. When the deadline passed on July 27, Anubis published the stolen files. Coca-Cola confirmed that data had been taken but never confirmed how much or what kind, a caution very different from how quickly it had confirmed the production shutdown itself.

Fairlife’s shutdown landed inside a sector already absorbing a wave of similar attacks. The Food and Agriculture Information Sharing and Analysis Center counted 205 ransomware incidents against the industry through the first several months of 2026 alone, nearly five percent of every ransomware attack tracked anywhere that year.

Dr. Louise Manning, a food supply chain researcher whose work on ransomware and food defense appeared in the peer-reviewed journal Trends in Organized Crime, has described why this sector carries a distinct kind of risk. “The globalisation, digitalisation and integration of food supply chains can increase the level of vulnerability to ransomware,” she and co-author Aleksandra Kowalska wrote, noting that ransomware operates as “an organised food defence threat that can operationalise both extortion and sabotage,” carried out by attackers who remain “remote, non-visible and often anonymous.”

A dairy plant cannot pause the way an office can pause email. Milk keeps arriving from farms on a schedule nobody controls from a keyboard. That kind of time pressure is exactly the leverage Manning and Kowalska’s research says attackers count on across food and agriculture, citing FBI warnings that even seed and fertilizer suppliers make attractive targets precisely because their operations are too time-critical to sit idle during a negotiation.

The kind of theft Anubis ran looks nothing like the Telegram poll that put Coca-Cola in the news in 2022. A stolen session token needs no malware and no tricked click. It only needs to still be valid. Adaptive Security studies this history because watching how a login behaves, not only whether a password was typed correctly, is becoming as important as watching for the phishing message that used to be the whole story.

Next in this series: Ingram Micro, the technology distributor whose ransomware attack traced back to a single set of stolen VPN credentials.

Get started with Adaptive Security

Get started

Human security for the AI era.