Fairlife Ransomware Attack: What Happened and What Lessons Were Learned From the Anubis Breach

Key takeaways
- The entry point was never confirmed, and the CitrixBleed 2 attribution circulating in secondary summaries is not established fact. Coca-Cola has disclosed no vector for the Fairlife ransomware intrusion in any filing or statement, and the only account of one comes from the cyberattackers.
- Production likely halted for documentation reasons, while the product itself remained safe. While not explicitly disclosed by the company, regulated food manufacturing relies on business systems for batch records, allergen control, and labeling; losing these systems renders the output undocumentable.
- An operator that can destroy its own decryption keys removes decryption from the negotiating table. Anubis carries a wipe mode that permanently erases file contents, and no Anubis decryptor appears on No More Ransom.
- No customer records have been reported in the published data, only internal company information, which increases rather than reduces downstream risk.
- Buffer inventory, a supply chain decision more than a security control, protected retail availability. Finished goods already in distribution absorbed 11 days of suspended production, making stock a measurable component of recovery capacity.
The Fairlife ransomware attack was a July 2026 intrusion by the Anubis ransomware group into Fairlife, LLC, the dairy subsidiary of The Coca-Cola Company. Coca-Cola disclosed on July 16, 2026, that US production operations were temporarily suspended. Anubis published the stolen data on July 28, 2026, and claimed it amounted to 671 GB.
Two questions remain unanswered publicly. Coca-Cola has not disclosed how the cyberattackers obtained access, and no public evidence establishes whether the intrusion reached the operational technology running the production floor. Both questions shape every defensive conclusion drawn from the case, and both are addressed directly below.
Organizations seeking a broader understanding of how modern ransomware operations are structured and financed can consult Adaptive Security's Ransomware: Essential 2026 Guide for Cybersecurity Teams.
Fairlife Ransomware Quick Facts
Several entries in these Fairlife ransomware quick facts derive from an interview Anubis gave to SuspectFile on August 15, 2026, summarized by DataBreaches.net. Both are established independent outlets, but the material they relay is the cyberattackers' own uncorroborated account and is labeled as a claim throughout.
| Field | Detail |
|---|---|
| Also known as | Anubis, preceded by a near-identical build named Sphinx. SOCRadar states it is "not related to the older Anubis Android banking trojan, nor to the Anubis backdoor historically associated with FIN7" |
| Operating model | Ransomware-as-a-service, with three affiliate programs advertised on the RAMP forum in February 2025 |
| Initial access vector | Not confirmed. Anubis claims "another exploitation of a vulnerability in a corporate VPN followed by brute-force attacks" |
| Strain characteristics | ECIES encryption, which KELA describes as ChaCha with ECIES; .anubis file extension; RESTORE FILES.html ransom note. None confirmed in this incident |
| Ransom demanded | Anubis claims $15 million. Coca-Cola has not disclosed a figure |
| Ransom paid | Anubis claims no contact was ever made. Coca-Cola has not addressed the question |
| Time to full privileges | Anubis claims roughly one week: "We obtained the highest privileges on all their systems. Otherwise, we would not have been able to shut down the entire production" |
| Organizations affected | fairlife, LLC, dairy subsidiary of The Coca-Cola Company. Four US facilities per Coca-Cola, five per Anubis |
| Systems affected | "A portion of its systems, including its production-related systems," per the Form 8-K. Anubis claims 500 hosts encrypted and Nutanix systems fully encrypted |
| Data compromised | 671 GB, disclosed by the attacker in a post by a since-suspended account on X. 1 TB also disclosed by the attacker on its own leak site. Coca-Cola has confirmed no volume |
| Downtime | 11 days, July 16 to July 27, 2026 |
| Free decryptor | None listed in the No More Ransom directory as of August 2026 |

What Happened in the Fairlife Ransomware Attack?
The Fairlife ransomware attack became public on July 16, 2026, when The Coca-Cola Company filed a Form 8-K. The filing stated that Fairlife, LLC "identified unauthorized access by a third party to a portion of its systems, including its production-related systems, in connection with a ransomware event." Coca-Cola activated incident response and business continuity protocols, engaged external cybersecurity advisors, and notified law enforcement.
Four distinct dates define the public record, and a fifth is entirely absent because no detection date has ever been made public.
Fairlife Ransomware Attack Timeline
| Date | Event |
|---|---|
| Not disclosed | Intrusion begins. Anubis claims roughly one week before disclosure |
| Not disclosed | fairlife identifies unauthorized access. No filing gives a detection date |
| July 16, 2026 | Coca-Cola files under Item 8.01 and announces US production suspended, Canadian operations unaffected, and that "product quality and safety have not been impacted" |
| July 16, 2026 | Coca-Cola shares dip 1% in after-hours trading |
| July 20, 2026 | Anubis lists fairlife on its data leak site |
| July 21, 2026 | Anubis claims 1 TB stolen and Nutanix systems encrypted. BleepingComputer "could not independently verify the gang's claims" |
| July 27, 2026 | Coca-Cola announces production resumed at four US facilities, confirms the "taking of certain data," and states retail availability was "largely unimpacted, due to the availability of existing inventory" |
| July 28, 2026 | Coca-Cola reports Q2 2026 results and raises full-year guidance, without reference to the incident |
| July 28, 2026 | Anubis publishes the stolen data and claims the set amounts to 671 GB |
| August 15, 2026 | SuspectFile publishes an Anubis interview claiming 500 hosts, 546,573 files, five facilities, a $15 million demand and deletion of the keys (claims) |
What Is Still Unknown About the Fairlife Ransomware Attack
Six questions remain unresolved as of August 2026, each an absence of information instead of a disputed fact.
- Initial access vector: Not confirmed by Coca-Cola, leaving only the cyberattackers' claim as evidence.
- Whether operational technology was reached: No evidence of ICS malware or controller manipulation has been published.
- Detection date and dwell time: Never disclosed, so the intrusion duration cannot be determined.
- Facility count: Four per Coca-Cola against five per Anubis, unresolved independently.
- Ransom amount: Not disclosed by Coca-Cola.
- Employee personal information: Whether the published set contains it, and whether individuals were notified.
- Data stolen: Conflicting reporting numbers from the attacker. No other reported or verified.
How Did the Fairlife Ransomware Work?
Coca-Cola has confirmed the Fairlife ransomware intrusion, the affected systems category, the production suspension, and the data theft. It has not confirmed how access was obtained, which is consistent with standard practice during an open investigation.
A correction is warranted before any technical discussion proceeds. Several secondary summaries have described CVE-2025-5777, the NetScaler vulnerability commonly called CitrixBleed 2, as the confirmed entry point at Fairlife. No filing, company statement, government advisory, or incident report establishes that.
What Anubis Said About the Fairlife Ransomware Attack
The only detailed account of the intrusion comes from the cyberattackers, and it deserves to be read as exactly that. A ransomware group giving an interview after a failed extortion attempt has clear incentives to overstate its access and present the victim as negligent. SuspectFile and DataBreaches.net can be trusted to accurately report what Anubis said, which is not the same as any of it being true.
Anubis described the intrusion as opportunistic: "It was not a targeted attack. We simply open all doors with weak locks and only then check what we have entered." At the entry point, the group claimed to have exploited a corporate VPN vulnerability, followed by brute-force attacks against weak passwords.
If that framing is accurate, it changes the lesson of the incident. A targeted campaign implies an adversary willing to invest heavily against one victim. Indiscriminate scanning that happened to find an exposed gateway implies something more uncomfortable: that scale and security budget offer no protection against exposure nobody was tracking.
Why Patching the Edge Device Would Not Have Been Enough
Applying a patch to an internet-facing appliance closes the vulnerability without evicting a cyberattacker who already used it. This distinction between remediation and eviction is the most transferable lesson from edge appliance compromises, and it holds regardless of which vulnerability was involved at Fairlife.
CVE-2025-5777 illustrates the mechanism. NIST records it as an "insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway," with a CVSS v4.0 base score of 9.3 (Critical).
CISA added it to the Known Exploited Vulnerabilities Catalog on July 10, 2025, with a due date of July 11. That one-day window reflects how quickly it was being exploited. The flaw leaks memory contents, which may include valid session tokens.
Session tokens harvested before a patch remain valid after it. Security researcher Kevin Beaumont documented on July 14, 2025, that Citrix's own remediation guidance "doesn't clear all session cookies which are leaked by the vulnerability", leaving organizations that followed vendor instructions still carrying live cyberattacker sessions. A stolen token also bypasses multi-factor authentication, because the authentication event it represents has already occurred.
Three actions convert remediation into eviction: session invalidation as a mandatory post-patch step, rotation of every credential exposed to the compromised device, and persistence hunting. That last step matters because an operator with a week of access rarely relies on the original entry path.
Who Is Anubis? The Ransomware Group Behind the Fairlife Ransomware Attack
Anubis, the group behind the Fairlife ransomware attack, is a ransomware-as-a-service operation that emerged in December 2024. It formalized affiliate recruitment on the RAMP cybercrime forum in February 2025, according to Trend Micro. Ransomware.live, a public tracker compiled from leak site monitoring, listed 106 Anubis victims as of August 2026.
Anubis operates three revenue streams instead of one. KELA documents an encryption affiliate program that returns 80% of proceeds to affiliates, a data extortion program that returns 60% for exclusive stolen data, and an access monetization program that returns 50% to initial access brokers who supply corporate credentials.
That third program is what widens exposure beyond whoever Anubis chooses to target. An operation purchasing access from brokers inherits whatever those brokers have already harvested, so an organization's risk is not determined by whether Anubis selected it. Credentials stolen months earlier by an unrelated actor can become an Anubis intrusion the moment they change hands.
Where affiliates break in themselves, Trend Micro identifies "spear phishing emails that include malicious attachments or links" as the primary route. SOCRadar documents abuse of exposed internet-facing services, particularly Remote Desktop Protocol, though neither route is confirmed at Fairlife.
The Anubis Wiper: Why Recovery May Not Be an Option
Trend Micro documents a wipe mode parameter that "can permanently delete the contents of a file, preventing any recovery attempt." BleepingComputer describes the result as erasing "all file contents, reducing their sizes to 0 KB while keeping the filenames and structure intact."
That capability inverts the logic on which ransomware negotiation normally rests. Conventional extortion assumes the encrypted data still exists and that payment can retrieve it, which gives a victim time to evaluate options.
An operator able to destroy the asset unilaterally removes that assumption, so delay carries a risk of permanent loss. Offline, immutable backups become the only recovery path a cyberattacker cannot revoke.
How the Anubis Ransomware Attack Affected Fairlife and Coca-Cola
The most visible consequence of the Fairlife ransomware attack was the loss of physical production across every US facility for 11 days, while Canadian operations continued. Commercial impact was substantially narrower: finished goods already in distribution absorbed the gap, and Coca-Cola reported second-quarter results and raised full-year guidance eleven days after disclosure, without reference to the incident.
A cyberattack severe enough to stop every US production line at a major dairy brand produced no measurable disruption to shelves and no stated financial consequence, which raises the question of why the lines stopped at all.
Why Did Coca-Cola Decide to Shut the Factories Down?
Coca-Cola stated that product quality and safety were unaffected, even as it reported the suspension of production in the same announcement. Those statements are not in tension once the regulatory basis of food manufacturing is understood, because the constraint is documentation.
Regulated food production is legally inseparable from its paperwork. Federal regulation requires a documented food safety plan, records of monitoring and corrective actions, and records demonstrating allergen controls, all of which are retained and made available to the FDA on request under 21 CFR Part 117.
Dairy processing adds another layer, with FDA inspection guidance requiring pasteurization charts that record each product, any unusual occurrences, and the operator's signature.
Most of that recording is now performed by software. The systems that hold recipes, generate batch records, enforce allergen segregation, and drive label content sit at what the ISA-95 standard calls Level 3. That is the layer of manufacturing execution systems that "manage manufacturing operations," and they are ordinary enterprise software in every respect that matters to a cyberattacker.
Losing them does not make the milk unsafe. It makes the milk undocumentable, and an undocumented product cannot lawfully ship. It is worth noting that the explanation is an interpretation, since Coca-Cola has stated no reason, and the alternative cannot be excluded. A precautionary halt ordered the moment business systems looked compromised fits the public record equally well.
An organization with Coca-Cola's resources could not say publicly, days after disclosure, whether the intrusion had crossed into production systems. That gap suggests most manufacturers lack a current picture of which systems connect to which other systems.
A Decision Framework for Similar Situations
The #StopRansomware Guide, published in September 2023 by CISA, MS-ISAC, NSA, and the FBI, directs organizations to "determine which systems were impacted, and immediately isolate them," positioning a full shutdown as a fallback. Four questions convert that into a usable threshold.
- Evidence: What observable conditions justify stopping production, defined in advance instead of assessed by feel.
- Containment short of a stop: Whether segmentation, disabled integrations, or manual procedures can hold the line.
- Manual fallback: Whether recipe, batch record, and labeling processes can run without the affected systems.
- Authority: Who owns the call at the critical moment, delegated in writing before the incident.
The last is most often left unresolved, because halting a line carries commercial consequences a security leader is rarely empowered to accept alone, while waiting for executive availability extends cyberattacker dwell time.
What Data Was Compromised in the Fairlife Ransomware Attack and What Can Happen to It?
The data compromised in the Fairlife ransomware attack has never been itemized. Coca-Cola confirmed the "taking of certain data" without describing what it contained. Three volume figures circulate, and all three originate with the attacker, so each should be taken with a certain amount of skepticism.
| Figure | Source | What it actually evidences |
|---|---|---|
| Roughly 1 TB exfiltrated | Anubis claim | What the group says it took, unverifiable by anyone outside the intrusion |
| 671 GB | Anubis, relayed by Infosecurity Magazine | The group’s own description of the set, not an independent measurement |
| 546,573 files | SuspectFile, citing Anubis | The group’s file count for the published set |
The gap between those figures is instructive, and so is their common origin. Extortion groups have every incentive to overstate exfiltration while negotiations are live, because the claim is the leverage and inflation costs nothing. No independent party has measured what Anubis released, so every number in circulation about this breach traces back to the group that carried out the attack.
Any organization assessing an extortion claim during an active incident is evaluating an unverifiable assertion by an adversary with a direct incentive to exaggerate. Internal telemetry on outbound data movement therefore matters more than the number on the leak site.
The Second Wave: Why Non-Customer Data Is the Most Dangerous Kind
The absence of customer data reads as reassuring, but it is not. Ross Filipek, CISO at Corsica Technologies, told Infosecurity Magazine that "that information creates options. Criminals could impersonate executives or vendors. They could redirect payments or target employees with convincing phishing messages."
Internal documents solve the hardest problem an impersonator faces: sounding legitimate. Organizational charts establish who can plausibly instruct whom, and vendor lists and purchase order formats supply the references that make a payment redirection look routine. Process documentation provides the approval sequences that separate a convincing pretext from an obvious one, and employee records provide the contact details to deliver it.
Cyberattack data shows the capability being used at scale. Mandiant's M-Trends 2026 records that "highly interactive voice phishing saw a significant surge to 11%, becoming the second-most commonly observed vector," behind exploits at 32% of intrusions.
The CrowdStrike 2026 Threat Hunting Report records that "vishing intrusions in the first half of 2026 increased 2x compared to the second half of 2025." Gartner reported in September 2025 that "62% of organizations experienced a deepfake attack."
Impersonation historically failed on details an outsider could not know, and a leaked document set removes exactly that failure mode. The population at risk is therefore employees, suppliers, and commercial partners.

What Breached Organizations Should Do About Second-Wave Risk
Second-wave exposure begins when the data is published, which places it outside most incident response plans.
- Notify the exposed, as well as the legally required: Named employees and suppliers need to know which pretexts are now credible against them.
- Control payment changes procedurally: Any instruction to alter bank details should be verified through a contact record established before the breach.
- Apply out-of-band callback to identity claims: Voice is no longer evidence of identity against AI-generated voice phishing, including for helpdesk credential resets.
- Simulate the actual pretexts: Where vendor names and approval chains are public, the realistic test is built from that same material.
Adaptive Security's security awareness training covers voice and video pretexts, as well as email, making it a routine practice.
The Disclosure Question: Why Coca-Cola Filed Under Item 8.01 Instead of Item 1.05
Coca-Cola disclosed under Item 8.01 of Form 8-K, headed Other Events, rather than Item 1.05, headed Material Cybersecurity Incidents, stating that "the Company has not yet determined whether the incident is reasonably likely to materially affect the Company."
The SEC defines the distinction. In a statement issued on May 21, 2024, Erik Gerding, Director of the SEC's Division of Corporation Finance, explained that Item 1.05 applies to incidents "determined by the registrant to be material."
Item 8.01 is appropriate for an incident "for which it has not yet made a materiality determination." The four-business-day clock therefore attaches to the materiality determination.
The choice is also the common one, and the SEC expressly supports it. Greenberg Traurig recorded in February 2025 that "since April 2024, 41 companies disclosed cybersecurity incidents via Form 8-K, with 26 filing under voluntary Item 8.01 and 15 under mandatory Item 1.05." Separate obligations still apply under state breach notification statutes, contracts, and insurance conditions.
Anubis Fairlife Ransomware Decryption: Was the Ransom Paid?
No free decryptor exists for Anubis ransomware. No entry appears in the No More Ransom directory, the law-enforcement and industry repository where recovered keys and working decryptors are published, and no law-enforcement action against the Anubis infrastructure has been announced.
That absence has a cryptographic cause. The strain uses a standard public-key construction with no known practical weakness, and free decryptors generally emerge only from the seizure of key infrastructure or the discovery of an implementation flaw. Recovery from the Fairlife ransomware without usable backups is therefore not realistically achievable, and any tool advertised elsewhere as an Anubis decryptor should be treated as unverified.
Whether a ransom was paid has never been addressed by Coca-Cola, which has not disclosed whether it negotiated, declined to engage, or paid. Anubis claims a $15 million demand, states that no contact was ever made, and claims it deleted the decryption keys and published the data in response.
Publication on July 28, 2026 is consistent with a failed extortion attempt, since operators generally publish when payment does not arrive. Consistency is not confirmation. The only account of non-payment comes from the cyberattackers, and the accurate position is that no payment has been established either way.
Why the Wiper Changes the Math
Because Anubis can unilaterally destroy file contents, payment purchases only a promise. The group claims to have deleted the Fairlife decryption keys; if that is accurate, no subsequent payment could have recovered anything, since a victim cannot verify what remains recoverable before deciding.
The wider payment landscape has moved in the same direction. The Verizon 2026 Data Breach Investigations Report records that "69% of ransomware victims didn't pay," with ransomware present in 48% of breaches. The Chainalysis 2026 Crypto Crime Report records payments falling "by approximately 8% to $820 million in 2025," with the share of victims paying possibly reaching "an all-time low this year at 28%."
One constraint is worth settling before any incident. The US Treasury's Office of Foreign Assets Control advised in September 2021 that sanctions penalties may be imposed "based on strict liability." A payer can therefore be held liable even without knowing the recipient was sanctioned.
Fairlife Ransomware Recovery: How to Recover From a Ransomware Attack in the Production Line
Fairlife ransomware recovery took 11 days from disclosure to the resumption of most production, indicating a phased restart instead of a single restoration event. Coca-Cola has not published its recovery sequence, so the stages below describe established practice for manufacturing environments.
- Containment: Isolate affected systems and establish which networks, identities, and platforms the intrusion touched.
- Identity core rebuild: Restore trustworthy authentication first, assuming directory services were compromised.
- Dependency mapping: Establish which production processes rely on which business systems;
- OT validation: Verify control system integrity. Do not assume anything below the business layer was altered.
- Controlled restart: Bring production back progressively in the sequence dictated by a predefined critical asset list.
- Hardening: Close the exposure that permitted the intrusion and remove the persistence established during it.
The #StopRansomware Guide directs organizations to "identify and prioritize critical systems for restoration on a clean network," working from "a predefined critical asset list." A list assembled during an incident is a list assembled under pressure by people guessing.
Identity comes before applications because of what Anubis claims occurred here, which is full privilege across Fairlife's systems. Detecting and Mitigating Active Directory Compromises was published in September 2024 by ASD's ACSC, CISA, NSA, and partner agencies. It warns that "full recovery may require building a new Active Directory domain with new user and computer objects and destroying the compromised domain."
An organization that restores production onto a directory it has not rebuilt has restored the cyberattacker's access alongside its own.
One recovery lever in this case sat entirely outside the security function. Coca-Cola reported that "retail availability of fairlife products has been largely unimpacted, due to the availability of existing inventory." Finished-goods coverage, therefore, determined how long production could remain offline before the brand incurred commercial damage.
Inventory is planned against cost, shelf life, and demand, while recovery time objectives are set by security and IT. Where the two numbers are never compared, an organization does not know how many days of outage its buffer actually finances.
How to Prevent Cyberattacks Like the Fairlife Ransomware Attack
Prevention guidance for the Fairlife ransomware attack has to work around an unconfirmed entry point, so the measures below address the categories of exposure this case actually evidences.
Tier 1: Close the Front Door (0 to 30 Days)
Tier 1 addresses the exposure Anubis itself describes, an internet-facing VPN vulnerability followed by password brute-forcing. The Verizon 2026 DBIR records only 26% of CISA KEV entries were fully remediated, with a median of 43 days, while the Microsoft Digital Defense Report 2025 reports that "phishing-resistant multifactor authentication (MFA) can stop over 99%" of identity attacks.
- Complete inventory of internet-facing appliances, including gateways operated by a subsidiary.
- Patching prioritized by CISA KEV listing above severity score alone.
- Session invalidation as a mandatory step after patching any appliance capable of leaking session material.
- Phishing-resistant MFA on every remote access path, with legacy local accounts on gateway devices removed.
Tier 2: Make Lateral Movement Expensive (30 to 90 Days)
Anubis claims it reached full privileges in roughly a week, which is the interval Tier 2 is meant to lengthen. Provendata documents that lateral movement "has been observed prior to encryption" while noting that "specific lateral movement tooling has not been independently confirmed," so the controls below target behavior instead of named products. Virtualization deserves particular attention:
- Tiered administration, so an account managing workstations cannot authenticate to domain controllers or the virtualization platform.
- Hypervisor and backup management separated from the production domain, with independent identity.
- Backups held immutable, off-domain, and restore-tested on a schedule.
- Alerting on unapproved remote management tooling, outbound tunneling, and the stopping of backup services and endpoint protection, which Provendata documents as an Anubis precursor to encryption.
Tier 3: Break the IT-to-OT Chain (90 Days and Beyond)
Tier 3 exists because Fairlife could not answer the crossing question quickly, and because the population of cyberthreat actors capable of forcing that question is growing.
The Dragos 2026 OT Cybersecurity Year in Review records 119 ransomware groups targeting industrial organizations in 2025, up from 80 in 2024. Industry-wide average OT dwell time ran to 42 days, against 5 days for organizations that had built detection capable of answering it.
- Separate identity for operational technology, so business-domain credentials cannot authenticate to plant systems.
- A documented dependency map linking each production process to the business systems it requires.
- Written and rehearsed manual fallback for recipe, batch record, allergen control and labeling processes.
- Detection coverage within the OT environment is sufficient to answer the crossing question in hours rather than weeks.
Tier 4: Harden the Human Layer, Before and After the Breach
The human layer carries two workloads here, and most programs address only the first. Before a breach, credential and pretext exposure is what allows an affiliate in, and spear phishing is the primary vector documented for Anubis. After a breach, the internal documentation now in public circulation provides raw material for impersonation targeting employees, suppliers, and partners.
- Simulation built on current pretexts, including AI-generated voice and video, in place of template phishing emails.
- Targeting of the roles that hold operational authority: helpdesk, accounts payable, plant IT and executive assistants.
- Verification procedures for payment changes and credential resets that do not rely on voice recognition.
- Post-breach exercises constructed from the pretexts an organization's own leaked documents would enable.
Programs of this kind are a control category, and structuring one is covered in Adaptive Security's ransomware awareness training guide.
Fairlife Ransomware: What the Incident Should Change
The Fairlife ransomware attack is instructive precisely because so much of it remains unconfirmed. An intrusion of unknown origin halted production at four US facilities and published a set of internal documents the group put at 671 GB. Whether operational technology was reached remains unanswered by anyone outside the company.
The controls that would have mattered are identifiable regardless. They are inventoried edge appliances, session invalidation treated as part of patching, identity separated across production, virtualization, and backup, documented manual fallback for regulated processes, and a workforce rehearsed against the pretext that leaked documents now enable.
Organizations working through what the Fairlife ransomware attack means for their own exposure can start with the human layer, where the majority of intrusions still begin, at Adaptive Security.
Fairlife Ransomware FAQ
Was Fairlife's Operational Technology Compromised?
No public evidence establishes that operational technology was compromised in the Fairlife ransomware incident. The Form 8-K of July 16, 2026 states that unauthorized access affected a portion of Fairlife's systems, including production-related systems, without specifying whether industrial control systems were among them.
Is Fairlife Milk Safe to Drink After the Ransomware Attack?
Coca-Cola stated on July 16, 2026, that "product quality and safety have not been impacted." No recall was issued, and no contamination has been reported. Production at all four US facilities had largely resumed by July 27, 2026.
Was There a Fairlife Shortage Because of the Hack?
No public source has established a consumer-facing shortage attributable to the cyberattack, and Coca-Cola stated that retail availability was largely unaffected because existing inventory covered the suspension period. Capacity pressure predated the incident: Coca-Cola announced a $650 million expansion of its Michigan facility in March 2026 and broke ground in August 2026.
Was Fairlife Employee Data Stolen in the Ransomware Attack?
Coca-Cola confirmed that data was taken without describing its contents. Infosecurity Magazine, citing the group’s own description, reported that the set included HR records, engineering documentation, and production data. Whether that material contains employees' personal information and whether individuals have been notified have not been addressed publicly.
What Is Anubis Ransomware?
Anubis is a ransomware-as-a-service operation that emerged in December 2024 and advertised affiliate programs on the RAMP cybercrime forum in February 2025. It encrypts using the Elliptic Curve Integrated Encryption Scheme, carries a wipe mode capable of permanently destroying file contents, and runs three revenue streams covering encryption affiliates, data extortion affiliates, and initial access brokers.
Is Anubis Still Active?
Yes. Ransomware.live, a public leak-site tracker whose figures reflect cyberattackers' claims rather than confirmed incidents, listed 106 Anubis victims as of August 2026, with new entries recorded that month. No law enforcement action against the group has been announced.
As experts in cybersecurity insights and AI threat analysis, the Adaptive Security Team is sharing its expertise with organizations.
Get started with Adaptive Security
Get started


