Anubis (RaaS) — unconfirmed claim; incident confirmed via SEC 8-Khigh
Fairlife: the ransomware that stops Coca-Cola's milk
On 16 July 2026 The Coca-Cola Company disclosed to the SEC, via a Form 8-K, a ransomware attack on its Fairlife subsidiary: unauthorised access to some systems, including production-related ones, and a temporary suspension of US production. The company states that product quality and safety were not affected and that Canadian operations are not involved. On 20 July the Anubis group claimed the attack, saying it had encrypted systems and stolen 1 TB of data: claims by the group, not confirmed by Coca-Cola. We keep the facts stated by the company and the claims strictly apart.
What the company put in writing
On 16 July 2026 The Coca-Cola Company filed a Form 8-K with the SEC — the US markets regulator — to disclose a ransomware attack on its Fairlife subsidiary. It is an official document, and the perimeter of what it says is precise: Fairlife detected unauthorised access to some of its systems, including production-related ones, in connection with a ransomware attack. The company activated its incident-response and business-continuity protocols, brought in outside cybersecurity advisors, and notified law enforcement.
Two clarifications in the filing matter as much as the announcement. First: product quality and safety were not affected. Second: production at US facilities has been temporarily suspended while the company responds to the incident and restores affected systems, while operations in Canada are not currently affected. Fairlife is no marginal brand: it makes ultra-filtered milk and protein drinks sold across the United States. A cyberattack that halts food production lines is the point at which ransomware stops being an IT-department problem and becomes a problem of empty shelves.
- 16 July 2026SEC disclosure
8-K: unauthorised access, US production suspended
- 20 July 2026The claim
Anubis lists Coca-Cola and Fairlife on its leak site
- 20-22 July 2026The threats
Anubis says it encrypted systems and stole 1 TB
What the group claims, and what remains to be verified
At the time of disclosure, as BleepingComputer noted, no group had claimed the attack and Coca-Cola had not confirmed any data theft or ransom demand. A few days later the picture shifted: around 20 July the Anubis ransomware group listed Coca-Cola and Fairlife on its extortion site, and between 21 and 22 July it claimed to have encrypted the systems and exfiltrated roughly 1 TB of confidential data, threatening to publish it.
Here the same discipline we apply to every leak site is required. The figures and the claims — the encryption, the terabyte, the "confidential" data — are Anubis's, not Coca-Cola's, and the company, when asked, added nothing beyond its public statement. A name on an extortion site means someone is claiming an attack and seeking leverage to get paid, not that the scale of the theft has been independently verified. Anubis, for context, is a ransomware-as-a-service operation that emerged in late 2024, known for combining data theft and encryption — so-called double extortion. Coca-Cola itself writes in the filing that it has not yet been determined whether the attack is reasonably likely to materially affect the company: the investigation is ongoing.
The lesson, minus the noise
Stripped of the famous name, the story tells us something useful to anyone: the largest, best-resourced organisations get hit too, and the most immediate effect is not always data theft but the halting of operations — here, literally, the milk lines. The defence that makes such an attack survivable is not a single product but the ability to keep functioning while you restore: business-continuity plans that have actually been tested, backups an attacker cannot reach, segmentation between the business systems and the ones that move production.
And there is a consumer angle. When a company's data is exfiltrated — or is feared to be — it ends up fuelling targeted scams and identity-theft attempts. The only move that truly protects downstream is the boring, always-valid one: turn on two-step verification on your accounts and never reuse the same password, so that someone else's data breach does not become the key to your mailboxes. In this story, the confirmed facts and the claims must be kept apart until proven otherwise.