Ransomware Gang Comes for Coca-Cola's Milk, Not Its Soda

Ransomware Gang Comes for Coca-Cola's Milk, Not Its Soda

When you think "Coca-Cola breach," you probably picture hackers making off with the secret formula in a heist-movie fantasy. The actual story is less cinematic and more relatable: a ransomware crew broke into the company's protein-milk subsidiary and shut down the dairy production line instead. Nobody's smuggling Coke's syrup recipe out in a briefcase — they're just making sure your Fairlife shake shipment is running late.

The Milk Stopped Flowing on July 16

Coca-Cola disclosed in an SEC filing that attackers had gained unauthorized access to parts of Fairlife's environment tied to production systems, forcing the company to temporarily suspend dairy manufacturing at its U.S. facilities while Canadian operations kept running. The Anubis ransomware group claimed responsibility, saying it had exfiltrated roughly 1 terabyte of confidential data, and set a leak deadline that has since expired — meaning the stolen data is now public.

Coca-Cola says a majority of U.S. production has since resumed, and maintains that product quality and safety were never compromised. Small comfort if you're the IT team that had to explain to a Fortune 500 board why milk cartons stopped shipping because someone clicked the wrong thing.

Ransomware Doesn't Care How Wholesome Your Brand Is

This is the part that should worry every manufacturer, not just beverage giants: modern ransomware increasingly goes straight for operational technology — the systems that actually run factory floors — rather than just office networks. Hitting production is how attackers guarantee a company feels real financial pain fast enough to consider paying up, and it turns a data breach into a supply-chain problem overnight.

It's also a reminder that "brand trust" and "security posture" are two completely separate metrics. Fairlife spent years building a wholesome, protein-shake-for-your-gym-bag reputation; none of that goodwill does anything to stop a phishing email or an unpatched server from taking down a production line.

Somewhere, a ransomware operator is very pleased with themselves for accidentally becoming the reason your post-workout shake was on backorder.

Source: BleepingComputer