Regional Deals

Coca-Cola resumes dairy production after cyberattack

By Sofia Ramirez · · 3 min read
Coca-Cola resumes dairy production after cyberattack - cyberattack dairy production
Coca-Cola resumes dairy production after cyberattack

Coca-Cola has mostly restored production at its Fairlife dairy facilities in the United States following a ransomware attack earlier this month that disrupted operations.

The beverage company confirmed on Monday that most production capacity is now operational. Fairlife, which produces ultra-filtered, lactose-free milk and protein shakes, had halted operations after hackers infiltrated its systems and stole data.

Hackers claimed 1TB of stolen data

A ransomware group known as Anubis took responsibility for the attack. Security analysts at Arctic Wolf reported the hackers claimed to have encrypted Fairlife’s servers and removed up to 1TB of data. Anubis threatened to release the information unless its demands were met, though specifics of those demands remain unclear.

The group has previously breached targets using stolen login details or by exploiting critical flaws, including CitrixBleed, tracked as CVE-2025-5777. Another security firm, Sophos, noted Anubis operates through three models: traditional ransomware services, data-theft extortion, and selling access to compromised networks.

The beverage company did not explain how the hackers gained entry or how systems were recovered. It also refused to say whether a ransom was paid.

No major financial impact expected

The disruption is not expected to significantly affect Coca-Cola’s financial results or operations. Fairlife, which generated over $1 billion in annual revenue in 2022, operates four U.S. facilities. The company stated that retail availability of Fairlife products remained stable due to existing inventory, and its Canadian operations were unaffected.

This incident occurs as Coca-Cola expands Fairlife’s production capacity. The company recently announced a $650 million investment to grow its Coopersville, Michigan, plant. A new 745,000-square-foot facility in Webster, New York, is also nearing completion.

While most production has resumed, some systems remain offline. Coca-Cola has not provided a timeline for full recovery.

Attacks on food and beverage manufacturers have increased in recent years, often targeting supply chains. The industry’s reliance on just-in-time inventory makes it especially vulnerable, though Fairlife’s stockpiles helped limit the impact this time.

Anubis, like similar groups, frequently changes tactics after major incidents. Its use of stolen credentials and known vulnerabilities shows many breaches could be avoided with basic security practices, which many companies have been slow to implement.

Coca-Cola’s response mirrors a common corporate approach: minimizing the financial impact of cyber incidents while acknowledging growing operational risks. For now, the company appears to view the Fairlife disruption as a short-term issue rather than a long-term problem.

Efforts to remove trade barriers have faced similar challenges in balancing security and efficiency.

Leave a Reply

Your email address will not be published.