
The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola's Fairlife dairy subsidiary, threatening to publish allegedly stolen corporate data unless the company pays a ransom.
Fairlife is one of Coca-Cola's dairy brands and produces a range of ultra-filtered milk products, protein shakes, and nutrition drinks sold throughout the United States. The company's product lineup includes Ultra-Filtered Milk, Core Power Protein Shakes, and Nutrition Plan.
On July 16, The Coca-Cola Company disclosed that a ransomware attack had disrupted Fairlife's operations, forcing the company to suspend production at its U.S. facilities.
The company said attackers gained unauthorized access to a portion of Fairlife's systems, including production-related systems, prompting it to activate its incident response and business continuity plans. Coca-Cola also said product quality and safety were not affected and that Canadian production operations continued as normal.
At the time, Coca-Cola had not disclosed whether data was stolen, whether it had received an extortion demand, or which ransomware operation was responsible for the attack.
Anubis ransomware claims attack
On Monday, the Anubis ransomware gang added Fairlife to its dark web data leak site, claiming responsibility for the attack and alleging it stole approximately one terabyte of corporate data. The ransomware gang warned it would publish the stolen data unless the company enters negotiations by the end of the week.

The ransomware gang claimed it attacked Fairlife roughly a week before the company publicly disclosed the incident and encrypted the company's Nutanix infrastructure.
"We attacked their systems a week ago. Just a few days later, they immediately reported the incident without attempting to follow the instructions we left on their network," Anubis claimed to BleepingComputer.
"We have fully encrypted their Nutanix systems. They have no chance of recovering without our encryption key."
The ransomware gang also claimed to have stolen 1 TB of corporate data during the attack.
BleepingComputer could not independently verify the gang's claims regarding the alleged theft of data, the encryption of Fairlife's systems, or the amount of data purportedly stolen.
When contacted about these claims, Coca-Cola declined to comment.
Anubis is a ransomware-as-a-service (RaaS) operation that emerged in December 2024 and has since targeted organizations worldwide across multiple industries.
The operation is known for combining data theft with file encryption and using stolen information as leverage to pressure victims into paying a ransom.
Last year, Anubis added a data wiper to its arsenal that destroys the victim's files to make recovery impossible.
Test every layer before attackers do
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Get the whitepaper
