A ransomware group calling itself Anubis has claimed responsibility for a cyberattack that disrupted operations at Fairlife, the dairy subsidiary of The Coca-Cola Company, and is threatening to release stolen corporate data if the company does not begin negotiations by the end of this week.
The group posted the claim to its dark web leak site, alleging it took roughly one terabyte of corporate data from Fairlife and encrypted the company’s Nutanix infrastructure. Anubis told BleepingComputer it breached Fairlife’s network about a week before the company publicly acknowledged the incident, and that Fairlife reported the attack without engaging with instructions the group says it left inside the network. The group said its encryption left Fairlife unable to restore the affected systems without its key. BleepingComputer said it could not independently confirm the claims regarding the data theft, the extent of the encryption, or the volume of data allegedly taken. Coca-Cola declined to comment when asked about the claims.
Coca-Cola first disclosed the attack on July 16, stating that unauthorized actors had accessed a portion of Fairlife’s systems, including systems tied to production, which led the company to halt production at its U.S. facilities and activate its incident response and business continuity plans. The company said the disruption did not affect product quality or safety and that Fairlife’s Canadian operations continued without interruption. At that time, Coca-Cola had not said whether any data was taken, whether it had received a ransom demand, or which group was behind the intrusion.
Fairlife makes ultra-filtered milk and nutrition products sold across the United States, including its Ultra-Filtered Milk line, Core Power protein shakes and Nutrition Plan drinks.
Reuters reported Monday that Anubis claimed credit for the attack on its dark web site and repeated the group’s assertion that it had stolen a terabyte of Fairlife data, threatening to publish it absent an unspecified ransom payment. Reuters said it sought comment from Coca-Cola and did not receive an immediate response, and that a message it sent to the hackers also went unanswered. No reports have surfaced indicating that Coca-Cola or Fairlife made any ransom payment.
According to Reuters’ account, the breach is believed to have occurred the Wednesday or Thursday before Coca-Cola’s July 16 announcement of the U.S. production halt, with Fairlife’s Canadian operations unaffected throughout.
Anubis is a ransomware-as-a-service operation that surfaced in December 2024 and has since struck organizations across a range of industries worldwide, pairing data theft with file encryption to pressure victims into paying. Last year the group added a data-wiping tool to its capabilities, a feature capable of destroying a victim’s files outright and eliminating the possibility of recovery. Reuters cited a Trend Micro analysis published last year describing the group’s use of such wiping software as giving its operations a particularly destructive character.
Click Here For The Original Source.
