Coca-Cola’s Fairlife Milk Production Resumes as Hackers Tout 1TB Data Theft | #ransomware | #cybercrime


Coca-Cola says milk production has resumed at its Fairlife brand after a ransomware attack shut down US-based facilities for over a week. 

Fairlife has “resumed the majority of production at its four facilities in the United States,” Coca-Cola said on Monday. That said, the company is still working to restore all impacted systems and operations. In some good news, Coca-Cola adds that “retail availability of Fairlife products has been largely unimpacted, due to the availability of existing inventory. Product quality and safety have not been impacted.”

The company confirmed that “certain data” was stolen during the breach after ransomware group Anubis claimed responsibility for the attack. However, Coca-Cola doesn’t expect the incident to have a significant impact on its business. “Based on the information currently available, the company believes the incident has not had, and is not reasonably likely to have, a material impact on the company’s financial condition or results of operations,” it adds.

Ransomware usually works by encrypting fleets of computers and forcing victims to pay to free their IT systems. The Anubis gang claims to have stolen 1TB of data from Fairlife, in addition to locking down the brand’s servers. “Be smart and give the people back their milk, damn it! The timer is ticking. You have until the end of the week,” Anubis wrote on its ransom site last week.

Coca-Cola declined to comment on whether it paid a ransom. But Anubis’ site still lists the Fairlife brand as a victim, suggesting no ransom was paid. Although the group has threatened to leak the stolen data as soon as today, it’s possible that no sensitive data was taken.

Recommended by Our Editors

Cybersecurity vendor Trend Micro says Anubis emerged in late 2024 and has been renting out its ransomware to cybercriminals. This includes advertising its activities in cybercrime forums using Russian-language posts.

“Anubis affiliates most commonly gain initial access through spear-phishing emails containing malicious documents or compressed executables,” added cybersecurity provider SOCRadar. The attack also features an “optional wipe mode” that can erase files, rather than encrypt them.

About Our Expert





Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW