Coca-Cola-owned dairy company Fairlife has become the latest high-profile organization to be targeted by a ransomware attack, drawing significant attention across the cybersecurity community. According to emerging reports, a relatively new ransomware group known as Anubis has claimed responsibility for infiltrating Fairlife’s systems and stealing approximately 1 terabyte of data from the company’s servers.
The cybercriminal group alleges that it successfully accessed Fairlife’s network and exfiltrated a large volume of sensitive information before announcing the breach. While the full extent of the stolen data remains under investigation, the attackers are reportedly threatening to publish or exploit the information if their demands are not met, following the increasingly common double-extortion ransomware model.
Cybersecurity researchers at Arctic Wolf were among the first to identify and track the activities of the Anubis ransomware operation. The security firm has been monitoring the group’s tactics and infrastructure, noting that Anubis has quickly emerged as a notable threat in the ransomware landscape. Researchers believe the group has been actively targeting organizations across multiple industries while continuously refining its techniques to evade detection.
In response to the incident, Coca-Cola issued a public statement emphasizing that the cyberattack did not affect the safety, production, or quality of Fairlife’s dairy products. The company also stated that the data believed to have been compromised originated from archived systems rather than active operational environments. However, cybersecurity experts continue to investigate the attackers’ claims, and authorities have yet to independently verify the exact nature and sensitivity of the stolen information.
Security analysts believe that Anubis is closely linked to the Sphinx ransomware operation and may represent a rebranded version or spin-off of the earlier threat group. According to Arctic Wolf, Anubis first appeared in 2024 and has since evolved its identity and operational methods to avoid detection by law enforcement agencies and cybersecurity researchers. Rebranding has become a common strategy among ransomware gangs seeking to distance themselves from previous campaigns while maintaining similar attack capabilities.
Investigators also note that the group commonly gains initial access through compromised VPN credentials or by exploiting critical vulnerabilities in enterprise software. One of the vulnerabilities associated with its campaigns is CitrixBleed 2, a severe security flaw that can enable unauthorized access to corporate networks if left unpatched.
Meanwhile, threat intelligence firm Halcyon has highlighted another dangerous characteristic of the Anubis ransomware. According to its researchers, the malware is designed to disable Windows Volume Shadow Copies and other backup mechanisms before encrypting files. This tactic significantly reduces an organization’s ability to restore data quickly, making recovery more difficult and increasing pressure on victims to pay a ransom. The incident serves as another reminder of the growing sophistication of ransomware groups and the importance of strong cybersecurity defenses, timely patch management, and resilient backup strategies.
Click Here For The Original Source.
