Threat group claims credit for ransomware attack on Coca-Cola’s dairy unit | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


A threat group called Anubis claimed credit for the ransomware attack against Fairlife, the dairy products unit of Coca-Cola. 

The group says it locked the servers at Fairlife and obtained 1TB of data from the attack, according to researchers at Arctic Wolf. Anubis is threatening to leak information if its demands are not met within a week. Researchers provided screenshots posted on the group’s data leak site

Coca-Cola was forced to suspend U.S. production at Fairlife while it launched an investigation into the attack. Coca-Cola officials noted there was no impact on the safety or quality of its dairy products. 

Destructive tendencies

Anubis is a ransomware-as-a-service operation that emerged in late 2024 as a rebrand of Spinx ransomware, Arctic Wolf researchers said. 

The group generally has used two methods to gain initial access, either through valid, stolen VPN credentials or the exploitation of vulnerabilities such as CitrixBleed 2, which is tracked as CVE-2025-57777

“Anubis affiliates have repeatedly secured initial access by exploiting internet-facing vulnerabilities and abusing stolen VPN credentials,” Stefan Hostetler, staff threat intelligence researcher at Arctic Wolf, told Cybersecurity Dive. “In our investigations, we’ve seen attackers take advantage of vulnerabilities that were not new or especially sophisticated, underscoring a persistent reality that threat actors often succeed by exploiting known weaknesses that organizations haven’t fully remediated.”

Anubis often uses destructive tactics designed to undermine recovery methods, according to researchers at Halcyon. Prior to encryption, Anubis frequently shuts down the ability to create volume shadow copies and prevents other security processes from helping companies restore data. 

Coca-Cola has not provided any details about the threat group linked to the attack or how the attackers gained access to systems. 

CitrixBleed 2 is linked to insufficient input validation, which can lead to memory overread when Citrix NetScaler is configured as a Gateway. 

Fairlife is a significant portion of Coca-Cola’s overall business. Coca-Cola bought out the remaining majority stake in Fairlife in 2020, following a prior joint venture deal with Select Milk Producers. 

Fairlife surpassed $1 billion in annual revenue in 2022. In March, Coca-Cola announced plans for a $650 million expansion of a Fairlife plant in Coopersville, Mich. 

A spokesperson for Coca-Cola did not return a request for comment.

——————————————————–


Click Here For The Original Source.

.........................

National Cyber Security

FREE
VIEW