Public incident case study · Manufacturing and industrial · United States

Coca-Cola / fairlife Ransomware Production Shutdown Case Study

Ransomware disclosed 16 July 2026 · majority production restored by 27 July

U.S.-widefairlife production temporarily suspendedCoca-Cola disclosed that unauthorised access associated with a ransomware event affected a portion of fairlife's systems, including production-related systems, and resulted in temporary suspension of fairlife production operations in the United States.
4
U.S. facilities in the recovery
11 days
from disclosure to majority production restored
1
Canadian production network unaffected
0
reported product quality or safety impact
Executive summary

Incident sequence

  1. Ransomware reached production-related systems

    On 16 July 2026, Coca-Cola disclosed that fairlife had identified unauthorised third-party access to a portion of its systems, including production-related systems, in connection with a ransomware event. The public record doesn't establish the initial access mechanism, the date on which the attacker first entered the environment, or direct compromise of PLCs or other industrial controllers.

  2. Containment resulted in a nationwide U.S. production suspension

    After detecting the incident, Coca-Cola activated incident response and business continuity protocols, engaged outside advisors and cybersecurity specialists, and notified law enforcement. Production operations at fairlife in the United States were temporarily suspended while the investigation and restoration proceeded. fairlife's Canadian production operations weren't affected.

  3. Product quality and safety remained unaffected

    Coca-Cola explicitly stated that the incident hadn't affected fairlife product quality or safety. The cyber incident disrupted the technology needed to support production, but the public record doesn't describe malicious manipulation of the physical production process or unsafe product.

  4. An attacker claimed responsibility but attribution remains unconfirmed

    The Anubis ransomware operation subsequently claimed responsibility for the fairlife incident and claimed to have stolen approximately 1TB of data. Coca-Cola didn't publicly attribute the incident to Anubis. The company later confirmed that certain data had been taken, but neither the adversary identity nor the volume claimed by the ransomware group should be treated as confirmed.

Full incident chronology

Incident timeline

Incident chronology.

  1. Detection

    fairlife identified unauthorised access associated with ransomware

    Coca-Cola disclosed that a third party had accessed part of fairlife’s environment, including systems related to production.

  2. Containment

    U.S. production was suspended

    Incident response and continuity protocols were activated while production operations across fairlife’s U.S. footprint were paused for investigation and restoration.

  3. Operational boundary

    Canadian production and product safety remained unaffected

    Coca-Cola separated the U.S. technology disruption from unaffected Canadian operations and reported no product-quality or product-safety consequence.

  4. Adversary claim

    Anubis claimed the attack and approximately 1TB of theft

    The claim remained unconfirmed by Coca-Cola; later company reporting confirmed that some data was taken without validating the adversary or claimed volume.

  5. Production recovery

    Most production resumed across four U.S. facilities

    The company described majority production restoration while affected systems and remaining operations continued through staged recovery.

  6. Business assessment

    Inventory limited downstream disruption

    Existing finished-goods inventory largely protected retail availability, and Coca-Cola assessed that the event was not reasonably likely to materially affect its financial condition or results.

  7. Data-impact evidence

    Security research described the contents of published leak material

    Constella Intelligence reported that its review of material published on the attackers' leak site included engineering and production documentation, process control schematics, maintenance material, formulation and supplier information, and employee-related records. These categories are security research observations, not independently confirmed by Coca-Cola.

  8. Legal aftermath

    Proposed employee class action was dismissed

    A proposed class action filed by a former fairlife employee after the incident was voluntarily dismissed without prejudice. The complaint's allegations weren't adjudicated and shouldn't be treated as established breach findings.

Lykos analysis

What organisations should learn.

Why this matters to executives and boards

fairlife demonstrates that ransomware does not need to manipulate industrial controllers directly to stop physical production. Compromise of production-related technology was sufficient to suspend U.S. manufacturing operations while trust was re-established and systems were restored. The case also shows that operational impact and customer impact can be materially different: existing finished-goods inventory absorbed much of the production outage before it reached retailers and consumers.

Readiness gaps and strengths visible in the public record

The public record doesn't establish how the attacker gained access, which production-related systems were affected, whether backups were involved, or whether any OT assets were compromised, so those control deficiencies should not be inferred. Later security research concerning the published leak material adds evidence that sensitive engineering, production, formulation, supplier, and employee information may have been exposed, but it doesn't establish the attacker's initial access path. The documented response instead highlights the importance of understanding which IT and production-support systems can halt manufacturing, having authority to suspend production safely, maintaining sufficient inventory or alternative supply to tolerate disruption, exercising staged restoration, coordinating cyber and production teams, separately validating product quality and safety before normal operations resume, and treating engineering and production documentation as sensitive information requiring appropriate protection and incident scoping. Coca-Cola's rapid activation of incident response and business continuity processes, continued Canadian production, inventory buffer, and progressive restart are all relevant resilience features.

How Lykos helps

Turn the lesson into tested capability.

Operational resilience and business continuity

Build and re-test workable continuity, containment, and recovery arrangements before disruption.

Explore IR Readiness

Asset and vulnerability management

Establish whether critical assets, exposures, and remediation priorities are known before response begins.

Explore Capability Validation

Not sure where to begin? Start with Capability Validation.

Public record

Sources

Public record reviewed 21 Sept 2026.

  1. Form 8-K — fairlife Ransomware EventThe Coca-Cola Company / U.S. Securities and Exchange Commission · 16 Jul 2026 · Company regulatory filing
  2. The Coca-Cola Company Announces Technology Disruption Involving fairlife OperationsThe Coca-Cola Company · 16 Jul 2026 · Company statement
  3. Hackers claim attack on Coca-Cola's Fairlife, threaten to leak dataThe Atlanta Journal-Constitution · 23 Jul 2026 · News reporting
  4. The Coca-Cola Company Announces Significant Progress in Restoring fairlife Operations Following Technology DisruptionThe Coca-Cola Company / fairlife · 27 Jul 2026 · Company update
  5. Form 10-Q for the Quarter Ended 3 July 2026The Coca-Cola Company / U.S. Securities and Exchange Commission · 29 Jul 2026 · Company regulatory filing
  6. From a Stolen Login to a Ransomware Leak SiteConstella Intelligence · 1 Sept 2026 · Threat intelligence analysis
  7. Montalvo v. Fairlife, LLC et al. — Notice of Voluntary Dismissal Without PrejudiceU.S. District Court for the Northern District of Georgia / public docket reporting · 17 Sept 2026 · Court record