Public incident case study · Manufacturing and industrial · United States
Coca-Cola / fairlife Ransomware Production Shutdown Case Study
Ransomware disclosed 16 July 2026 · majority production restored by 27 July
- 4
- U.S. facilities in the recovery
- 11 days
- from disclosure to majority production restored
- 1
- Canadian production network unaffected
- 0
- reported product quality or safety impact
Executive summary
Incident sequence
Ransomware reached production-related systems
On 16 July 2026, Coca-Cola disclosed that fairlife had identified unauthorised third-party access to a portion of its systems, including production-related systems, in connection with a ransomware event. The public record doesn't establish the initial access mechanism, the date on which the attacker first entered the environment, or direct compromise of PLCs or other industrial controllers.
Containment resulted in a nationwide U.S. production suspension
After detecting the incident, Coca-Cola activated incident response and business continuity protocols, engaged outside advisors and cybersecurity specialists, and notified law enforcement. Production operations at fairlife in the United States were temporarily suspended while the investigation and restoration proceeded. fairlife's Canadian production operations weren't affected.
Product quality and safety remained unaffected
Coca-Cola explicitly stated that the incident hadn't affected fairlife product quality or safety. The cyber incident disrupted the technology needed to support production, but the public record doesn't describe malicious manipulation of the physical production process or unsafe product.
An attacker claimed responsibility but attribution remains unconfirmed
The Anubis ransomware operation subsequently claimed responsibility for the fairlife incident and claimed to have stolen approximately 1TB of data. Coca-Cola didn't publicly attribute the incident to Anubis. The company later confirmed that certain data had been taken, but neither the adversary identity nor the volume claimed by the ransomware group should be treated as confirmed.
Full incident chronology
Incident timeline
Incident chronology.
Detection
fairlife identified unauthorised access associated with ransomware
Coca-Cola disclosed that a third party had accessed part of fairlife’s environment, including systems related to production.
Containment
U.S. production was suspended
Incident response and continuity protocols were activated while production operations across fairlife’s U.S. footprint were paused for investigation and restoration.
Operational boundary
Canadian production and product safety remained unaffected
Coca-Cola separated the U.S. technology disruption from unaffected Canadian operations and reported no product-quality or product-safety consequence.
Adversary claim
Anubis claimed the attack and approximately 1TB of theft
The claim remained unconfirmed by Coca-Cola; later company reporting confirmed that some data was taken without validating the adversary or claimed volume.
Production recovery
Most production resumed across four U.S. facilities
The company described majority production restoration while affected systems and remaining operations continued through staged recovery.
Business assessment
Inventory limited downstream disruption
Existing finished-goods inventory largely protected retail availability, and Coca-Cola assessed that the event was not reasonably likely to materially affect its financial condition or results.
Data-impact evidence
Security research described the contents of published leak material
Constella Intelligence reported that its review of material published on the attackers' leak site included engineering and production documentation, process control schematics, maintenance material, formulation and supplier information, and employee-related records. These categories are security research observations, not independently confirmed by Coca-Cola.
Legal aftermath
Proposed employee class action was dismissed
A proposed class action filed by a former fairlife employee after the incident was voluntarily dismissed without prejudice. The complaint's allegations weren't adjudicated and shouldn't be treated as established breach findings.
Lykos analysis
What organisations should learn.
Why this matters to executives and boards
fairlife demonstrates that ransomware does not need to manipulate industrial controllers directly to stop physical production. Compromise of production-related technology was sufficient to suspend U.S. manufacturing operations while trust was re-established and systems were restored. The case also shows that operational impact and customer impact can be materially different: existing finished-goods inventory absorbed much of the production outage before it reached retailers and consumers.
Readiness gaps and strengths visible in the public record
The public record doesn't establish how the attacker gained access, which production-related systems were affected, whether backups were involved, or whether any OT assets were compromised, so those control deficiencies should not be inferred. Later security research concerning the published leak material adds evidence that sensitive engineering, production, formulation, supplier, and employee information may have been exposed, but it doesn't establish the attacker's initial access path. The documented response instead highlights the importance of understanding which IT and production-support systems can halt manufacturing, having authority to suspend production safely, maintaining sufficient inventory or alternative supply to tolerate disruption, exercising staged restoration, coordinating cyber and production teams, separately validating product quality and safety before normal operations resume, and treating engineering and production documentation as sensitive information requiring appropriate protection and incident scoping. Coca-Cola's rapid activation of incident response and business continuity processes, continued Canadian production, inventory buffer, and progressive restart are all relevant resilience features.
How Lykos helps
Turn the lesson into tested capability.
Operational resilience and business continuity
Build and re-test workable continuity, containment, and recovery arrangements before disruption.
Explore IR ReadinessAsset and vulnerability management
Establish whether critical assets, exposures, and remediation priorities are known before response begins.
Explore Capability ValidationIncident response
Turn recurring incident lessons into decision-led plans, playbooks, and escalation guidance.
Explore Plans & PlaybooksNot sure where to begin? Start with Capability Validation.
Public record
Sources
Public record reviewed 21 Sept 2026.
- Form 8-K — fairlife Ransomware EventThe Coca-Cola Company / U.S. Securities and Exchange Commission · 16 Jul 2026 · Company regulatory filing
- The Coca-Cola Company Announces Technology Disruption Involving fairlife OperationsThe Coca-Cola Company · 16 Jul 2026 · Company statement
- Hackers claim attack on Coca-Cola's Fairlife, threaten to leak dataThe Atlanta Journal-Constitution · 23 Jul 2026 · News reporting
- The Coca-Cola Company Announces Significant Progress in Restoring fairlife Operations Following Technology DisruptionThe Coca-Cola Company / fairlife · 27 Jul 2026 · Company update
- Form 10-Q for the Quarter Ended 3 July 2026The Coca-Cola Company / U.S. Securities and Exchange Commission · 29 Jul 2026 · Company regulatory filing
- From a Stolen Login to a Ransomware Leak SiteConstella Intelligence · 1 Sept 2026 · Threat intelligence analysis
- Montalvo v. Fairlife, LLC et al. — Notice of Voluntary Dismissal Without PrejudiceU.S. District Court for the Northern District of Georgia / public docket reporting · 17 Sept 2026 · Court record