• 2 min read
Anubis says it hit Coca-Cola’s Fairlife
The Anubis ransomware gang says it attacked Fairlife, stole 1 TB of data, and encrypted Nutanix systems after Coca-Cola disclosed a production outage.

Image: BleepingComputer
The Anubis ransomware gang says it was behind the recent cyberattack on Coca-Cola’s Fairlife dairy unit and is now threatening to leak allegedly stolen data unless the company negotiates by the end of the week.
Fairlife, one of Coca-Cola’s dairy brands, sells ultra-filtered milk, Core Power Protein Shakes, and Nutrition Plan products across the United States. On July 16, The Coca-Cola Company said a ransomware attack had disrupted Fairlife’s operations and forced a production suspension at its U.S. facilities.
At the time, Coca-Cola said attackers had gained unauthorized access to part of Fairlife’s systems, including production-related systems, and that it had activated its incident response and business continuity plans. The company also said product quality and safety were not affected, and that Canadian production operations were continuing normally.
On Monday, Anubis added Fairlife to its dark web leak site, claiming it stole about 1 terabyte of corporate data.
The gang also told BleepingComputer that it attacked Fairlife about a week before the company publicly disclosed the incident and had encrypted the company’s Nutanix infrastructure.

Recommended reading
SharePoint flaw now used to steal machine keys
“We attacked their systems a week ago. Just a few days later, they immediately reported the incident without attempting to follow the instructions we left on their network.” “We have fully encrypted their Nutanix systems. They have no chance of recovering without our encryption key.”
BleepingComputer said it could not independently verify Anubis’s claims about data theft, the alleged encryption of Fairlife’s systems, or the volume of data supposedly stolen. When asked about those claims, Coca-Cola declined to comment.
Anubis is a ransomware-as-a-service operation that emerged in December 2024 and has targeted organizations across multiple industries worldwide. The group combines data theft with file encryption, and last year added a data wiper designed to destroy victims' files and make recovery impossible.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via BleepingComputer


