The Anubis ransomware gang has claimed responsibility for the cyberattack that recently disrupted operations at Fairlife, the dairy company owned by Coca-Cola. The group alleges it stole approximately one terabyte of corporate data and has threatened to publish the information unless an undisclosed ransom demand is met. At the time of writing, Coca-Cola has not confirmed whether data was exfiltrated or commented on Anubis’ claims.

 

 

The claim appeared on Anubis’ dark web leak site several days after Coca-Cola disclosed that Fairlife had suffered a ransomware incident affecting production systems. In its earlier disclosure, the company said an unauthorized third party had accessed portions of Fairlife’s infrastructure, including systems used in manufacturing. As a precaution, Fairlife temporarily suspended production at all of its U.S. facilities while recovery efforts began. Canadian production sites were not affected, and Coca-Cola said product quality and safety had not been compromised.

According to the ransomware group’s post, the attackers obtained roughly one terabyte of internal company data during the intrusion. However, Anubis has not released evidence verifying the full extent of the alleged theft, and Coca-Cola has not confirmed whether sensitive corporate information or customer data was accessed. Like many ransomware operations, the group is using the threat of publishing stolen files to pressure the victim into paying a ransom.

Fairlife, headquartered in Chicago, produces ultra-filtered milk, protein shakes, and other dairy products that are distributed throughout the United States. The company has grown into one of Coca-Cola’s fastest-expanding businesses, generating billions of dollars in annual retail sales. The temporary shutdown of U.S. production highlighted the operational impact the cyberattack had on the company’s manufacturing systems, although Coca-Cola has not disclosed how long recovery is expected to take.

After detecting the incident, Coca-Cola activated its incident response and business continuity procedures and retained external cybersecurity specialists to assist with the investigation. The company also notified law enforcement authorities and said it is continuing to assess the scope and business impact of the attack. Coca-Cola has not indicated whether it has been in contact with the attackers or whether any ransom demand has been received directly.

Anubis is a relatively recent ransomware operation that combines data theft with extortion. According to security researchers, the group has also employed destructive tactics, including file-wiping capabilities, to increase pressure on victims during negotiations. Whether those techniques were used during the Fairlife incident has not been confirmed.

Leave a Reply