The Coca-Cola Company has acknowledged that attackers stole data during the ransomware incident that recently disrupted operations at its Fairlife dairy business. While some affected systems are still being restored, the company said the majority of production at Fairlife’s U.S. facilities has resumed.

 

 

The cyberattack was first disclosed in a filing submitted to the U.S. Securities and Exchange Commission (SEC) on July 16. At the time, Coca-Cola said the incident had temporarily interrupted manufacturing activities at Fairlife, which produces ultra-filtered milk, protein drinks and other dairy beverages.

In a subsequent update, the company confirmed that the attackers gained unauthorised access to part of Fairlife’s network and removed certain data before the incident was contained. Coca-Cola has not identified the type of information that was taken or indicated whether customer or employee records were among the affected data.

According to the company, production was briefly suspended while response measures were implemented. Coca-Cola said existing inventory helped maintain product availability during the disruption and added that the cyberattack did not compromise the safety or quality of Fairlife products.

The ransomware operation known as Anubis later claimed responsibility for the intrusion by listing Fairlife on its extortion site. The group alleged it had copied approximately one terabyte of data and demanded payment in exchange for withholding the files from public release.

The attackers also claimed they encrypted Fairlife’s Nutanix infrastructure during the attack. Those statements originate from the ransomware group and have not been independently confirmed by Coca-Cola.

The company said it notified law enforcement after identifying the incident. It also stated that it did not engage with the attackers’ demand for negotiations.

After the deadline displayed on Anubis’ leak site expired, the group published files it claimed were stolen from Fairlife. Although Coca-Cola has confirmed that data was taken during the breach, it has not verified that the material released by Anubis is authentic or complete, nor has it confirmed the volume of information involved.

Coca-Cola continues to investigate the incident while recovery work remains underway on the remaining affected systems. The company has not disclosed how many individuals or organisations may have been impacted by the data theft, and no further details about the stolen information have been released.

Leave a Reply