Coca-Cola has confirmed that data was stolen during the ransomware attack on its Fairlife dairy business, escalating the incident beyond a temporary production disruption.
The beverage giant said that the attack poses potential legal, regulatory, and reputational challenges even as operations have begun to recover. The acknowledgment came days after the Anubis ransomware group claimed it had copied roughly 1 TB of information from Fairlife’s systems.
According to BleepingComputer, Anubis followed through on its extortion threat after the leak deadline expired, publishing the allegedly stolen files online. Coca-Cola has not disclosed what categories of data were affected or confirmed the group’s claim that roughly 1 TB of information was stolen.
Coca-Cola faces a ransomware attack
While the exact duration of the intrusion is still unknown, Coca-Cola disclosed the incident in a filing with the U.S. Securities and Exchange Commission (SEC) on July 16. The company said it had identified a ransomware attack involving systems related to Fairlife, its dairy subsidiary, which disrupted production operations and forced a temporary halt to U.S. manufacturing.
Canadian operations were unaffected, and Coca-Cola said product quality and food safety remained unaffected.
Shortly after the disclosure, the Anubis ransomware group claimed responsibility for the attack and set a leak timer on its website, alleging it had stolen roughly 1 TB of data before encrypting Fairlife’s systems. The claims could not be independently verified, and Coca-Cola had declined BleepingComputer’s request to comment on the matter.
BleepingComputer reported that Coca-Cola did not heed the group’s demands but instead notified law enforcement and has begun its own investigation to determine the scope of the attack.
According to PCMag, Coca-Cola has now confirmed that “certain data” was stolen during the attack and said recovery efforts remain ongoing.
Depending on the nature of the compromised information, the incident could trigger regulatory reporting obligations, customer notifications, or legal scrutiny that continue long after production has resumed.
Meanwhile, the countdown on Anubis’ leak site expired on Monday, and the group has published the stolen data, marking the latest escalation in the ransomware incident.
Must-read security coverage
- UK Police Convicts Pair in £5.5 Billion Bitcoin Launder Case
- Blackpoint Cyber vs. Arctic Wolf: Which MDR Solution is Right for You?
- How GitHub Is Securing the Software Supply Chain
- 8 Best Enterprise Password Managers
The pressure point has shifted from systems to operations
The Fairlife incident illustrates how modern ransomware campaigns increasingly rely on double-extortion tactics, combining system encryption with data theft to extend pressure beyond technical recovery.
Even if a victim recovers its infrastructure from backups, the risk of exposing confidential data can prolong the crisis and lead to lasting consequences that outlast the technical recovery. In effect, the attack no longer ends when systems come back online.
The Fairlife incident also sheds light on an often-overlooked measure of cyber resilience: how well a business continues to function during disruption.
For enterprises, that raises the bar for preparedness. Security controls remain essential, but they are only one layer of resilience.
As ransomware groups increasingly combine operational disruption with data theft, the defining question for enterprises may no longer be whether every attack can be prevented, but whether critical operations can continue when preventive controls prove insufficient.