Two Days in July That Took Fairlife’s Plants Offline
On July 16, 2026, The Coca-Cola Company filed a Form 8-K with the US Securities and Exchange Commission disclosing that fairlife, LLC — its ultra-filtered dairy subsidiary — had suffered a ransomware event that reached “a portion of the company’s systems,” including systems tied to production, according to Help Net Security’s review of the disclosure. The consequences were immediate and physical: production was temporarily suspended across fairlife’s US manufacturing facilities, while operations in Canada continued without interruption, per the same filing.
Four days later, on July 20, the Anubis ransomware-as-a-service group posted fairlife to its dark web leak site. The gang claimed it had encrypted the company’s Nutanix infrastructure and exfiltrated roughly 1 terabyte of confidential data, according to SWK Tech’s cybersecurity news recap. Coca-Cola has not confirmed that figure; a later account from Infosecurity Magazine put the leaked trove at 671GB, including HR records, engineering and technical documentation, and production data. The gap between 1TB and 671GB is itself a lesson — leak-site claims are marketing for the extortion, not verified fact.
By the time Coca-Cola issued its fuller public statement, the company said it had resumed the majority of production across its four US manufacturing facilities and that “product quality and safety have not been impacted,” adding it does not expect the incident to have a material effect on its financial results, per Infosecurity Magazine’s reporting. Retail shelves stayed stocked from existing inventory throughout the disruption.
Why an IT Breach Reached the Plant Floor
fairlife generates more than $1 billion in annual revenue from its ultra-filtered milk and protein shake lines, according to Infosecurity Magazine, and the incident shows how a purely digital compromise can stop a beverage line as effectively as a mechanical failure. That is the defining feature of IT-to-OT cascade risk: attackers rarely need to touch a programmable logic controller directly. As DeepStrike’s manufacturing cybersecurity analysis puts it, “an attack on enterprise IT can still affect plant operations when ERP, MES, file shares, engineering workstations, and production support systems are connected to the plant environment.” A compromised vendor account or weak IT/OT segmentation is often all it takes to turn an ordinary ransomware note into a stopped production line.
The Anubis group itself illustrates why this convergence is getting more dangerous. First observed in December 2024, Anubis pairs conventional double extortion — encrypt, then threaten to leak — with a built-in wiper mode that, per Trend Micro’s research, permanently destroys file contents and makes recovery “virtually impossible,” reserved as extra leverage against victims who refuse to pay. The group runs three separate profit-sharing tiers for affiliates — an 80% cut for standard ransomware-as-a-service, 60% for data-theft-assisted extortion, and a 50/50 split for post-compromise extortion support, according to Arete’s threat assessment — a menu that lets low-skill affiliates specialize in whichever stage of the attack chain they handle best.
fairlife is not an outlier. Manufacturing has been the most-targeted sector for cyberattacks for four consecutive years, and ransomware has cost the sector an estimated $17 billion in downtime since 2018 across 858 manufacturers worldwide, averaging $1.9 million per day offline, according to Infosecurity Magazine’s analysis of Comparitech data. DeepStrike’s review adds that 61% of manufacturing breaches involve a third party — a supplier, vendor, or managed service provider — reinforcing that the weak point is rarely the plant floor itself but the connective tissue between corporate IT and the factory network.
Under SEC rules adopted in 2023, Item 1.05 of Form 8-K requires public companies to disclose a material cybersecurity incident within four business days of determining materiality — which is exactly the clock Coca-Cola was running against between the July 16 filing and the July 20 leak-site posting. Fairlife’s timeline shows that clock now runs in parallel with an active extortion negotiation, not after it.
Advertisement
What Enterprise CISOs and Plant Operators Should Do Now
1. Map — and Pressure-Test — Every IT-to-OT Bridge Before an Attacker Does
Most manufacturers can list their ICS/SCADA assets but cannot say, with confidence, which corporate IT systems have a live path into the plant network. ERP, MES, engineering workstations, and historian servers are the usual bridges, and DeepStrike’s finding that 61% of manufacturing breaches involve a third party means the audit has to extend past your own network to every vendor and integrator with standing access. Don’t just diagram the connections — run a red-team exercise that tries to move laterally from a compromised IT account into an OT-adjacent system, and fix every path that succeeds, not just the ones that were flagged on paper.
2. Treat Leak-Site Numbers as Extortion Leverage, Not Evidence
Anubis claimed 1TB stolen from fairlife; later reporting put the real figure closer to 671GB. That gap matters because ransomware negotiation teams and legal counsel make disclosure decisions based partly on scope, and inflated leak-site claims are designed to maximize pressure, not accuracy. Build your incident response playbook around independent forensic verification of what was actually taken before you brief the board, notify customers, or file anything with a regulator — never let the attacker’s press release set your factual record.
3. Build a Production Continuity Plan That Assumes Zero IT for Five-Plus Days
With unplanned manufacturing downtime averaging $1.9 million per day according to Comparitech’s data cited by Infosecurity Magazine, the financial exposure of an OT-adjacent ransomware event is rarely the ransom demand — it’s the days of stopped lines. fairlife kept retail shelves stocked through existing inventory while it resumed production at its four US facilities; that only works if you already know your inventory buffer and have a manual fallback procedure for core production steps that doesn’t depend on the compromised systems. Test that fallback annually, not just after an incident.
4. Fold the SEC’s Four-Business-Day Clock Into the Incident Response Runbook, Not an Afterthought
Item 1.05 of Form 8-K gives public companies four business days from a materiality determination to disclose — a tight window that Coca-Cola met on July 16, only to have the attacker’s own leak-site posting land four days later and reframe the story publicly. Legal, communications, and security teams need a pre-agreed materiality assessment template and a joint drafting process rehearsed before an incident, not improvised during one, so the company’s own disclosure — not the extortion group’s leak page — stays the primary source reporters and regulators rely on.
The Structural Lesson
Fairlife’s shutdown is a data point in a much larger pattern: ransomware groups have learned that hitting operational technology — even indirectly, through shared IT infrastructure — produces faster leverage than encrypting office files alone. A stopped beverage line generates headlines, retail-partner phone calls, and SEC disclosure obligations within days; a locked file server generates an IT ticket. That asymmetry is exactly why Anubis and groups like it increasingly aim at manufacturers, and why the $17 billion manufacturing-ransomware downtime figure since 2018 keeps climbing rather than plateauing.
The regulatory layer adds a second pressure point that didn’t exist in earlier ransomware cycles. Public companies now have to make disclosure judgment calls inside the same 96-hour window an extortion group is using to apply maximum pressure, which means the SEC’s 2023 disclosure rule has inadvertently synchronized corporate legal timelines with attacker negotiation timelines. Any manufacturer — public or private, beverage or otherwise — that hasn’t rehearsed this exact sequence (breach, containment, materiality call, disclosure, leak-site countermove) is planning to improvise it live, on the same week a rival’s leak-site claims are already shaping the narrative.
Frequently Asked Questions
What happened in the Coca-Cola Fairlife ransomware attack?
On July 16, 2026, Coca-Cola filed an SEC Form 8-K disclosing that its Fairlife dairy subsidiary suffered a ransomware event that reached production-related systems, temporarily halting US manufacturing. On July 20, the Anubis ransomware group posted Fairlife to its dark web leak site, claiming it encrypted Fairlife’s Nutanix infrastructure and stole roughly 1TB of data — though later reporting put the confirmed leaked volume at 671GB.
Why did an IT ransomware attack stop physical production lines?
Modern manufacturing plants connect ERP systems, engineering workstations, file shares, and production support systems to the factory floor, so a ransomware attack on “IT” can still disable the systems plant operators depend on to run production, even without directly touching a controller. DeepStrike’s manufacturing cybersecurity research notes that weak IT/OT segmentation and third-party vendor access — involved in 61% of manufacturing breaches — are the most common paths attackers use to cross from corporate networks into plant environments.
What should manufacturers do to prevent a similar shutdown?
Manufacturers should map and pressure-test every connection between IT and OT systems, verify leak-site data claims independently before making disclosure decisions, and build a production continuity plan that assumes IT systems could be unavailable for five or more days. With manufacturing ransomware downtime averaging $1.9 million per day according to Comparitech data, the financial case for testing these fallbacks before an incident — not during one — is direct and quantifiable.
Sources & Further Reading
- Coca-Cola confirms hackers stole data in Fairlife ransomware attack — Help Net Security
- Coca-Cola Reveals Subsidiary Fairlife Suffered Data Breach — Infosecurity Magazine
- Ransomware Costs Manufacturing Sector $17bn in Downtime — Infosecurity Magazine
- Anubis: A Closer Look at an Emerging Ransomware with Built-in Wiper — Trend Micro
- Anubis Ransomware Group: A Global Threat — Arete
- Manufacturing Cybersecurity Statistics 2026: OT Risk & Ransomware — DeepStrike
- SWK Cybersecurity News Recap — July 2026 — SWK Technologies
- SEC Adopts Rules on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure by Public Companies — SEC.gov














