SYS::ONLINE
Wasteland.
Briefs1499
Issues20
SinceFeb 2026
LIVE
█ Ransomware COCA-COLA-FAIRLIFE 2026-07-23

Fairlife: Anubis Ransomware Extortion

"Here is the complete intel brief:"

Here is the complete intel brief:


title: "Fairlife: Anubis Ransomware Extortion" date: 2026-07-23 slug: coca-cola-fairlife-anubis-ransomware


Fairlife: Anubis Ransomware Extortion

The Anubis ransomware group has claimed responsibility for a disruptive attack on Fairlife, a dairy subsidiary of Coca-Cola, that halted production and left the company weighing a ransom demand. Coca-Cola confirmed last week that operations at Fairlife were suspended following the ransomware incident. Anubis listed both Coca-Cola and Fairlife on its leak site on July 20, claiming to have encrypted servers and exfiltrated roughly 1 TB of confidential data, and gave the company one week to pay before the stolen information is published.

What Happened

Coca-Cola disclosed that production at Fairlife had been suspended due to a ransomware attack, with the full impact still under assessment at the time of disclosure. On July 20, the Anubis group publicly listed Coca-Cola and Fairlife on its dark web leak website, taking credit for the intrusion. The attackers claimed to have "locked" servers, language that typically indicates file encryption, and to have stolen approximately one terabyte of data.

The group framed the extortion around operational recovery, offering to help restore affected systems within hours if a ransom is paid. Coca-Cola was given a one-week deadline. If the company does not pay, Anubis threatens to leak the full dataset. SecurityWeek reported that it reached out to Coca-Cola for comment.

What Was Taken

Anubis claims to have exfiltrated around 1 TB of "confidential data" from Fairlife's environment. The specific contents have not been detailed publicly, but a dataset of that size from a food and beverage manufacturer typically spans corporate records, employee personal information, supplier and logistics documentation, financial data, and operational or production records.

The volume alone signals a deep and sustained presence inside the network, consistent with a threat actor that had time to move laterally and stage large-scale data collection before triggering encryption. Until Coca-Cola completes its impact assessment, the exact sensitivity and scope of the stolen data remain unconfirmed.

Why It Matters

This incident hits a well-known consumer brand through a subsidiary, a recurring pattern in which attackers exploit the relative security gaps of acquired or affiliated companies to reach a marquee parent name. The reputational pressure of associating "Coca-Cola" with a leak listing is itself part of the extortion leverage.

Anubis is not an ordinary double-extortion crew. The group has drawn industry attention for a "wiper mode" capability that permanently deletes victim files and blocks recovery. That feature raises the stakes considerably: even organizations with backups may face irreversible data destruction, and a decision to withhold payment could carry harsher consequences than in a standard encrypt-and-leak scenario. Active since December 2024, Anubis has already listed roughly 100 organizations, marking it as a fast-moving and increasingly prolific operation.

The Attack Technique

The initial access vector for the Fairlife intrusion has not been disclosed. Based on the group's known behavior, Anubis operates a double-extortion model that combines file encryption on compromised systems with exfiltration of valuable data to pressure victims into paying.

What distinguishes Anubis from typical ransomware operators is the reported wiper mode, which enables permanent destruction of victim files rather than mere encryption. This capability suggests the group is prepared to escalate beyond recoverable disruption, using the threat of unrecoverable loss as additional negotiating leverage. The claim of locked servers plus a 1 TB exfiltration indicates the attackers achieved broad access and completed staging before the disruption became visible.

What Organizations Should Do

Defenders, particularly in manufacturing and food and beverage, should treat this incident as a prompt to harden against destructive double-extortion campaigns:

Sources: Ransomware Group Threatening to Leak Data Stolen From Coca-Cola's Fairlife - SecurityWeek