Here is the complete intel brief:
title: "Fairlife: Anubis Ransomware Extortion" date: 2026-07-23 slug: coca-cola-fairlife-anubis-ransomware
Fairlife: Anubis Ransomware Extortion
The Anubis ransomware group has claimed responsibility for a disruptive attack on Fairlife, a dairy subsidiary of Coca-Cola, that halted production and left the company weighing a ransom demand. Coca-Cola confirmed last week that operations at Fairlife were suspended following the ransomware incident. Anubis listed both Coca-Cola and Fairlife on its leak site on July 20, claiming to have encrypted servers and exfiltrated roughly 1 TB of confidential data, and gave the company one week to pay before the stolen information is published.
What Happened
Coca-Cola disclosed that production at Fairlife had been suspended due to a ransomware attack, with the full impact still under assessment at the time of disclosure. On July 20, the Anubis group publicly listed Coca-Cola and Fairlife on its dark web leak website, taking credit for the intrusion. The attackers claimed to have "locked" servers, language that typically indicates file encryption, and to have stolen approximately one terabyte of data.
The group framed the extortion around operational recovery, offering to help restore affected systems within hours if a ransom is paid. Coca-Cola was given a one-week deadline. If the company does not pay, Anubis threatens to leak the full dataset. SecurityWeek reported that it reached out to Coca-Cola for comment.
What Was Taken
Anubis claims to have exfiltrated around 1 TB of "confidential data" from Fairlife's environment. The specific contents have not been detailed publicly, but a dataset of that size from a food and beverage manufacturer typically spans corporate records, employee personal information, supplier and logistics documentation, financial data, and operational or production records.
The volume alone signals a deep and sustained presence inside the network, consistent with a threat actor that had time to move laterally and stage large-scale data collection before triggering encryption. Until Coca-Cola completes its impact assessment, the exact sensitivity and scope of the stolen data remain unconfirmed.
Why It Matters
This incident hits a well-known consumer brand through a subsidiary, a recurring pattern in which attackers exploit the relative security gaps of acquired or affiliated companies to reach a marquee parent name. The reputational pressure of associating "Coca-Cola" with a leak listing is itself part of the extortion leverage.
Anubis is not an ordinary double-extortion crew. The group has drawn industry attention for a "wiper mode" capability that permanently deletes victim files and blocks recovery. That feature raises the stakes considerably: even organizations with backups may face irreversible data destruction, and a decision to withhold payment could carry harsher consequences than in a standard encrypt-and-leak scenario. Active since December 2024, Anubis has already listed roughly 100 organizations, marking it as a fast-moving and increasingly prolific operation.
The Attack Technique
The initial access vector for the Fairlife intrusion has not been disclosed. Based on the group's known behavior, Anubis operates a double-extortion model that combines file encryption on compromised systems with exfiltration of valuable data to pressure victims into paying.
What distinguishes Anubis from typical ransomware operators is the reported wiper mode, which enables permanent destruction of victim files rather than mere encryption. This capability suggests the group is prepared to escalate beyond recoverable disruption, using the threat of unrecoverable loss as additional negotiating leverage. The claim of locked servers plus a 1 TB exfiltration indicates the attackers achieved broad access and completed staging before the disruption became visible.
What Organizations Should Do
Defenders, particularly in manufacturing and food and beverage, should treat this incident as a prompt to harden against destructive double-extortion campaigns:
- Maintain offline, immutable, and regularly tested backups so recovery does not depend on systems an attacker with wiper capability can reach or destroy.
- Segment IT and operational or production networks to limit lateral movement and prevent a single intrusion from halting manufacturing.
- Enforce phishing-resistant multi-factor authentication on all remote access, VPNs, and administrative accounts to close common initial-access paths.
- Deploy and monitor endpoint detection and response tooling to catch lateral movement, credential abuse, and large-scale data staging before exfiltration completes.
- Watch for anomalous outbound data transfers; a 1 TB exfiltration leaves detectable network signatures that data loss prevention and egress monitoring can flag.
- Extend security assessments and monitoring to subsidiaries and acquired companies, which attackers frequently target as the softer route into a larger parent organization.
Sources: Ransomware Group Threatening to Leak Data Stolen From Coca-Cola's Fairlife - SecurityWeek