Anubis Attacks Coca-Cola's Fairlife Subsidiary
The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola's dairy brand, Fairlife. The attack, which halted production, allegedly involved the theft of 1 TB of corporate data, with threats to leak it.
What Happened
Fairlife, a dairy brand subsidiary of the global beverage giant Coca-Cola, has become the target of a major cyberattack. A ransomware gang known as Anubis has claimed responsibility for the attack, stating they have crippled the company's operations and exfiltrated a large amount of data. The attackers are threatening to leak the allegedly stolen data unless a ransom is paid.
The incident was first disclosed to the public on July 16 by The Coca-Cola Company. The company announced that they had detected a ransomware attack affecting Fairlife's operations, forcing them to temporarily suspend activities at their U.S. production facilities. This initial statement did not share details about the attackers' identity, whether data had been stolen, or if a ransom demand had been received.
However, on Monday, the Anubis ransomware gang officially took credit for the attack by adding Fairlife to its dark web data leak site. The group stated that it has given the company until the end of the week to begin negotiations, otherwise, they will publish the data in their possession. This development indicates that the attack has evolved from a mere operational disruption to a potential data breach.
Data Compromised
According to the Anubis gang's claim, approximately 1 terabyte (TB) of corporate data was stolen during the attack. While the specific contents of this data have not been disclosed, ransomware groups are known to target sensitive and valuable information such as financial records, employee information, customer lists, trade secrets, and operational documents.
This claim of data theft by the attackers has not yet been independently verified. Coca-Cola is refraining from commenting on the matter. If the claims are true, a data leak of this magnitude could lead to significant reputational damage, legal issues, and a competitive disadvantage for Fairlife and its parent company, Coca-Cola. The nature of the stolen data will be critical in determining the full scope of the incident.
How the Attack Happened
The technical details of the attack have not yet been fully clarified. However, the Anubis gang provided some clues in a statement to BleepingComputer. The group claimed to have fully encrypted Fairlife's Nutanix infrastructure. Nutanix is a critical infrastructure solution that combines server, storage, and network resources into a single platform for virtualization. The encryption of such an infrastructure explains why the company had to halt its core operations, including production.
The attackers are trying to corner the company by stating, "They have no chance of recovering without our encryption key." They also mentioned that they carried out the attack about a week before the company publicly disclosed it and that the instructions they left on the network were not followed. How the attackers initially breached the network (the attack vector) remains unknown. Such attacks often begin with methods like phishing emails, software vulnerabilities, or weak password security.
Who is the Anubis Ransomware Group?
Anubis is a relatively new but dangerous player in the cybersecurity world. Emerging in December 2024, the group operates on a "Ransomware-as-a-Service" (RaaS) model. In this model, the core group that develops the ransomware partners with other cybercriminals (affiliates) to carry out attacks, sharing the ransom proceeds. This structure allows for the rapid proliferation of attacks.
Anubis is known for its double extortion tactic. This means they not only encrypt the victim's systems but also steal sensitive data before encryption. This way, even if the victim can restore their systems from backups, they are pressured to pay the ransom with the threat of a data leak. The group is also known to have added a data wiper to its arsenal last year, which permanently destroys the victim's files, making their threats even more dangerous.
Who is Affected
The primary entity directly affected by the attack is Fairlife, a subsidiary of Coca-Cola. The shutdown of its U.S. production operations could lead to supply chain disruptions and financial losses. The availability of Fairlife's products, such as ultra-filtered milk, Core Power protein shakes, and Nutrition Plan, may be impacted on store shelves. Operations in Canada were reported to be continuing as normal.
Indirectly affected parties include company employees, business partners, and potentially customers. If the 1 TB data leak claim is confirmed, the personal or financial information of employees and business partners could be at risk.
What You Can Do
This incident serves as an important warning for both individuals and organizations. Here are some precautions that can be taken:
- For Individual Users and Customers: Be cautious of suspicious emails, text messages, or phone calls using the Fairlife or Coca-Cola name. Attackers may use such incidents as an opportunity to launch phishing attacks. Do not trust messages that ask for your personal information or prompt you to click on suspicious links.
- For Company Employees and Business Partners: Follow official announcements from your company's cybersecurity department. Be extra vigilant about emails and attachments from unknown sources and report any suspicious activity immediately.
- Lessons for Other Organizations: This attack once again highlights the importance of protecting critical infrastructure and having a strong incident response plan. Companies should regularly back up their data, implement network segmentation, and provide ongoing cybersecurity training to their employees. Such events show the importance of regularly following Data Breach News and checking if your own data has been compromised with Data Breach Search tools.
What the Company Says
The Coca-Cola Company confirmed the incident in its initial statement on July 16. In that announcement, they stated that a ransomware attack resulted in unauthorized access to a portion of Fairlife's systems, affecting production-related systems. The company emphasized that they immediately activated their incident response and business continuity plans and that product quality and safety were not affected.
However, after the Anubis gang claimed responsibility for the attack and the data theft allegations, Coca-Cola officials, when reached by BleepingComputer, declined to comment on the matter, citing the ongoing investigation. It is a common approach for companies to remain silent in such situations until an investigation is complete.
Source
This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.