BleepingComputer reported that Coca-Cola disclosed a ransomware attack affecting its Fairlife dairy subsidiary.
Coca-Cola said Fairlife detected unauthorized access to some systems, including production-related systems, in connection with the ransomware attack.
The company activated incident response and business continuity protocols and is working with outside advisors and cybersecurity experts.
Coca-Cola notified law enforcement about the incident.
The company said product quality and safety have not been affected.
Production at Fairlife’s U.S. facilities has been temporarily suspended while Coca-Cola responds to the incident and restores impacted systems.
Canadian production operations were not affected at the time of the report.
Coca-Cola later confirmed that attackers accessed and took certain data, though it has not disclosed the scope of that data, whether it received an extortion demand, or which ransomware operation was responsible.
A ransomware attack at fairlife, a dairy company owned by Coca-Cola, has temporarily suspended production across its U.S. facilities after unauthorized access affected a portion of its systems, including production-related infrastructure. Coca-Cola said product quality and safety were not affected, while Canadian production continued operating at the time of disclosure.
The incident demonstrates how quickly a cyberattack can move beyond data and endpoint risk to become a business continuity and supply-chain issue. When ransomware reaches systems connected to production workflows, organizations may be forced to halt operations while they contain the intrusion, assess affected environments, and restore systems safely.
For IT and security leaders, the disruption reinforces the need to align endpoint security, identity controls, incident response, and recovery planning with operational resilience—not treat them as separate priorities.
Fairlife detected unauthorized third-party access to part of its environment, including production-related systems, in connection with the ransomware event. Coca-Cola later confirmed that the attackers also took certain data, while the technical scope of the compromise remains under investigation. The Anubis ransomware-as-a-service group has since claimed responsibility, stating it encrypted Fairlife’s Nutanix infrastructure and threatening to leak roughly 1TB of stolen data if a ransom isn’t paid; Coca-Cola has not independently confirmed these claims.
This means responders must examine more than the ransomware payload or encryption activity. The investigation should reconstruct the entire intrusion lifecycle, from initial access and privilege escalation to lateral movement, persistence, data access, and operational disruption.
Key questions include:
How did the attackers gain initial access?
Were compromised credentials, exposed remote services, or unmanaged access paths involved?
Which endpoints, servers, identities, and production-supporting systems were accessed?
Were systems encrypted, deliberately shut down, or isolated as a containment measure?
What data was accessed or exfiltrated, and where was it transferred?
Did the attackers establish persistence that could survive initial restoration efforts?
Because Coca-Cola has not publicly confirmed the initial access vector or the full scope of affected assets, endpoint forensics, identity log analysis, network telemetry, and egress monitoring remain central to independently verifying the attack path described by Anubis. Investigators must also validate restored systems before reconnecting them to production workflows, particularly where compromised IT systems interact with operational processes.
Coca-Cola reported on July 27, 2026, that most production had resumed across Fairlife’s four U.S. facilities, although restoration work was still ongoing.
Mitsogo (Hexnode) Recognized as a Strong Performer in 2026 Gartner® Peer Insights™
Hexnode recognized as a Strong Performer in the 2026 Gartner® Peer Insights™ Voice of the Customer.
Strengthening Ransomware Recovery with Hexnode
Recovering from a ransomware incident requires more than restoring encrypted systems. IT teams must verify that endpoints remain compliant, remove unauthorized changes, and ensure compromised devices do not regain access to business resources before they have been fully remediated.
Hexnode UEM helps organizations maintain centralized visibility across managed endpoints, enforce security configurations, deploy operating system updates, manage software, and remotely execute remediation actions where supported. During recovery, administrators can use compliance policies and remote management capabilities to identify noncompliant devices, isolate issues, and restore endpoints to an approved security baseline.
Combined with Hexnode UEM’s device compliance, policy enforcement, and access management integrations, organizations can reduce the risk of unmanaged or noncompliant devices reconnecting to corporate resources before they meet security requirements. This supports a controlled recovery process while helping IT teams restore normal operations with greater confidence.
For security operations, Hexnode XDR extends endpoint visibility by helping security teams detect and investigate suspicious activity across managed devices. When used alongside incident response processes, it can provide additional context for identifying potentially compromised endpoints and prioritizing remediation efforts before systems are returned to production.
Featured Resource
Centralize Microsoft Defender Settings with Hexnode UEM
See how Hexnode UEM simplifies Microsoft Defender management by centralizing supported Windows security and policy deployment.
The Fairlife ransomware incident illustrates how attacks on enterprise IT can rapidly disrupt physical operations when production-supporting systems are affected. While the technical details of the intrusion remain limited, the incident highlights the importance of preparing for both cyber resilience and operational continuity.
Organizations should view ransomware preparedness as a business resilience initiative rather than solely an IT security responsibility. A layered strategy that combines endpoint management, identity security, network segmentation, continuous monitoring, and well-tested incident response and recovery plans can help contain attacks more effectively and reduce operational downtime. As manufacturing and other critical industries become increasingly interconnected, the ability to restore trusted systems quickly is becoming as important as preventing the initial compromise.
I’m a technical content writer at Hexnode who loves simplifying tech. I break down complex ideas, remove the fluff, and help readers clearly understand our product for what it actually is: simple, reliable, and built to solve real problems.