Coca-Cola faced an uncomfortable reality on Monday when it officially admitted that a ransomware attack on Fairlife, its popular dairy subsidiary, had breached its systems and stolen sensitive company data. The admission comes days after the Anubis cybercrime group went public with threats to leak 1 TB of confidential information unless a ransom is paid.
The beverage company first detected the intrusion on July 16 and immediately suspended production across all four Fairlife facilities in the United States. That decision bought the company time to respond, but it also painted a target on their back. By July 20, Anubis had already listed Coca-Cola and Fairlife on its leak website, claiming to have stolen an enormous cache of company secrets and setting a ticking clock for payment.
Good news came quickly: production has now resumed at most facilities, and shelves remain stocked with Fairlife products. The company says retail availability hasn’t been disrupted, product safety hasn’t been compromised, and investors shouldn’t worry about financial fallout. But that calm exterior masks a much grittier reality playing out behind the scenes.
Anubis isn’t your typical ransomware gang. They operate using a ruthless double-extortion playbook: encrypt files to lock companies out of their systems, then exfiltrate sensitive data as insurance. If victims refuse to pay, the stolen files get leaked. What makes Anubis genuinely dangerous is their wiper mode. It permanently deletes files beyond recovery, transforming negotiation failures into permanent data loss. Since launching in December 2024, the group has targeted roughly 100 organizations worldwide.
At the moment Coca-Cola released its statement, an active timer on Anubis’s website was counting down to when the stolen data would be released publicly. The company refused to specify what information was compromised or whether it included customer records, employee data, or financial details. It also stayed silent on whether negotiations were underway or if any ransom discussions had occurred. It, however, filed its findings to United States Securities and Exchange Commission (SEC). You can read its online copy here.
Ransomware gangs routinely inflate the value of stolen data to pressure victims into paying. The actual importance of Anubis’s 1 TB haul remains a mystery. So does the question of whether Coca-Cola will ultimately negotiate with the attackers.

