# Anubis Ransomware Turns Up the Heat on Coca-Cola's Fairlife
Ransomware crews don't usually need a marketing strategy. But claiming an attack on a brand synonymous with America's refrigerator — one that generated over $1 billion in retail sales in 2023 — gets you headlines, and headlines are leverage.
The Anubis ransomware gang has announced they breached Fairlife, Coca-Cola's premium dairy subsidiary, and are threatening to publish what they describe as stolen corporate data unless a ransom is paid. No timeline has been confirmed. No ransom figure has been publicly disclosed. But the clock is ticking in the way it always does in double-extortion scenarios: loudly enough that everyone in the building can hear it.
## Who Gets Hit When a Dairy Brand Gets Ransomed
Fairlife isn't exactly a household name in the way Coca-Cola's flagship products are, but it's a dominant player in a specific corner of the market. The brand's ultra-filtered milk lines and Core Power protein shakes are staples at gyms, Targets, and hospital cafeterias across the country. Coca-Cola completed a full acquisition of Fairlife in 2020 after years of a joint venture with founder Mike McCloskey.
What that corporate structure means, practically, is that Fairlife sits at the intersection of a massive enterprise IT estate (Coca-Cola's global infrastructure) and the kinds of smaller, semi-autonomous subsidiary operations that often lag behind in security maturity. The subsidiary problem is one of the persistent failure modes in enterprise security: you inherit a business, inherit its network, and don't always inherit the same controls you run at headquarters.
The Anubis group, operating a ransomware-as-a-service (RaaS) model, knows how to find that gap.
## Double Extortion, Same Playbook
Anubis operates the now-standard RaaS double-extortion model: exfiltrate data first, deploy ransomware second, then threaten publication as leverage even if the victim restores from backups. This approach, pioneered at scale by Maze ransomware around 2019, effectively neutralized the "just restore from backup" response that organizations had been leaning on.
The gang maintains a data leak site where they publish stolen files from victims who don't pay — a pressure mechanism that turns the attack into a reputational crisis regardless of whether encryption actually crippled operations.
In the Fairlife case, the specific nature of the stolen data matters enormously. If this is supplier contracts, R&D documents, financial forecasts, or merger-and-acquisition materials — the kind of corporate data that a company with Fairlife's trajectory would be generating — that's significant commercial exposure. If it touches any co-manufacturer relationships or logistics data, third parties get pulled into the blast radius.
What's less immediately obvious as a risk here: Fairlife has had prior legal trouble with animal welfare investigations in 2019 that drew significant scrutiny. Ransomware groups have increasingly shown willingness to cherry-pick embarrassing internal communications rather than simply dumping raw databases. Selective publication can be more damaging than bulk release.
## Food and Beverage Is a Soft Target
This isn't the first time a major food or beverage brand has ended up in a ransomware gang's sights, and the pattern deserves scrutiny.
JBS, the world's largest meat producer, paid $11 million to REvil in 2021 after a ransomware attack briefly disrupted beef processing across the United States. Dole disclosed a ransomware attack in early 2023 that temporarily shut down North American production. Pepsi Bottling Ventures suffered a breach the same year. Sysco, one of the largest food distributors in the country, reported a breach affecting 126,000 individuals.
The throughline across these incidents isn't bad luck. Food and beverage companies operate complex supply chains with legacy operational technology (OT), numerous third-party logistics integrations, and often decentralized IT inherited through decades of acquisitions. They aren't building widgets in a digital-native environment — they're running cold chains, distribution networks, and manufacturing operations that were designed before anyone worried much about network segmentation.
| Incident | Year | Outcome |
|----------|------|---------|
| JBS Foods | 2021 | $11M ransom paid |
| Dole | 2023 | North American production halted |
| Pepsi Bottling Ventures | 2023 | Data breach, ~30K affected |
| Sysco | 2023 | 126K individuals notified |
Fairlife joins an uncomfortable list.
## What Anubis Is Actually After
The Anubis group is worth watching beyond this specific incident. They emerged as a notable RaaS operator in recent years and have targeted organizations across sectors. What distinguishes Anubis from some lower-tier groups is a degree of operational patience — they tend to spend time in victim environments before triggering the extortion phase, which suggests they're looking for high-value data to maximize leverage, not just running spray-and-pray encryption.
The choice to publicly claim the Fairlife attack rather than negotiate quietly also suggests they're either testing Coca-Cola's response posture or they've already hit a wall in private negotiations. Public disclosure by ransomware groups typically comes after a victim refuses initial contact or misses an internal deadline. If that's the case here, the data publication clock may be closer to zero than the public announcement makes it appear.
---
## HackWire Analysis
The Fairlife breach fits a pattern that's been building for several years, but the food and beverage sector still hasn't internalized the lesson that peers in finance and healthcare were forced to learn the hard way.
What's missing from most coverage of this incident is the subsidiary angle. Coca-Cola is an enormous enterprise with substantial security resources. But Fairlife, acquired in full just six years ago, operates production facilities, cold chain logistics, and co-manufacturer relationships that carry their own attack surface. Enterprise security teams frequently underestimate integration risk — the moment a subsidiary's ERP, logistics platform, or even email system touches the parent company's network, that becomes a lateral movement opportunity. The attacker doesn't need to breach Coca-Cola's headquarters. They need to find the weakest link in a sprawling acquired portfolio.
The selective publication risk also deserves more attention. Anubis doesn't just publish data as a punishment — they curate it. Ransomware groups have become sophisticated about identifying documents that carry legal, regulatory, or reputational weight. For Fairlife specifically, given its history of public controversy and its premium brand positioning, the calculus around paying versus not paying is more complex than the ransom number alone suggests.
For defenders watching this unfold: subsidiaries acquired in the last five years should be at the top of your threat modeling queue right now. Segment aggressively. Audit third-party integrations. And if you don't know what data would be most damaging if selectively published from your environment, threat intelligence teams need to answer that question before a ransomware group does it for you.
Coca-Cola hasn't confirmed the breach publicly as of this writing. That silence is its own data point.
— HackWire Editorial
---
## Related Coverage