# Anubis Hit Fairlife. Coca-Cola Is Doing the Corporate Tango While the Clock Runs Out.
The ransomware attack on Fairlife — Coca-Cola's premium dairy brand — confirms what security teams in the food and agriculture sector have been dreading: the industrial producers behind America's grocery staples are soft targets, and the gangs know it.
Coca-Cola disclosed the intrusion on July 16, announcing it had suspended production at Fairlife's four U.S. facilities while it investigated what it politely called "a cybersecurity intrusion." The Anubis ransomware group made things less polite four days later, posting Coca-Cola and Fairlife on its public leak site and claiming to have walked out with one terabyte of confidential data. On Monday, Coca-Cola confirmed the data was actually taken — the first time the company acknowledged this publicly, and only after Anubis set a public countdown timer.
That timer, ticking toward a data dump unless a ransom lands, was still running at the time of publication.
## Who Is Anubis and Why You Should Pay Attention
Anubis hasn't been around long enough to have a Wikipedia page, but it's built its reputation fast. Active since December 2024 — barely seven months — the group has already listed roughly 100 organizations on its leak site. That's not a slow-burn operation; that's an aggressive land-grab pace that suggests either a well-resourced team or a group that recycled infrastructure and playbooks from a predecessor operation.
The group runs a textbook double-extortion model: encrypt the files, steal the data, and now you have two levers. Pay up or your operations stay crippled. Pay up or your customers' data — or your internal financials, contracts, and supplier lists — go public. Most ransomware crews stop there. Anubis doesn't.
What makes Anubis genuinely different is the wiper mode. Buried in its toolkit is a feature that can permanently delete victim files, stripping away any possibility of recovery without a ransom payment. This isn't ransomware in the traditional sense; it's a loaded gun with the safety off. When a group can credibly threaten "pay us or we burn your backups," the negotiating posture shifts entirely. Security vendors noticed this capability when it emerged, and it moves Anubis from nuisance-tier to genuinely destructive-tier threat actor.
## The Food Sector Problem Nobody Wants to Talk About
Fairlife makes protein shakes, flavored milk, and ultra-filtered dairy products. It's not a bank. It doesn't hold credit card numbers at scale. So why would a ransomware crew target it?
Because operational disruption in food production is itself the weapon.
Fairlife's four U.S. facilities going offline doesn't just stop production — it strains a supply chain that feeds retail shelves nationwide. Coca-Cola was careful to note that "retail availability of Fairlife products has been largely unimpacted, due to the availability of existing inventory," and that's a meaningful statement. They had buffer. But the incident reveals how narrow that buffer can be and how quickly a ransomware dwell-time of even a week can eat into it.
The agricultural and food manufacturing sector has been on the receiving end of a sustained targeting campaign for several years now. The 2021 JBS Foods attack — which briefly disrupted beef processing across multiple countries — was the clearest demonstration that food supply chains are critical infrastructure in practice, even when they aren't designated as such in law. Since then, the playbook has been adopted by successively smaller ransomware crews. You don't need to be sophisticated to hit a dairy plant. You need to find a weak perimeter, move laterally, and encrypt fast.
The Fairlife attack fits that template precisely.
## "Not Reasonably Likely to Have a Material Impact"
Coca-Cola's public statement includes the phrase that every publicly traded company reaching for its securities attorneys now defaults to: the incident "has not had, and is not reasonably likely to have, a material impact on the company's financial condition or results of operations."
This is post-2023 SEC disclosure language, and it's technically precise in a way that's almost deliberately unhelpful. It means the parent company's stock price and earnings call guidance are probably fine. It says nothing about what data was taken, whose information is at risk, or what Fairlife's remediation costs look like. It's a liability management sentence dressed as transparency.
The gap between what companies are legally required to say and what their customers, employees, and supply chain partners actually need to know remains one of the most persistent failures in breach disclosure. Coca-Cola hasn't said whether employee records were taken. It hasn't said whether supplier data, financial documents, or operational blueprints are in the 1TB Anubis claims to hold. "Certain data" is the loosest possible non-denial.
That vagueness serves the company. It doesn't serve anyone trying to assess their own exposure.
## What the Countdown Means for Negotiations
Anubis running a public countdown timer while negotiations presumably proceed in the background is a calculated humiliation tactic. The visibility pressure is the point. Every security researcher, journalist, and competitor watching that timer is indirect pressure on Fairlife's leadership.
Extortion groups have refined this theater over the past three years. The timer isn't always honored — groups routinely extend deadlines when there's money still potentially on the table — but the public posting itself is irreversible. The reputational damage of being listed on a ransomware site doesn't undo when the timer resets. Anubis already got what it needed in terms of public attention the moment it posted the listing.
The 1TB claim is worth treating skeptically. Ransomware crews routinely inflate data volume claims to increase negotiating pressure, and "1TB of confidential data" is a round number that almost certainly reflects what they're advertising rather than what they actually have indexed and ready to release. That said, even a fraction of that — if it includes personal data, financial records, or trade secrets — creates real exposure.
---
## HackWire Analysis
The Fairlife attack lands in a context that makes it more significant than a single corporate breach. Anubis has now crossed 100 claimed victims in under eight months — a tempo that rivals the early aggressive expansion of LockBit and ALPHV before law enforcement disruptions slowed both groups. The wiper capability is the detail that should concern defenders most. Adding a destructive fallback to a ransomware toolkit signals a group willing to escalate beyond money extraction into pure damage. That's a posture shift.
For food and agriculture security teams, the operational lesson is uncomfortable: production OT environments are increasingly reachable from corporate IT networks, and the IT network is where most of these intrusions start. The JBS breach followed the same path. So did the 2021 attack on NEW Cooperative, the Iowa grain cooperative that handles a significant share of U.S. corn and soy scheduling. A pattern of IT-to-OT lateral movement in agricultural producers is not a coincidence — it's an industry-wide architectural vulnerability.
What other coverage is missing here: the supplier and partner exposure. When 1TB leaves a food manufacturer, it doesn't just contain employee records. It contains supplier contracts, pricing agreements, logistics routes, and procurement data for dozens of companies in the supply chain. None of those companies have been notified publicly. None of them get a countdown timer. Indirect victims of ransomware exfiltration are a systematically underreported category, and the Fairlife breach is a clean example of why that matters.
Defenders in food and beverage, agriculture, and consumer goods manufacturing should treat this as a forcing function: segment OT from IT aggressively, test your backups against wiper scenarios (not just ransomware scenarios), and have an incident response retainer in place before you need it. The ceiling on attacker sophistication required to reach your production floor has dropped significantly. — HackWire Editorial
---
## Related Coverage