# Anubis Ransomware Stopped Fairlife's Milk Lines. The Wiper Mode Is Why Coca-Cola Should Pay Attention.


Production at Fairlife, Coca-Cola's premium dairy brand, went dark last week. Not because of a supply chain crunch or equipment failure — because ransomware encrypted the systems that run it, and a group called Anubis walked away with a terabyte of data and a hard deadline.


Coca-Cola disclosed the attack publicly, which is more than most companies do. What they haven't said is whether they're negotiating, and they have about a week to decide.


## A Group Seven Months Old, Already Claiming 100 Victims


Anubis surfaced in December 2024. That's not long ago. Seven months in, the group has already listed roughly 100 organizations on its leak site — a pace that puts them in the upper tier of active ransomware operations by volume. They're not the most sophisticated threat actor you've ever heard of, but they're clearly not amateur hour either.


The double-extortion model they use — encrypt the files, steal the data, threaten both — is now table stakes in ransomware. Every serious operation runs this playbook. What makes Anubis worth watching is something else: a feature they're calling "wiper mode."


## The Wiper Isn't Just a Threat. It's a Negotiating Mechanism.


Traditional ransomware holds data hostage. Pay up, get the decryption key, get your files back. Painful, but at least there's a path forward. Wiper mode breaks that model.


If Anubis activates it, encrypted files aren't just locked — they're permanently deleted. No key, no recovery, no coming back from backup if the backup itself was part of what they encrypted. That changes the math on paying versus not paying in a way defenders need to understand clearly: the ransom isn't just buying silence about stolen data anymore. It's potentially the last chance to avoid losing the data entirely.


For a company like Fairlife — which has to manage production records, supplier contracts, logistics data, and likely years of formulation and quality control documentation — permanent deletion isn't an abstract threat. It's operational collapse.


## Dairy Doesn't Sound Like Critical Infrastructure Until the Lines Stop


Fairlife is a meaningful business. Their milk products sit in millions of refrigerators. Production disruption at a major dairy operation doesn't trigger the same national conversation as a pipeline going offline, but the underlying dynamics are identical: ransomware hit operational technology (or systems adjacent to it) and physical production stopped.


The food and agriculture sector has been on the radar of threat researchers for years, but it still doesn't get the policy attention or security investment that energy or finance receives. The 2021 JBS Foods attack knocked out a significant share of U.S. beef processing capacity for days. A 2022 attack hit Dole's salad operations. The pattern is clear: ransomware operators have figured out that hitting the food supply chain creates immediate, visible pressure that forces executive attention in a way that a garden-variety data breach does not.


Coca-Cola is a massive company with legal resources, an insurance program, and incident response capabilities that most organizations can only dream about. They'll survive this. The question is what posture they take publicly and whether they negotiate, and what precedent that sets.


## The Subsidiary Play


There's a specific tactic worth naming here: Anubis listed Coca-Cola on its leak site, even though the actual target was Fairlife. That's deliberate brand amplification. The Coca-Cola name gets more coverage, more eyeballs, more pressure on the corporate parent to intervene.


This is increasingly common. Ransomware groups have gotten sophisticated about understanding corporate structures. Hitting a subsidiary with a recognizable parent gives you a two-for-one: the technical target and the reputational target. The subsidiary may not have the parent company's security stack, making it easier to breach. But the parent company's name means the story travels further and the embarrassment cuts deeper.


Security teams at major corporations should be asking themselves honestly how well-instrumented their subsidiaries actually are. Acquisitions often bring in legacy infrastructure, different IT cultures, and security gaps that don't get addressed until something goes wrong.


## What Defenders Should Take From This


A few concrete observations for security teams watching this:


  • Wiper capability demands airgapped backups. If your incident response plan assumes you can restore from backup after a ransomware hit, wiper mode is the specific counter to that assumption. Immutable, offline backups are not optional anymore.
  • Subsidiary environments need parity. If your M&A playbook doesn't include a security integration checklist with hard timelines, this is a case study in why it should.
  • The one-week deadline is negotiating theater. Anubis set a deadline of July 27. These deadlines almost always get extended — either because the victim is negotiating, or because the attacker wants to leave the door open. It's pressure, not a hard clock. Experienced IR teams know this.
  • 1 TB of data is a lot to verify. Anubis claims 1 TB of "confidential data." That claim should be verified through forensics before any payment decision — what was actually taken, whether it includes personally identifiable information, and whether disclosure obligations are triggered.

  • ---


    ## HackWire Analysis


    The Fairlife attack fits a pattern that's been building for two years: ransomware groups deliberately targeting subsidiaries of household-name corporations. The logic is sound from an attacker's perspective — subsidiaries often lag behind parents in security investment, carry inherited technical debt from pre-acquisition environments, and yet sit inside corporate structures where a breach creates maximum reputational pressure at the top.


    What's more interesting here is the wiper mode feature. A handful of ransomware groups have experimented with wiper capabilities, but they're typically deployed as a punishment mechanism after a victim refuses to pay or as a geopolitical statement in state-sponsored attacks. Building it in as a standard feature — a commercial offering, essentially — represents a meaningful escalation in the leverage available to criminal operators. It signals that Anubis is positioning itself as a premium threat actor, one willing to cause irreversible harm rather than just inconvenience.


    The food sector angle is also underreported. Since 2021, there have been at least eight significant ransomware incidents against food and agriculture targets in the U.S. and Europe that caused measurable production disruption. None of them generated the same legislative or regulatory response as comparable incidents in energy or healthcare. CISA has issued advisories. The sector has participated in tabletop exercises. But the investment gap between where food and agriculture security is and where it needs to be remains significant — and ransomware groups know it.


    Coca-Cola's response over the next week will be watched carefully. The outcome — pay, don't pay, partial negotiation — won't become public immediately. But the data almost certainly will, whether or not a ransom changes hands. Fairlife's customers and partners should assume that whatever Anubis took is compromised.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)