logologo
QuantliQuantli

News

/

Coca-Cola Resumes Fairlife Milk Production After Ransomware Attack

News

Market Update

Coca-Cola Resumes Fairlife Milk Production After Ransomware Attack

Suhaib

Executive summary

Coca-Cola has restored the majority of production at Fairlife's four US plants following a ransomware attack that forced a temporary shutdown in mid-July. The Anubis hacking group claimed responsibility and allegedly stole 1TB of data, though retail availability remained largely unaffected due to existing inventory. Coca-Cola does not expect a material financial impact from the incident.

What happened

Fairlife, Coca-Cola's wholly owned dairy brand, suspended production at its four US manufacturing facilities after detecting unauthorised access to its computer network around July 16. The Anubis ransomware group claimed responsibility for the attack, stating it encrypted Fairlife's servers and stole 1 terabyte of data. Coca-Cola brought in external cybersecurity experts to investigate and began restoring affected systems. By late July, the company announced it had resumed the majority of production, though some systems remain under restoration. Fairlife's Canadian plants were unaffected and continued operating throughout the incident.

Why it matters

The attack disrupted operations at a brand generating over $3 billion in annual sales for Coca-Cola, which acquired Fairlife for approximately $7 billion in 2020. However, the company mitigated immediate supply chain risk by drawing on existing inventory, keeping products available at retail during the shutdown. Coca-Cola confirmed that certain data was stolen but stated the incident is not reasonably likely to have a material impact on its financial condition or results of operations. The company has not disclosed whether it paid a ransom, and the Anubis group still lists Fairlife as a victim on its site, suggesting no payment was made.

Bigger picture

Ransomware attacks on food and beverage manufacturers pose operational and supply chain risks, particularly when production systems are compromised. The Anubis group, which emerged in late 2024, operates a ransomware-as-a-service model and has been targeting organisations through spear-phishing campaigns. Cybersecurity experts note that Anubis affiliates often gain initial access via malicious documents or executables, and the malware includes an optional wipe mode that can erase files rather than encrypt them. The incident highlights the vulnerability of consumer goods companies to cyberattacks that can disrupt manufacturing, even when product quality and safety remain intact.

What to watch

Monitor whether Coca-Cola fully restores all four Fairlife plants to normal production capacity and completes its cybersecurity investigation. Watch for any disclosure of what specific data was stolen and whether the Anubis group follows through on its threat to leak the information. Investors should also track whether product shortages emerge if inventory levels decline before full production resumes, and observe Coca-Cola's second-quarter earnings report for any revised commentary on the incident's financial impact.

#supply chain
#operations
#cybersecurity

Comments (0)

KO

Coca-Cola Co

NYSE

•

Consumer Staples

$84.07

USD

+$1.82

(+2.21%)

At close: Jul 27, 2026, 4:00 PM EDT

Market Cap:

$356.91B

Volume:

19.9M

52w High:

$85.68

P/E Ratio (TTM):

26.05

View Company Page

Daily Analyst Ratings

Track how 1,000 Wall Street analysts rate stocks — updated daily.

See which S&P 500 stocks analysts expect to rise most.

View Top Upside Stocks

Top Gainers

SMCI

Super Micro Computer Inc

$30.56

+19.8%

ARWR

Arrowhead Pharmaceuticals Inc

$88.70

+19.0%

FBRX

Forte Biosciences Inc

$56.63

+11.6%

WAB

Westinghouse Air Brake Technologies Corp

$290.00

+10.0%

View all

Upcoming IPOs