Executive summary
Coca-Cola has restored the majority of production at Fairlife's four US plants following a ransomware attack that forced a temporary shutdown in mid-July. The Anubis hacking group claimed responsibility and allegedly stole 1TB of data, though retail availability remained largely unaffected due to existing inventory. Coca-Cola does not expect a material financial impact from the incident.
What happened
Fairlife, Coca-Cola's wholly owned dairy brand, suspended production at its four US manufacturing facilities after detecting unauthorised access to its computer network around July 16. The Anubis ransomware group claimed responsibility for the attack, stating it encrypted Fairlife's servers and stole 1 terabyte of data. Coca-Cola brought in external cybersecurity experts to investigate and began restoring affected systems. By late July, the company announced it had resumed the majority of production, though some systems remain under restoration. Fairlife's Canadian plants were unaffected and continued operating throughout the incident.
Why it matters
The attack disrupted operations at a brand generating over $3 billion in annual sales for Coca-Cola, which acquired Fairlife for approximately $7 billion in 2020. However, the company mitigated immediate supply chain risk by drawing on existing inventory, keeping products available at retail during the shutdown. Coca-Cola confirmed that certain data was stolen but stated the incident is not reasonably likely to have a material impact on its financial condition or results of operations. The company has not disclosed whether it paid a ransom, and the Anubis group still lists Fairlife as a victim on its site, suggesting no payment was made.
Bigger picture
Ransomware attacks on food and beverage manufacturers pose operational and supply chain risks, particularly when production systems are compromised. The Anubis group, which emerged in late 2024, operates a ransomware-as-a-service model and has been targeting organisations through spear-phishing campaigns. Cybersecurity experts note that Anubis affiliates often gain initial access via malicious documents or executables, and the malware includes an optional wipe mode that can erase files rather than encrypt them. The incident highlights the vulnerability of consumer goods companies to cyberattacks that can disrupt manufacturing, even when product quality and safety remain intact.
What to watch
Monitor whether Coca-Cola fully restores all four Fairlife plants to normal production capacity and completes its cybersecurity investigation. Watch for any disclosure of what specific data was stolen and whether the Anubis group follows through on its threat to leak the information. Investors should also track whether product shortages emerge if inventory levels decline before full production resumes, and observe Coca-Cola's second-quarter earnings report for any revised commentary on the incident's financial impact.
Comments (0)
KO
Coca-Cola Co
NYSE
•
Consumer Staples
$84.07
USD
+$1.82
(+2.21%)
At close: Jul 27, 2026, 4:00 PM EDT
Market Cap:
$356.91B
Volume:
19.9M
52w High:
$85.68
P/E Ratio (TTM):
26.05
Related News
Daily Analyst Ratings
Track how 1,000 Wall Street analysts rate stocks — updated daily.
See which S&P 500 stocks analysts expect to rise most.