← Fairlife

2026 Fairlife (Coca-Cola) — ransomware; company confirms data theft; Anubis leak

2026 Unknown records affected Share on X

Data compromised

Company confirms unauthorized third party accessed systems and took certain data (no attested consumer/employee PII count). Anubis leak-site posts alleged ~1 TB files (field inventory unverified).

Technical writeup

Company-confirmed ransomware with confirmed data theft — Coca-Cola update July 27–28, 2026. The Coca-Cola Company disclosed (Form 8-K, July 16) that Fairlife detected unauthorized access including production-related systems in a ransomware event that temporarily suspended U.S. production, and later that the event “involved access by an unauthorized third party to a portion of the company’s systems and taking of certain data.” Anubis ransomware listed Fairlife / Coca-Cola and threatened to leak roughly 1 TB; BleepingComputer reported the actor timer expired and alleged data became available. August 16, 2026 SuspectFile / DataBreaches coverage of Anubis claims added actor assertions of ~500 hosts compromised, ~1 TB stolen, no meaningful negotiation (keys deleted after ~1 week), and that the attack was opportunistic (“open all doors with weak locks”) rather than specifically targeted at Fairlife — claims remain actor-side and not Coca-Cola-attested field inventory. No attested individual-count PII figure published; recordsAffected 0.

Root cause

Ransomware (company-confirmed). Coca-Cola confirmed unauthorized access and taking of certain data. Anubis group claimed the attack and later published alleged ~1 TB on its leak site — group attribution not independently confirmed by Coca-Cola in statements reviewed.

References