The Anubis ransomware group has taken credit for the disruptive attack on Coca-Cola subsidiary Fairlife and is threatening to leak stolen data unless a ransom is paid.
Coca-Cola revealed last week that production at dairy company Fairlife had been suspended due to a ransomware attack. The full impact of the incident was still being assessed at the time of disclosure.
The Anubis group listed Coca-Cola and Fairlife on its leak website on July 20. The cybercriminals claimed to have “locked” servers – this likely means they have encrypted files – and exfiltrated 1 TB of “confidential data”.

The hackers said they can help the company restore its systems within hours if it agrees to pay a ransom. Coca-Cola has been given a week to pay up, or the stolen data will be leaked.
SecurityWeek has reached out to Coca-Cola for comment.
[ Read: New Index Tracks Material Breaches — And Refuses to Add Up the Losses ]
Active since December 2024, the Anubis ransomware group has listed roughly 100 targeted organizations on its website.
Like many groups, Anubis uses a double-extortion model that involves encrypting files on compromised systems and exfiltrating valuable data to increase its chances of obtaining a ransom from victims.
However, the cybercrime gang caught the attention of the cybersecurity industry for a ‘wiper mode’ feature enabling the attackers to permanently delete victims’ files and prevent their recovery.
Related: Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack
Related: Clover Health Investments Discloses Data Breach
Related: Ernst & Young Data Breach Affects Personal, Financial Information
