Data Breaches

Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife

The Anubis ransomware group claims to have stolen 1 TB of confidential data from the Coca-Cola subsidiary.

Coca-Cola Fairlife ransomware

The Anubis ransomware group has taken credit for the disruptive attack on Coca-Cola subsidiary Fairlife and is threatening to leak stolen data unless a ransom is paid.

Coca-Cola revealed last week that production at dairy company Fairlife had been suspended due to a ransomware attack. The full impact of the incident was still being assessed at the time of disclosure.

The Anubis group listed Coca-Cola and Fairlife on its leak website on July 20. The cybercriminals claimed to have “locked” servers – this likely means they have encrypted files – and exfiltrated 1 TB of “confidential data”.

Anubis hacks Coca-Cola subsidiary Fairlife

The hackers said they can help the company restore its systems within hours if it agrees to pay a ransom. Coca-Cola has been given a week to pay up, or the stolen data will be leaked. 

SecurityWeek has reached out to Coca-Cola for comment.

[ Read: New Index Tracks Material Breaches — And Refuses to Add Up the Losses ]

Active since December 2024, the Anubis ransomware group has listed roughly 100 targeted organizations on its website. 

Advertisement. Scroll to continue reading.

Like many groups, Anubis uses a double-extortion model that involves encrypting files on compromised systems and exfiltrating valuable data to increase its chances of obtaining a ransom from victims. 

However, the cybercrime gang caught the attention of the cybersecurity industry for a ‘wiper mode’ feature enabling the attackers to permanently delete victims’ files and prevent their recovery. 

Related: Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack

Related: Clover Health Investments Discloses Data Breach

Related: Ernst & Young Data Breach Affects Personal, Financial Information

Related Content

Data Breaches

Hackers exfiltrated personal, financial, and health information from the company’s Oracle EBS instance in August 2025.

Data Breaches

Using social engineering, hackers compromised employee accounts with access to personal and health information.

Data Breaches

Longtime cybersecurity executive Richard Bird built the resource for security experts, journalists, policymakers, and everyday citizens.

Data Breaches

Hackers stole names, addresses, Social Security numbers, credit/debit card numbers, and other information from a third-party management platform.

Data Breaches

Targeting production infrastructure, the attack compromised internal datasets and service credentials.

Ransomware

The company has yet to determine the full scope, nature, and impact of the incident.

Cybercrime

The D1R cybercrime group claimed to have stolen valuable data from Synopsys and Bosch, threatening to leak it unless a ransom is paid. 

Data Breaches

The WorldLeaks extortion group claimed to have stolen 720 GB of data from the healthcare testing and laboratory services provider.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version