Coca-Cola restores most production capacity at dairy unit after ransomware attack

The company said it does not expect the Fairlife disruption to have a material impact on financial performance or operations.
Source Lens
Industry Context
Useful background context, but lower-priority than direct platform, community, or operator intelligence.
Impact Level
medium
Use this briefing to decide whether your team needs an immediate workflow, policy, or reporting change.
Key Stat / Trigger
No single quantitative trigger surfaced in this report.
Focus on the operational implication, not just the headline.
Full Coverage
An article from Coca-Cola restores most production capacity at dairy unit after ransomware attack The company said it does not expect the Fairlife disruption to have a material impact on financial performance or operations.
Published July 28, 2026 David Jones Reporter Share Copy link Email / Print License Add us on Google A majority of the production capacity at Fairlife's U. S. facilities is back online after a ransomware attack earlier this month. Permission granted by Fairlife First published on Listen to the article 2 min This audio is auto-generated.
Please let us know if you have feedback. Coca-Cola on Monday said production has mostly resumed at its Fairlife dairy facilities in the U. S. following a ransomware attack earlier this month. The company previously suspended operations at Fairlife after hackers gained access to certain systems and stole data.
Fairlife is a maker of ultra-filtered, lactose-free milk, as well as protein and nutritional shakes. Limited timeline A ransomware-as-a-service group called Anubis took credit for the attack. The hackers claimed to have locked Fairlife’s servers and stole up to 1TB of data, according to researchers at Arctic Wolf.
Anubis threatened to leak information if its demands were not met, but details of the extortion demand were not disclosed. Anubis previously gained entry to targeted sites through the use of stolen credentials or by exploiting critical vulnerabilities, including CitrixBleed2, tracked as CVE-2025-5777, Arctic Wolf said.
Anubis operates using three affiliate models, according to researchers at Sophos. The group engages in traditional ransomware-as-a-service as well as data-theft-only extortion and access monetization. Coca-Cola, while acknowledging the attack was linked to ransomware, did not comment on how it was able to restore production.
The company also did not provide any details about how the hackers gained access to the Fairlife systems. Coca-Cola said retail access to Fairlife’s milk products largely were not an issue, due to the wide availability of existing inventory. The company said Fairlife’s Canadian business was not impacted at all.
The company does not believe the attack will have a material impact on its financial condition or results of operations. Fairlife is a large business for Coca-Cola, surpassing $1 billion in annual revenue starting in 2022. The dairy unit has four locations in the U. S.
Earlier this year, Coca-Cola announced a $650 million investment to expand the size of its Coopersville, Michigan, facility. The company is also set to open a 745,000 square-foot facility in Webster, New York. The beverage giant said it is still working to fully restore all impacted systems and operations.
Add us on Google Share Copy link Email / Print License Filed Under: Operations Management
Original Source
This briefing is based on reporting from Supply Chain Dive. Use the original post for full primary-source context.
Style
Audience
