Anubis claims Fairlife hit, 1TB and Nutanix encrypted
Anubis ransomware has claimed the July 16 Coca-Cola Fairlife attack, alleging ~1TB stolen and full Nutanix encryption. Coca-Cola declined to comment; BleepingComputer could not verify.
Claim posted. Anubis has taken credit for the July 16 attack on Coca-Cola’s Fairlife dairy subsidiary and is threatening to publish stolen data. Confidence on the claim’s existence: as-reported by BleepingComputer from Anubis’s dark web leak site. Confidence on the claim’s contents: unverified — treat accordingly.
What Anubis says
- Volume. “Approximately one terabyte of corporate data” allegedly exfiltrated. Sample selection not published at time of writing.
- Impact. “We have fully encrypted their Nutanix systems.” Nutanix confirmation from Coca-Cola or Fairlife: not stated.
- Timeline. Anubis says the intrusion happened “roughly a week” before Coca-Cola’s July 16 disclosure — placing initial access on or around July 9. Corroboration from the SEC 8-K: none — the filing does not date the intrusion.
- Deadline. Publish threatened “unless the company enters negotiations by the end of the week.” No specific dollar demand disclosed on the leak page.
- Recovery framing. “They have no chance of recovering without our encryption key.” Standard extortion language, not a technical claim.
What Coca-Cola says
Coca-Cola declined to comment on the Anubis claim when BleepingComputer reached out. The original 8-K still stands as the only company-authorized public account. No amended or supplemental filing has hit EDGAR at the time of writing.
That is a change in posture from July 16 — the 8-K said law enforcement was engaged and outside advisors were on scene. “No comment” now is consistent with an active negotiation window, or with legal counsel simply refusing to react to leak-site theater. Either read is speculative. Not confirmed.
What is still not verified
- Whether Anubis actually holds ~1TB of Fairlife data. Leak-site totals routinely inflate.
- Whether Nutanix systems specifically were encrypted, or any systems at all. The 8-K referenced “production-related systems” without naming a virtualization stack.
- Whether initial access happened around July 9 as Anubis says, or earlier.
- Whether a ransom has been demanded in a specific amount, and whether Coca-Cola has responded to it privately.
BleepingComputer states directly that it “could not independently verify the gang’s claims regarding the alleged theft of data, the encryption of Fairlife’s systems, or the amount of data purportedly stolen.” That is the correct posture. Ours too.
Where this sits
Anubis has been active as a ransomware-as-a-service operation since December 2024, and its affiliates have been named in initial-access chains involving Citrix Bleed 2 (CVE-2025-5777) — no evidence yet ties the Fairlife intrusion to that vector or any other named CVE. Attribution to a group is not attribution to a technique.
This slots into the ongoing food-and-beverage ransomware tempo — the second disclosed event in the sector this quarter and the first with a named claimant. It does not, on current evidence, change the picture of who is attacking manufacturing IT, only that Anubis is willing to name a target that big publicly before any negotiation resolves.
What to watch next
- Sample data. If Anubis posts document samples, those become the first verifiable data point. Corporate-formatted internal files that check against Fairlife record structure are the tell; the volume claim on its own is not.
- 8-K/A from Coca-Cola. Material developments — confirmed exfiltration, negotiation status change, restart timeline slipping — trigger an amended filing. That, not the leak page, is the record.
- US production status. The 8-K left restart “temporarily” open. Every additional day the US Fairlife line is dark is a data point about the recovery difficulty, independent of whatever Anubis publishes.
- A CISA advisory. Still nothing at time of writing. One naming an initial-access vector would change what the rest of the sector does about this.
Confidence on everything above: the Anubis claims are the gang’s, not confirmed; Coca-Cola’s “no comment” is on the record via BleepingComputer. Everything else stays where the July 16 piece left it.
Sources
- BleepingComputer: Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak — July 21, 2026.
- Coca-Cola Company: Form 8-K, filed 2026-07-16 — the standing primary disclosure.
- Prior coverage: Coca-Cola halts Fairlife US production after ransomware — 0dayNews, July 16, 2026.
Found this useful? Share it.


