Coca-Cola Confirms Fairlife Data Theft
Eleven days after the initial 8-K, Coca-Cola confirms hackers stole data from Fairlife in the ransomware attack. Volume and categories remain undisclosed.
Data theft confirmed. BleepingComputer reports that Coca-Cola has acknowledged hackers exfiltrated data from its Fairlife dairy subsidiary during the ransomware attack disclosed via SEC 8-K on July 16. Confidence on the confirmation: as-reported.
That closes the last major open question from the original filing, which stated only that production-related systems were compromised and left data theft explicitly unconfirmed.
Timeline
- ~July 9 — Initial access, per Anubis’s claim. Not corroborated by Coca-Cola.
- July 16 — Coca-Cola files SEC 8-K. US Fairlife production halted. Data theft: unconfirmed at filing.
- July 21 — Anubis claims responsibility. Alleges ~1TB exfiltrated and Nutanix systems encrypted. Coca-Cola declines to comment.
- July 27 — Coca-Cola confirms data was stolen. Company-acknowledged exfiltration for the first time.
What is now confirmed
- Ransomware attack occurred. Company-confirmed via July 16 8-K.
- Data was exfiltrated from Fairlife systems. Company-confirmed, July 27.
What remains open
- Volume. Anubis claims approximately 1TB. Coca-Cola has not stated a figure. Unconfirmed — treat accordingly.
- Data categories. No disclosure on what was taken — employee records, customer data, financial documents, operational data. Not stated.
- Negotiation status. Whether a ransom was demanded in a specific amount, whether payment occurred, and whether Anubis’s publication deadline passed without consequence: not stated.
- Attribution vector. Anubis is the named claimant. Initial-access method has not been confirmed by Coca-Cola or independently verified. Not stated.
- US production status. The 8-K said “temporarily” suspended. Current restart timeline: not updated.
Context
The Anubis crew has been active since late 2024. Its affiliates have used Citrix Bleed 2 (CVE-2025-5777) for initial access in prior campaigns; no evidence ties that vector to the Fairlife intrusion on current evidence.
The company’s confirmation now removes the “unverified” qualifier from data theft. It does not add the volume, category, or timeline details that would let operators in adjacent sectors assess specific exposure risk. Those remain Anubis’s claims only.
Sources
- BleepingComputer: Coca-Cola confirms data theft in Fairlife ransomware attack — July 27, 2026.
- Prior coverage: Anubis claims Fairlife hit, 1TB and Nutanix encrypted — 0dayNews, July 21, 2026.
- Prior coverage: Coca-Cola halts Fairlife US production after ransomware — 0dayNews, July 16, 2026.
Found this useful? Share it.


