ALITEQ.

Coca-Cola just confirmed hackers stole its data the ransom clock said two hours

Fairlife's dairy plants went dark, a group called Anubis claimed a terabyte of files, and Coca-Cola's own filing still won't say what's actually in them.

Priya NairUpdated 2h ago7 min readWeb story
Interior of a large-scale dairy processing and bottling facility

Coca-Cola confirmed on July 28 that hackers didn't just knock its Fairlife dairy plants offline — they walked out with company data too. The group calling itself Anubis had already posted Fairlife to its dark-web leak site eight days earlier, claiming a full terabyte of stolen files and running a countdown clock: pay, or it goes public in two hours.

The timeline, in order

  1. Jul 16, 2026

    Coca-Cola files an SEC 8-K disclosing unauthorized access to Fairlife's production systems in a ransomware event; US manufacturing is suspended.

  2. Jul 20, 2026

    The Anubis ransomware group adds Fairlife to its dark-web leak site, claiming 1TB of stolen files and threatening publication on a countdown clock.

  3. Late Jul 2026

    Fairlife restarts the majority of production across its four US facilities, per its own technology disruption statement; Canada was unaffected throughout.

  4. Jul 28, 2026

    Coca-Cola confirms that data was in fact exfiltrated, per SecurityWeek's reporting, still without naming the data categories.

Why a dairy brand, and why the plant floor

This wasn't a marketing database or a customer-support ticket queue. Fairlife's own statement specifically names "production-related systems" as compromised, which is the detail worth sitting with. Anubis runs a double-extortion playbook — encrypt what you can reach, exfiltrate what's valuable, then threaten to publish it regardless of whether the ransom gets paid — and the same model has spent 2026 working its way through hospitals and billing processors as readily as manufacturers. Hitting the plant floor rather than the back office is what actually stops output, and stopped output is what makes a company negotiate faster than a stolen spreadsheet ever would.

Bottles moving down an automated dairy production line
Production systems, not just office IT, is what actually shuts a plant down — and what Anubis says it hit. · Unsplash

This is the food-and-beverage sector's problem now

Manufacturers have spent two decades bolting industrial control systems onto corporate networks for the sake of remote monitoring and predictive maintenance, and ransomware crews have noticed that this wiring makes an entire factory reachable from the same phishing email that used to just get someone's Outlook password. It isn't only Fairlife's problem. 2026 has been a genuinely bad year for the systems that sit behind the scenes running everything else — see the exploited-in-the-wild wave hitting SharePoint deployments all year, or Cisco's own SD-WAN manager getting a root-access bug that nobody outside networking teams noticed. The pattern is the same everywhere: attackers go after the infrastructure layer because that's where downtime actually costs money, not where the interesting data theoretically lives.

~1 TB

Data claimed stolen

4 plants

US facilities affected

2 hours

Leak countdown given

8 days

Days to confirm theft

What this means if you're not Coca-Cola

Segment operational technology from corporate IT — the network path that let this reach production systems is the same one most mid-size manufacturers haven't audited in years.

2

Verify your backups are actually immutable, not just replicated — encrypted replicas are useless against the encryption half of double extortion.

3

Run your incident-response tabletop with legal and comms in the room, not just IT — the corporate-boilerplate phase of a breach is now as predictable as the technical phase.

4

Assume regulators and class-action firms will scrutinize the gap between 'we detected an incident' and 'we confirmed data was stolen' — twelve days is already drawing attention here.

Verdict

My take

Coca-Cola's line that the incident is "not reasonably likely to have a material impact on financial condition" is standard 8-K boilerplate, not real transparency — it tells shareholders what they legally need to hear and tells everyone else nothing. The actually newsworthy part isn't that a beverage giant got hit; it's how fast a ransomware crew got from a dairy subsidiary's network into the systems that make bottles move. That's the story worth watching, not the countdown clock.

Quick answers

Did Coca-Cola pay the ransom?
Coca-Cola hasn't said, and Anubis hasn't confirmed it publicly either. The July 28 statement only confirms that data was taken — it says nothing about whether any payment changed hands.
What data was actually stolen?
Neither Coca-Cola nor fairlife has specified categories as of this writing — no confirmation of employee records, customer data, or manufacturing IP specifically.
Is Fairlife product on shelves safe to buy?
Yes — both Coca-Cola and fairlife have stated explicitly that product quality and safety were not affected by the intrusion.
Who is the Anubis ransomware group?
Anubis is a double-extortion ransomware operation that encrypts victim systems and exfiltrates data before threatening public release on its dark-web leak site — the same playbook used against dozens of manufacturers and healthcare providers this year.

Watch for two things next: a state attorney general notification if any consumer or employee personal data turns out to be in that terabyte, and whichever plaintiffs' firm files first. Neither has happened yet. What has already happened is instructive enough — a legacy beverage brand's dairy arm went from normal Tuesday to four suspended plants and a leak-site countdown inside four days, and the fix wasn't a firewall rule, it was shutting down the thing that makes the product.

Software & Systems Editor

Priya Nair

Priya has daily-driven more Linux distros than she can name and treats her setup like a workshop. She covers the operating systems, apps and settings worth your time — and cheerfully calls out the 'optimizations' that just quietly break your machine.

Work out the hardware

The Aliteq brief

The tech worth knowing — hardware, AI, gaming, deals. No spam, unsubscribe anytime.

Keep reading