Coca-Cola confirms data theft in Fairlife ransomware attack

2 hours ago 5

Coca-Cola confirms data theft in Fairlife ransomware attack

The Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month.

In a short statement earlier today, the global beverages giant says that it is still working to restore some of the impacted systems and operations, but most of the production in the U.S. has been resumed.

Coca-Cola disclosed the cyberattack in a filing with the U.S. Securities and Exchange Commission (SEC) on July 16, revealing that a ransomware attack had disrupted production operations at Fairlife.

image

Fairlife is a producer of ultra-filtered milk, protein shakes, and nutritional drinks. It operates four production facilities in the U.S., and has more than $1 billion in annual retail sales.

At the time, BleepingComputer sent a request for comments regarding the attack, but we received no reply.

A few days later, the Anubis ransomware gang claimed the attack and added Fairlife to the list of victims on its extortion site. The hacker group threatened to leak one terabyte of files allegedly stolen from the company, unless Fairlife paid a ransom.

The threat actor told BleepingComputer that they had encrypted the firm’s Nutanix systems, leaving no possibility of recovery.

As soon as Coca-Cola discovered the breach, the company reported the intrusion to the authorities and did not follow the attacker's instructions to negotiate.

BleepingComputer contacted Coca-Cola again to validate the threat actor's allegations, but a spokesperson declined to comment.

“The company previously disclosed that Fairlife experienced a ransomware event,” reads the Coca-Cola statement.

“This event involved access by an unauthorized third party to a portion of the company’s systems and taking of certain data, and a temporary suspension of production operations.”

Regarding Fairlife product availability, Coca-Cola says existing inventory helped cover temporary shortages caused by the production disruption, while product quality and safety were never jeopardized.

The timer that Anubis ransomware had previously set for the public release of the stolen data expired earlier today, and the data is now available for download.

article image

Test every layer before attackers do

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Read Entire Article