Ransomware attack on its dairy arm Fairlife was reported in late March, Coca-Cola has admitted it suffered an actual data breach, not a production halt.
The company revealed the cybersecurity incident on July 16. It then said it had stopped making products at Fairlife plants in the US after it was made aware of the intrusion, and was investigating the incident and responding it.
Coca-Cola followed up on Tuesday with a statement confirming that the incident was “the taking of certain data. The company has not disclosed additional details of the information that was accessed.
At the four impacted Fairlife facilities in the US, a majority of production has restarted. During the incident, Fairlife Canada operations were not affected at any time.
The hackers exploited Fairlife IT environment, according to earlier filing Coca-Cola made with the US Securities and Exchange Commission (SEC). The production units systems were among those impacted.
Anubis ransomware group has claimed responsibility for the attack. It had listed Coca-Cola and Fairlife on its own dark web leak site 20 days after the leak was first reported.
According to Anubis, it “locked” Fairlife servers, which presumably involved encrypting files, and claimed to have exfiltrated 1 terabyte of confidential information. The group released a copy of the alleged stolen files to substantiate its allegations.
According to the hackers, they could get the systems restored to Coca-Cola within hours if a ransom was paid. The public was not told of any specific ransom amount, but the group gave the deadline for payment as Monday, July 27.
Upon finding out about the breach, Coca-Cola notified the relevant authorities. It has said it did not comply with the attackers demands to agree.
Since that time, the deadline has expired. The countdown timer Anubis set for publicizing the leaked information has ended, so the data is apparently available for download on the group leak site, Bleeping Computer reports.
Coca-Cola has always said that the incident did not compromise product quality and safety. The company has stated that it had filled in any shortfalls in production due to the hiatus with existing stock.
Fairlife is one of the fastest growing brands for Coca-Cola, and boasts products such as ultra-filtered milk, protein shakes as Core Power, and its Nutrition Plan product line. The brand is expected to have about $4 billion in annual sales, one of the biggest non-carbonated business lines of Coca-Cola.
Anubis is a ransomware-as-a-service (RaaS) operation from December 2024. It has since enlisted approximately 100 organizations around the world on its leak site, across a variety of industries.
The group has a characteristic that distinguishes it from numerous other similar ransomware operations: a “wiper mode” that can permanently wipe a victim files out, making them unrecoverable even if they pay ransom.
Coca-Cola claimed its investigation is ongoing, with a third party advising and cybersecurity experts helping it with the probe. The company so far has not revealed the full extent of the data that was stolen, nor said whether customer data was included, but it has stressed that it does not have the ability to identify which customers data was accessed.
