Anubis Ransomware Targets Coca-Cola's Fairlife Brand
The Anubis ransomware gang has publicly claimed responsibility for a cyberattack on Fairlife, Coca-Cola's premium dairy and nutrition subsidiary. The group is threatening to leak allegedly stolen corporate data if its ransom demand goes unmet — a double-extortion tactic that has become standard in modern ransomware operations.
What Happened
The Anubis group posted Fairlife on its dark web leak site, asserting it had exfiltrated sensitive corporate data during the breach. The gang has set a payment deadline and claims it will publish the stolen files if Coca-Cola does not comply.
Fairlife is a major consumer brand under Coca-Cola's portfolio, known for its high-protein milk products and nutrition shakes. Its operations include large-scale dairy processing facilities across the United States.
Who Is Anubis?
Anubis (not to be confused with the older Android banking trojan of the same name) is a ransomware-as-a-service (RaaS) operation that emerged as a significant threat actor in 2025. Key characteristics:
| Attribute | Detail |
|---|---|
| Model | Ransomware-as-a-Service (RaaS) |
| Tactics | Double extortion (encrypt + exfiltrate) |
| Leak Site | Active dark web data leak portal |
| Target Profile | Enterprise and mid-market organizations across sectors |
| Notable TTPs | Phishing initial access, lateral movement via living-off-the-land binaries |
Anubis has claimed attacks on organizations in manufacturing, healthcare, and food production — sectors with operational technology (OT) environments that are particularly sensitive to downtime.
Double Extortion: The Modern Ransomware Playbook
Modern ransomware gangs rarely rely on encryption alone. The double-extortion model works as follows:
1. Initial access (phishing, credential theft, VPN exploit)
2. Lateral movement across corporate network
3. Data exfiltration — sensitive files copied to attacker-controlled servers
4. Ransomware deployment — files encrypted across endpoints and servers
5. Ransom demand — payment demanded for decryption key AND deletion of stolen data
6. Leak threat — if unpaid, data published on dark web leak site
For food and beverage companies like Fairlife, stolen data may include:
- Trade secrets — proprietary formulations, manufacturing processes
- Supply chain data — supplier contracts, logistics details
- Employee PII — HR records, payroll, health data
- Financial data — pricing, margins, acquisition targets
- Customer data — B2B contracts, distribution agreements
Fairlife Background
Fairlife was founded in 2012 as a joint venture with Select Milk Producers and acquired by Coca-Cola in 2020 for approximately $980 million. The brand processes over 1 billion pounds of milk annually and operates major facilities in Arizona, New York, and New Jersey.
In 2020, Fairlife faced a separate animal welfare controversy that drew significant public attention — demonstrating the company's sensitivity to brand reputation damage, which ransomware groups often factor into their leverage calculus.
Industry Context: Food & Beverage Under Attack
The food and beverage sector has emerged as a high-value ransomware target:
- JBS Foods (2021) — REvil ransomware forced shutdown of beef processing plants across the US, Canada, and Australia. JBS paid an $11M ransom.
- Dole Food (2023) — Ransomware disrupted North American operations.
- Sysco (2023) — Data breach exposed employee and customer information.
- Mondelez (2017) — NotPetya attack caused $100M+ in damages.
Food companies are attractive targets because operational disruptions can have immediate supply chain consequences, increasing pressure to pay.
What Fairlife and Coca-Cola Have Not Confirmed
As of publication, neither Coca-Cola nor Fairlife has publicly confirmed or denied the attack. This silence is typical in the early stages of ransomware incidents, as organizations assess the scope of the breach, consult legal counsel, and engage law enforcement before making public statements.
Protective Measures for Organizations
- Implement MFA everywhere — credential theft is the most common ransomware initial access vector
- Segment OT/IT networks — prevent ransomware spread from corporate IT to operational technology
- Maintain offline backups — the 3-2-1-1 rule (3 copies, 2 media types, 1 offsite, 1 offline)
- Deploy EDR with ransomware rollback — solutions like CrowdStrike, SentinelOne, or Microsoft Defender for Endpoint
- Test incident response plans — tabletop exercises before an incident, not after
- Monitor dark web leak sites — services like Recorded Future or Flare can alert when your organization appears on leak sites
What to Watch
- Whether Coca-Cola/Fairlife confirms the breach and discloses the scope
- Whether proof-of-data is published by Anubis to increase pressure
- Regulatory notifications under US state breach laws and potentially GDPR (if EU employee/customer data is involved)
- Law enforcement action — FBI and CISA actively track RaaS operations
BleepingComputer first reported Anubis's claim. CosmicBytez Labs will update this article as the situation develops.