Anubis Ransomware Claims Attack on Coca-Cola's Fairlife, Threatens Data Leak
The **Anubis** ransomware group has claimed responsibility for a cyberattack on **Coca-Cola**'s dairy subsidiary, **Fairlife**, alleging the theft of 1 TB of corporate data. The group threatens to publish the stolen information if a ransom is not paid, following a disruption that halted **Fairlife**'s U.S. production facilities.
The **Anubis** ransomware gang has claimed responsibility for the cyberattack on **Coca-Cola**'s **Fairlife** dairy subsidiary, threatening to publish allegedly stolen corporate data unless the company pays a ransom.
**Fairlife** is one of **Coca-Cola**'s dairy brands, producing ultra-filtered milk products, protein shakes, and nutrition drinks sold across the United States.
On July 16, **The Coca-Cola Company** disclosed that a ransomware attack had disrupted **Fairlife**'s operations, forcing the company to suspend production at its U.S. facilities.
The company stated that attackers gained unauthorized access to a portion of **Fairlife**'s systems, including production-related infrastructure. **Coca-Cola** activated its incident response and business continuity plans, confirming that product quality and safety were unaffected and Canadian production continued as normal. At the time, **Coca-Cola** had not disclosed details about data theft, extortion demands, or the responsible ransomware operation.
## Anubis Ransomware Claims Attack
On Monday, the **Anubis** ransomware gang added **Fairlife** to its dark web data leak site, claiming responsibility for the attack and alleging the theft of approximately one terabyte of corporate data. The group warned it would publish the stolen data unless the company enters negotiations by the end of the week.

The ransomware gang claimed it attacked **Fairlife** roughly a week before the company publicly disclosed the incident and encrypted the company's **Nutanix** infrastructure.
"We attacked their systems a week ago. Just a few days later, they immediately reported the incident without attempting to follow the instructions we left on their network," **Anubis** claimed to BleepingComputer.
"We have fully encrypted their Nutanix systems. They have no chance of recovering without our encryption key."
The ransomware gang also claimed to have stolen 1 TB of corporate data during the attack.
BleepingComputer could not independently verify the gang's claims regarding the alleged theft of data, the encryption of **Fairlife**'s systems, or the amount of data purportedly stolen. When contacted about these claims, **Coca-Cola** declined to comment.
**Anubis** is a ransomware-as-a-service (RaaS) operation that emerged in December 2024. It has since targeted organizations worldwide across multiple industries. The operation is known for combining data theft with file encryption, using stolen information as leverage to pressure victims into paying a ransom. Last year, **Anubis** added a data wiper to its arsenal, designed to destroy victim's files beyond recovery.