Anubis Ransomware Gang Claims Fairlife Hit, Gives Coca-Cola One Week to Pay
The Anubis ransomware group has claimed responsibility for the attack on Fairlife, Coca-Cola's dairy subsidiary, and is threatening to dump stolen data publicly if a ransom isn't paid.
Coca-Cola disclosed last week that production at Fairlife had been knocked offline following a ransomware attack. At the time, the company said it was still working out the full extent of the damage.
On July 20, Anubis listed both Coca-Cola and Fairlife on its extortion site, claiming to have encrypted servers and walked off with 1 TB of confidential data. The group says it can have systems back up within hours, provided Coca-Cola writes a cheque. The deadline is one week. After that, the data goes public.
Coca-Cola hasn't commented publicly. SecurityWeek said it reached out but had received no response at time of publication.
Anubis has been operating since December 2024 and has racked up around 100 claimed victims in that time. It runs the standard double-extortion playbook: encrypt the files, steal the data, then use both as leverage. Pay up or lose everything twice over.
What set Anubis apart when it first surfaced was a so-called wiper mode, a feature designed to permanently destroy victim data rather than just encrypt it. That's not a negotiating tool, that's a threat to simply obliterate files beyond any possibility of recovery. It got attention in the security community for obvious reasons.
Whether Coca-Cola decides to negotiate or call the bluff remains to be seen.