← BACK TO FEED
ransomwareCoca-ColaFairlifeOT securitycybersecurity

Ransomware Knocks Fairlife's US Dairy Plants Offline

Coca-Cola's dairy subsidiary Fairlife has been hit by a ransomware attack that forced a temporary halt to production at its US plants, while its Canadian facilities remain operational. The attack compromised a portion of Fairlife's systems, including production-related systems, prompting the company to activate its incident response plan, engage cybersecurity experts, and notify law enforcement. Key details remain unclear, including who carried out the attack, whether data was stolen, and when US production is expected to resume.

Coca-Cola's Fairlife subsidiary has become the latest corporate casualty of a ransomware attack, with production at its US facilities ground to a halt while the company figures out the damage.

A Thursday SEC filing confirmed that Fairlife detected unauthorised access to part of its systems, including those tied directly to production. Coca-Cola described it as a ransomware event, said it activated incident response and business continuity plans, called in outside cybersecurity help, and looped in law enforcement. The usual playbook.

Canadian operations are reportedly continuing normally. Fairlife, which Coca-Cola fully absorbed in 2020 and which produces ultra-filtered milk and Core Power protein shakes, has stressed that product quality and safety are unaffected. Cold comfort if the shelves run dry.

What the filing doesn't tell us is quite a lot. There's no clarity on whether the ransomware burrowed into operational technology controlling the physical manufacturing lines, or whether production was suspended as a precautionary measure after supporting IT systems were pulled offline. That distinction matters enormously. OT compromises are significantly harder to recover from and carry real safety implications. IT outages, while disruptive, are a different category of problem.

Coca-Cola hasn't named any suspects, and no ransomware group had publicly claimed responsibility at the time of writing. That's not unusual. Gangs frequently hold off on publishing claims while ransom negotiations are underway, only going public when talks collapse or they want to apply extra pressure.

How many facilities are actually affected, whether any employee or customer data was lifted, and when US production might resume all remain unanswered. The company didn't respond to press queries before publication.

The full scope of financial impact is also unclear. Coca-Cola's filing notes it hasn't yet determined whether the incident is likely to materially affect the company. Given Fairlife's rapid growth and premium positioning, even a brief production stoppage could be meaningful.

READ NEXT
Ransomware Knocks Out Fairlife Milk Production Across the USGrafana Labs Got Its GitHub Raided. It's Not Paying Up.This Cybersecurity Index Tracks Real Breaches and Refuses to Invent a Grand Total