Ransomware Knocks Out Fairlife Milk Production Across the US
Coca-Cola has disclosed a ransomware attack on its dairy subsidiary Fairlife, forcing a full suspension of US production operations. The company filed the disclosure with the Securities and Exchange Commission on July 16.
Fairlife, headquartered in Chicago, produces ultra-filtered milk across five varieties and is wholly owned by Coca-Cola. Canadian operations are reportedly unaffected, which is presumably some comfort.
According to the SEC filing, attackers accessed portions of Fairlife's systems, including production infrastructure. Coca-Cola says it activated incident response protocols promptly after detection, brought in outside cybersecurity advisors, and has notified law enforcement. The investigation is ongoing.
The company is at pains to stress that product quality and safety are unaffected. What is affected, clearly, is their ability to actually make the product.
Coca-Cola has not disclosed how the attackers got in, who they are, or whether any ransom demand has been made. No known ransomware group has publicly claimed responsibility at the time of writing.
The full scope and material financial impact remain undetermined. Given that Fairlife has become a significant growth brand for Coca-Cola in recent years, a prolonged outage would be uncomfortable at minimum.
We will update if anything substantive emerges.