Ransomware Attack on Coca-Cola's Fairlife Dairy Subsidiary Halts US Production — Threadlinqs Intelligence
As of 2026-07-16, Ransomware Attack on Coca-Cola's Fairlife Dairy Subsidiary Halts US Production is a high-severity ransomware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-1427 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Coca-Cola disclosed via SEC Form 8-K that its fairlife, LLC dairy subsidiary detected unauthorized third-party access to a portion of its systems, including production-related systems, in connection
On July 16, 2026, The Coca-Cola Company filed a Form 8-K (Item 8.01, Other Events) with the U.S. Securities and Exchange Commission disclosing that its wholly owned dairy subsidiary fairlife, LLC identified unauthorized access by a third party to a portion of its systems, including production-related systems, in connection with a ransomware event. As a direct consequence, production operations at fairlife's United States manufacturing facilities were temporarily suspended; fairlife's Canadian production operations were confirmed unaffected and continued to operate normally. fairlife's affected US product lines include Ultra-Filtered Milk, Core Power Protein Shakes, and Nutrition Plan. Coca-Cola stated that upon detection it 'promptly activated its incident response and business continuity protocols' and that its 'investigation and assessment of the impact of the incident is ongoing, with the assistance of outside advisors and cybersecurity experts.' The Company 'has also notified law enforcement.' The company affirmed that product quality and safety have not been impacted by the intrusion. As of disclosure (reported by BleepingComputer at 05:09 PM ET on July 16, 2026), no ransomware group had publicly claimed responsibility, no ransom demand or amount had been disclosed, and Coca-Cola had not determined whether data was accessed or exfiltrated during the intrusion, nor whether the incident will materially affect the company financially or operationally. The unauthorized access to fairlife's production-related (OT-adjacent) systems and the resulting suspension of manufacturing is consistent with the industry-wide pattern in which ransomware operators disrupt or lock IT systems that dairy/food manufacturers rely on to safely run production lines, forcing precautionary shutdowns even absent direct OT/ICS compromise, to contain lateral spread and protect product safety and integrity. This pattern has repeated across the sector: Schreiber Foods was forced to halt dairy production in a November 2021 ransomware attack; Dairy Farmers of America confirmed a June 2025 cyberattack (later found to have leaked personal data) that was publicly claimed by the Play ransomware gang on June 23, 2025. The Food and Agriculture ISAC's 2025 sector landscape report records 265 ransomware attacks against the food and agriculture sector in 2025 (4.2% of all tracked ransomware incidents, amid an 82% year-over-year rise in overall ransomware incidents, from 3,508 in 2024 to 6,377 in 2025), identifying Qilin, Akira, CL0P, Play, and Lynx as the five dominant groups targeting the sector — alongside RansomHub and LockBit, both separately documented by CISA #StopRansomware advisories as having struck food and agriculture victims. On June 4, 2025, the FBI, CISA, and the Australian Signals Directorate's ACSC jointly updated the Play ransomware advisory (originally AA23-352A) with new TTPs and refreshed IOCs, noting the FBI had identified roughly 900 entities allegedly victimized by Play as of May 2025 using a double-extortion model (encrypt-and-exfiltrate, with victims instructed to contact the actors via email rather than through a fixed ransom note demand). If data was in fact stolen during the fairlife intrusion, actors would likely attempt double-extortion by threatening to publish the data unless a ransom is paid — a pattern consistent with groups such as Play, RansomHub, LockBit, Qilin, Akira, CL0P, and Lynx that have targeted the food and agriculture sector, in some cases (CL0P) via mass zero-day exploitation of file-transfer platforms such as GoAnywhere MFT (e.g., CVE-2025-10035) rather than traditional phishing.
Target sectors: food and beverage, food and agriculture, manufacturing, dairy processing, consumer goods
Target regions: united states of america, North America
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1590, T1588.001, T1566, T1190, T1133, T1078, T1059.001, T1136, T1078.002, T1562.001