Ransomware Attack on Coca-Cola's Fairlife Dairy Subsidiary Halts US Production

Ransomware Attack on Coca-Cola's Fairlife Dairy Subsidiary (TL-2026-1427) is a high-severity ransomware operation, first published 2026-07-16. It has no confirmed attribution, affects fairlife, LLC (The Coca-Cola Company subsidiary) US dairy production, maps to 21 MITRE ATT&CK techniques (T1003, T1005, T1016), and is covered by 9 detection rules and 18 indicators of compromise.

Key facts for TL-2026-1427

Threat ID
TL-2026-1427
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
2026-07-16
Last reviewed
2026-07-16
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
food and beverage, food and agriculture, manufacturing, dairy processing, consumer goods
Target regions
united states of america, North America
Detection rules
9
Indicators of compromise
18

Malware and tooling in Ransomware Attack on Coca-Cola's Fairlife Dairy Subsidiary

Malware and tooling: Akira ransomware, CL0P ransomware, LockBit ransomware, Lynx ransomware, Play ransomware, Qilin ransomware, RansomHub ransomware-as-a-service

Coca-Cola disclosed via SEC Form 8-K that its fairlife, LLC dairy subsidiary detected unauthorized third-party access to a portion of its systems, including production-related systems, in connection with a ransomware event, temporarily suspending U.S. dairy production while Canadian operations continued unaffected.

How Ransomware Attack on Coca-Cola's Fairlife Dairy Subsidiary works

On July 16, 2026, The Coca-Cola Company filed a Form 8-K (Item 8.01, Other Events) with the U.S. Securities and Exchange Commission disclosing that its wholly owned dairy subsidiary fairlife, LLC identified unauthorized access by a third party to a portion of its systems, including production-related systems, in connection with a ransomware event. As a direct consequence, production operations at fairlife's United States manufacturing facilities were temporarily suspended; fairlife's Canadian production operations were confirmed unaffected and continued to operate normally. fairlife's affected US product lines include Ultra-Filtered Milk, Core Power Protein Shakes, and Nutrition Plan. Coca-Cola stated that upon detection it 'promptly activated its incident response and business continuity protocols' and that its 'investigation and assessment of the impact of the incident is ongoing, with the assistance of outside advisors and cybersecurity experts.' The Company 'has also notified law enforcement.' The company affirmed that product quality and safety have not been impacted by the intrusion. As of disclosure (reported by BleepingComputer at 05:09 PM ET on July 16, 2026), no ransomware group had publicly claimed responsibility, no ransom demand or amount had been disclosed, and Coca-Cola had not determined whether data was accessed or exfiltrated during the intrusion, nor whether the incident will materially affect the company financially or operationally. The unauthorized access to fairlife's production-related (OT-adjacent) systems and the resulting suspension of manufacturing is consistent with the industry-wide pattern in which ransomware operators disrupt or lock IT systems that dairy/food manufacturers rely on to safely run production lines, forcing precautionary shutdowns even absent direct OT/ICS compromise, to contain lateral spread and protect product safety and integrity. This pattern has repeated across the sector: Schreiber Foods was forced to halt dairy production in a November 2021 ransomware attack; Dairy Farmers of America confirmed a June 2025 cyberattack (later found to have leaked personal data) that was publicly claimed by the Play ransomware gang on June 23, 2025. The Food and Agriculture ISAC's 2025 sector landscape report records 265 ransomware attacks against the food and agriculture sector in 2025 (4.2% of all tracked ransomware incidents, amid an 82% year-over-year rise in overall ransomware incidents, from 3,508 in 2024 to 6,377 in 2025), identifying Qilin, Akira, CL0P, Play, and Lynx as the five dominant groups targeting the sector — alongside RansomHub and LockBit, both separately documented by CISA #StopRansomware advisories as having struck food and agriculture victims. On June 4, 2025, the FBI, CISA, and the Australian Signals Directorate's ACSC jointly updated the Play ransomware advisory (originally AA23-352A) with new TTPs and refreshed IOCs, noting the FBI had identified roughly 900 entities allegedly victimized by Play as of May 2025 using a double-extortion model (encrypt-and-exfiltrate, with victims instructed to contact the actors via email rather than through a fixed ransom note demand). If data was in fact stolen during the fairlife intrusion, actors would likely attempt double-extortion by threatening to publish the data unless a ransom is paid — a pattern consistent with groups such as Play, RansomHub, LockBit, Qilin, Akira, CL0P, and Lynx that have targeted the food and agriculture sector, in some cases (CL0P) via mass zero-day exploitation of file-transfer platforms such as GoAnywhere MFT (e.g., CVE-2025-10035) rather than traditional phishing.

MITRE ATT&CK techniques used in TL-2026-1427

Credential Access

T1003 OS Credential Dumping

Collection

T1005 Data from Local System

Discovery

T1016 System Network Configuration Discovery; T1046 Network Service Discovery

Lateral Movement

T1021.001 Remote Desktop Protocol

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059.001 PowerShell

Defense Evasion

T1070 Indicator Removal

Command and Control

T1071 Application Layer Protocol

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1566 Phishing

Privilege Escalation

T1078.002 Domain Accounts

Persistence

T1136 Create Account

Impact

T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery

Resource Development

T1588.001 Malware

Reconnaissance

T1590 Gather Victim Network Information

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Ransomware Attack on Coca-Cola's Fairlife Dairy Subsidiary

  • fairlife, LLC (The Coca-Cola Company subsidiary) — US dairy production and manufacturing systems (Ultra-Filtered Milk, Core Power Protein Shakes, Nutrition Plan lines)
    Vulnerable versions: production-related systems at US facilities

Remediation for Ransomware Attack on Coca-Cola's Fairlife Dairy Subsidiary

Immediate actions

  • Isolate and segment production-related/OT-adjacent systems from corporate IT to contain lateral movement
  • Engage third-party incident response and forensics to determine initial access vector and scope of access
  • Notify law enforcement (FBI/CISA) and preserve logs and forensic artifacts before remediation
  • Reset credentials and rotate secrets for accounts with access to production and manufacturing execution systems
  • Validate integrity of production/manufacturing execution systems before resuming operations
  • Assess and disclose whether data was exfiltrated to determine breach notification obligations
  • Patch and inventory internet-facing managed file transfer (MFT) platforms (e.g., GoAnywhere MFT) given active CL0P mass-exploitation of such systems sector-wide

Workarounds

  • Temporary manual/paper-based production and quality-control processes at affected US facilities pending system restoration
  • Route affected US production volume through unaffected Canadian facilities where feasible

Longer-term hardening

  • Deploy EDR/XDR with behavioral detection across corporate and OT-adjacent environments
  • Implement network segmentation (IT/OT boundary) per ISA/IEC 62443 to limit ransomware spread into manufacturing environments
  • Enforce MFA on all remote access (RDP, VPN, Citrix) and disable unused external-facing remote services
  • Establish and test immutable, offline backups for both IT and production-support systems
  • Adopt CISA #StopRansomware Guide controls (asset inventory, patch management, account lockout, application allowlisting)
  • Join and actively participate in the Food and Ag-ISAC for sector threat intelligence sharing
  • Track FBI/CISA updated IOC releases (e.g., the June 2025 Play ransomware advisory refresh) to keep detection content current against evolving affiliate TTPs

Timeline of Ransomware Attack on Coca-Cola's Fairlife Dairy Subsidiary

  • Schreiber Foods, a major dairy producer, is forced to halt production at multiple US plants following a ransomware attack — an early sector precedent for ransomware-driven dairy manufacturing shutdowns.
  • The FBI, CISA, and the Australian Signals Directorate's ACSC jointly update the Play ransomware #StopRansomware advisory with new TTPs and refreshed IOCs, noting roughly 900 entities allegedly victimized by Play as of May 2025.
  • The Play ransomware gang publicly claims responsibility for a cyberattack on Dairy Farmers of America.
  • Dairy Farmers of America confirms its June 2025 cyberattack resulted in leaked personal data.
  • BleepingComputer reports on the SEC filing at 05:09 PM ET, noting no group has claimed responsibility and no ransom demand or data theft has been confirmed.
  • The Coca-Cola Company files a Form 8-K (Item 8.01, Other Events) with the SEC disclosing the fairlife ransomware event.
  • Coca-Cola confirms product quality and safety have not been affected by the incident.
  • Coca-Cola notifies law enforcement of the incident.
  • Production operations at fairlife's United States manufacturing facilities (Ultra-Filtered Milk, Core Power Protein Shakes, Nutrition Plan lines) are temporarily suspended as a precautionary/containment measure; Canadian production operations remain unaffected.
  • Coca-Cola activates its incident response and business continuity protocols and engages outside advisors and third-party cybersecurity experts to investigate scope and impact.
  • fairlife, LLC identifies unauthorized third-party access to a portion of its systems, including production-related systems, in connection with a ransomware event.

Sources cited for Ransomware Attack on Coca-Cola's Fairlife Dairy Subsidiary

Threats related to Ransomware Attack on Coca-Cola's Fairlife Dairy Subsidiary

Detection coverage for TL-2026-1427

As of 2026-07-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1427 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats