Ransomware Attack Halts Fairlife (Coca-Cola Subsidiary) US Dairy Production Operations — Threadlinqs Intelligence
As of 2026-07-17, Ransomware Attack Halts Fairlife (Coca-Cola Subsidiary) US Dairy Production Operations is a high-severity ransomware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 17 indicators of compromise.
Threat ID: TL-2026-1456 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
On 2026-07-16, The Coca-Cola Company disclosed via SEC Form 8-K that its dairy subsidiary fairlife, LLC suffered unauthorized third-party access to portions of its systems, including
The Coca-Cola Company filed a Form 8-K on July 16, 2026 disclosing that fairlife, LLC — its ultra-filtered dairy brand behind Core Power protein shakes and Nutrition Plan products, with roughly $4B in annual revenue — identified unauthorized access by a third party to a portion of its systems, including production-related systems, in connection with a ransomware event. As a direct result, fairlife's US production operations were temporarily suspended; Canadian production was not impacted, consistent with either network segmentation between the two operating regions or a geographically bounded blast radius. Coca-Cola activated its incident response and business continuity protocols, engaged outside cybersecurity advisors, and notified law enforcement. Company statements to BleepingComputer confirmed the investigation is being conducted 'with the assistance of outside advisors and cybersecurity experts' and that when directly asked about data theft, extortion demands, or attacker identity, the company 'had nothing additional to share beyond its public statement.' The company stated that product quality and safety have not been compromised, but as of disclosure had not determined the full scope, nature, or impact of the incident, nor whether it is reasonably likely to be material to the Company under SEC materiality rules. No ransomware group had publicly claimed responsibility (checked against known leak-site trackers and dark-web monitoring accounts) at time of research, the specific ransomware strain/family is unidentified, no CVE or initial-access vector has been disclosed, and it remains unknown whether data was exfiltrated or an extortion demand was received. Industry commentary (BleepingComputer) notes that if data was in fact stolen, the attackers will likely attempt double-extortion by threatening to publish it unless a ransom has already been paid — a now-standard RaaS-affiliate playbook. The incident fits a recurring pattern of ransomware operators targeting food and beverage manufacturers for maximum operational leverage — comparable prior incidents include JBS Foods (May-June 2021, REvil/Sodinokibi ransomware; beef and pork slaughterhouse production halted across the US, Canada, and Australia after a ~3-month dwell time beginning with February 2021 reconnaissance, credential-based initial access via reused passwords and compromised TeamViewer remote-access accounts, RDP/VPN weaknesses for lateral movement, exfiltration from March-May 2021, and encryption triggered June 1, 2021 — later ATT&CK-for-ICS analysis mapped 22 unique techniques across 21 steps and 361 observables), Clorox (August 2021, manufacturing and supply disruption causing weeks of product shortages), Schreiber Foods (October 2021, dairy processor ransomware forcing multi-plant shutdown), Arizona Beverages (March 2019, Sodinokibi/iiRansomware-linked incident causing a multi-week production shutdown), and UNFI/United Natural Foods (June 2025, grocery distribution disruption and shortages). Sector telemetry corroborates the pattern: ransomware attacks against industrial organizations rose roughly 87% over a two-year period with manufacturing the most-targeted sector for three consecutive years, and food-and-beverage-sector attacks more than doubled between Q1 2024 and Q1 2025 (per RSM/Dragos industry reporting), reflecting attacker awareness that IT/OT convergence in manufacturing environments — production lines, warehouse automation, and environmental controls increasingly bridged to enterprise IT — allows an IT-side compromise to directly force production stoppage without requiring specialized industrial-control expertise. Common initial-access pathways documented across this incident class include credential theft/reuse, phishing and social engineering, exploitation of internet-facing/unpatched legacy systems, poorly secured remote-access services (exposed RDP, VPN), access purchased from initial-access brokers, and third-party/vendor supply-chain conn
Target sectors: food and beverage manufacturing, dairy processing, consumer packaged goods, critical infrastructure - food and agriculture
Target regions: North America, united states of america
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 17 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1589, T1650, T1078, T1566, T1133, T1190, T1204, T1136, T1552, T1003