Anubis Ransomware Group Claims Fairlife Attack, Threatens to Leak 1 TB of Data
Coca-Cola's milk brand has a week to pay an undisclosed ransom, or criminals say they will publish what they took.

Key points
- Coca-Cola confirmed production at its Fairlife dairy subsidiary was suspended following a ransomware attack, disclosed in the week of 14 July 2025.
- The Anubis ransomware group listed Coca-Cola and Fairlife on its public extortion site on 20 July 2025.
- Anubis claims to have encrypted Fairlife's servers and stolen 1 TB (terabyte) of confidential data.
- Coca-Cola has been given one week to pay a ransom before the stolen data is published online.
- Anubis has been active since December 2024 and has listed roughly 100 target organisations on its site.
A criminal group called Anubis has claimed responsibility for a ransomware attack, where malicious software locks a company's files until a payment is made, on Fairlife, the dairy brand owned by Coca-Cola. Fairlife makes protein shakes, ultra-filtered milk, and other products sold widely across North America.
Coca-Cola confirmed last week that production at Fairlife had been suspended. The company said it was still assessing the full scale of the damage.
On 20 July 2025, Anubis published Coca-Cola and Fairlife's names on its leak site, which is a website criminals use to pressure victims by threatening to publish stolen files publicly. The group claims to have encrypted the company's servers and removed 1 TB of confidential data. That is roughly equivalent to 250,000 photographs, to give a sense of scale.
What does this mean for ordinary people?
Right now, Fairlife has not confirmed that customer or employee personal information was taken. That could change as the investigation continues. The stolen 1 TB described by Anubis could contain anything from internal business documents to customer records, though no specific personal data categories have been confirmed publicly.
Anubis operates what is known as a double-extortion model. First, it encrypts the victim's files so the business cannot function. Second, it copies those files and threatens to release them. This gives criminals two ways to press for payment: restore our systems, or we publish your data.
The group, active since December 2024, has a further capability that drew attention from security researchers: a "wiper mode" that can permanently delete a victim's files rather than simply encrypt them, making recovery impossible even if backups exist.
Anubis told Coca-Cola it could have systems restored within hours if a ransom is paid. The deadline, based on the 20 July listing, gives the company roughly one week. Coca-Cola had not responded publicly to requests for comment at the time of writing, as first noted by SecurityWeek.
What Fairlife customers and employees should do now:
Check your email for any breach notification letter from Fairlife or Coca-Cola. If one arrives, follow the specific steps it describes. Watch your bank statements and any accounts where you use the same password as a Fairlife account. Change that password and turn on two-step verification, where a text message or app code is required alongside your password, on any account that offers it. If no notification arrives and the company confirms no personal data was taken, no further action is needed.



