Coca-Cola discloses ransomware attack on fairlife production systems, temporarily halts US operations - Industrial Cyber
Industrial CyberArchived Aug 01, 2026✓ Full text saved
Coca-Cola discloses ransomware attack on fairlife production systems, temporarily halts US operations Industrial Cyber
Full text archived locally
✦ AI Summary· Claude Sonnet
Attacks And Vulnerabilities
Control Device Security
Critical Infrastructure
Industrial Cyber Attacks
IT/OT Collaboration
Malware, Phishing & Ransomware
Manufacturing
News
Product Security
Risk & Compliance
SBOM
Secure Remote Access
Secure-By-Design
Supply Chain Security
Technology & Solutions
Threat Landscape
Vulnerabilities
Coca-Cola discloses ransomware attack on fairlife production systems, temporarily halts US operations
JULY 17, 2026
The Coca-Cola Company disclosed Thursday that its dairy subsidiary, fairlife, identified unauthorized third-party access to a portion of its systems, including production-related systems, in connection with a ransomware incident. The Chicago-based unit said it activated its incident response and business continuity protocols, engaged outside cybersecurity experts, and notified law enforcement. While product quality and safety were not affected, the fairlife subsidiary has temporarily suspended production operations in the U.S., though its Canadian production facilities remain operational.
Coca-Cola said in a Form 8-K filing that it is continuing to investigate the incident and restore affected systems, adding that it has not yet determined whether the attack is reasonably likely to have a material impact on the company.
“On July 16, 2026, The Coca-Cola Company (the “Company”) announced that fairlife, LLC (“fairlife”), a dairy company owned by the Company, identified unauthorized access by a third party to a portion of its systems, including its production-related systems, in connection with a ransomware event,” Monica Howard Douglas, the company’s executive vice president and global general counsel, wrote in the filing. “After detecting the issue, the Company promptly activated its incident response and business continuity protocols. The Company’s investigation and assessment of the impact of the incident is ongoing, with the assistance of outside advisors and cybersecurity experts. The Company has also notified law enforcement.”
Douglas noted that product quality and safety have not been impacted. “However, as a result of the incident, production operations at fairlife in the United States are temporarily suspended. fairlife’s Canada production operations are not currently impacted.”
She mentioned that the company is working diligently to complete the investigation and restore the systems and impacted operations. “The full scope, nature and impacts of the incident are not yet known. Accordingly, the Company has not yet determined whether the incident is reasonably likely to materially affect the Company.”
As of Friday, Coca-Cola has not disclosed whether any data was stolen, whether the attackers have made extortion demands, or which ransomware group was behind the incident. Moreover, no ransomware operation has publicly claimed responsibility.
The Coca-Cola disclosure comes as Japanese food and cold chain logistics company Nichirei Corp. confirmed that a cyberattack caused system failures that disrupted operations across its group beginning July 13, saying investigators determined that company servers had been compromised. The company said it established an emergency response headquarters immediately after the incident and disconnected group systems to protect customer and business partner data while the investigation continued.
In March, the Food and Ag-ISAC warned that the food and agriculture sector faces sustained and increasingly sophisticated cyber pressure, with 72 active threat actors identified over 330 monitored adversaries. The analysis, powered by the Predictive Adversary Scoring System (PASS), highlights that both nation-state groups and financially motivated cybercriminals are consistently targeting the farm-to-table supply chain, using a mix of persistence, technical sophistication, and clear strategic intent to exploit sector vulnerabilities.
Anna Ribeiro
Industrial Cyber News Editor. Anna Ribeiro is a freelance journalist with over 14 years of experience in the areas of security, data storage, virtualization and IoT.
Related
Foreign robotic systems could expose US critical infrastructure to cyberattacks, espionage, remote manipulation
CISA, federal agencies, international partners refresh SBOM guidance with new data fields to boost software supply chain security
Team Cymru launches Pure Signal Command to accelerate AI-driven threat intelligence and incident response
NetRise Provenance strengthens software supply chain security with developer workflow enforcement
Minnesota water cyberattacks prompt CISA warning on growing threats targeting internet-exposed PLCs
Cyberattacks target water utilities in Minnesota, disrupting OT operations and triggering multi-agency cyber response
Claroty’s Team82 reveals widespread CPS exposures across data center infrastructure, calls for zero trust measures
New CI Fortify guidance helps operators protect vital OT systems, maintain essential services during cyberattacks
Wyden urges federal agencies to replace legacy VPNs with zero trust architectures to counter nation-state cyber threats
Cyware and Armis partner to deliver asset-centric threat intelligence with real-time asset visibility and agentic AI