← All news

ransomware

Ransomware Halts Fairlife's US Milk Production

2026-07-17

Coca-Cola told the SEC this week that its Fairlife dairy subsidiary has been hit by ransomware, and production at Fairlife's US facilities is paused while the company works through the fallout. Canadian operations are unaffected, and Coca-Cola says product quality and safety are not in question.

The disclosure came via an 8-K filing. Fairlife spotted unauthorised access to some of its systems, including production-related ones, and activated its incident response and business continuity plans. Outside advisors are in, law enforcement has been notified, and the investigation is ongoing.

What's not being said

What Coca-Cola has not confirmed is arguably more interesting than what it has. There is no word on whether data was stolen. No mention of an extortion demand. No named threat actor. No ransomware group has publicly claimed the attack.

That silence is normal in the early days of an incident, and it often breaks a few weeks later, when stolen files start appearing on a leak site and the negotiation gets aired in public. Whether that happens here will tell us a lot about how the attackers got in and how far they got.

Milk, protein shakes, and a loading bay problem

Fairlife is not a small piece of the Coca-Cola empire. The brand makes ultra-filtered milk, Core Power protein shakes and Nutrition Plan drinks, all of which come off physical production lines. The disruption is squarely on the operational side rather than the corporate one, which is why the impact reads as paused plants rather than an inconvenienced finance team.

That distinction matters. Ransomware in manufacturing rarely stops at the file server. When production systems share a network with the office, an intrusion on the IT side quickly becomes an empty loading bay on the OT side. The malware doesn't need to understand what a pasteuriser does. It just needs to encrypt the Windows machine that tells the pasteuriser what to do.

Segmentation between corporate IT and operational technology is one of those things every manufacturer knows they should have, and many still don't, at least not properly. The reasons are almost always the same: legacy kit that predates the current network, vendors who need remote access, engineers who want a straight line from their laptop to a controller, and a slow drift over years where the tidy diagram on the wall stops matching reality.

What to watch

  • Attribution. If a group claims the attack on a leak site, that will hint at the initial access vector, phishing, stolen credentials, or an exposed remote service.
  • Data theft. Modern ransomware crews almost always steal data before encrypting. The absence of a claim now does not mean the absence of a leak later.
  • Duration. How long US production stays offline is the real measure of how deeply the attackers reached into the environment, and how well Fairlife's backups and segmentation held up.

Coca-Cola has not given a timeline for restoration. For now, the shelves will thin out where Fairlife's US-produced lines usually sit, and the rest of the industry gets another reminder that a shared network is a shared risk.

Ransomware Halts Fairlife's US Milk Production | RiskSense