Executive Summary
In July 2026, Coca-Cola's subsidiary, Fairlife, experienced a ransomware attack attributed to the Anubis group. The attackers gained unauthorized access to production-related systems, leading to a temporary suspension of U.S. operations. While product quality and safety remained unaffected, the incident disrupted supply chains and highlighted vulnerabilities in critical infrastructure. (techradar.com)
This attack underscores a growing trend of ransomware groups targeting essential industries, emphasizing the need for robust cybersecurity measures and incident response plans to mitigate operational disruptions and protect sensitive data.
Why This Matters Now
The Anubis ransomware attack on Fairlife highlights the escalating threat to critical infrastructure sectors, emphasizing the urgent need for enhanced cybersecurity defenses and proactive incident response strategies to safeguard against operational disruptions and data breaches.
Attack Path Analysis
The Anubis ransomware group gained unauthorized access to Fairlife's production systems, likely through phishing or exploiting vulnerabilities. They escalated privileges to gain deeper access, moved laterally across the network to identify critical systems, established command and control channels, exfiltrated approximately 1 TB of corporate data, and encrypted production-related systems, leading to a temporary suspension of U.S. operations.
Kill Chain Progression
Initial Compromise
Description
The Anubis ransomware group gained unauthorized access to Fairlife's production systems, likely through phishing or exploiting vulnerabilities.
Related CVEs
CVE-2025-5777
CVSS 9.3A vulnerability in Citrix NetScaler allows attackers to bypass multi-factor authentication, leading to unauthorized access.
Affected Products:
Citrix NetScaler – < 12.1.65.21
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Valid Accounts
Data Encrypted for Impact
Data Manipulation: Stored Data Manipulation
Exfiltration Over C2 Channel
Inhibit System Recovery
Application Layer Protocol: Web Protocols
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Protect stored cardholder data
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Encryption of Nonpublic Information
Control ID: 500.15
DORA – ICT Risk Management Framework
Control ID: Article 10
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Food Production
Anubis ransomware targeting Fairlife dairy operations demonstrates critical vulnerability in food manufacturing systems, requiring enhanced segmentation and egress security controls.
Food/Beverages
Coca-Cola Fairlife attack exposes beverage industry risks from ransomware encrypting Nutanix infrastructure and stealing corporate data during production system compromises.
Consumer Goods
Ultra-filtered milk and protein shake production disruption illustrates consumer goods sector exposure to operational technology attacks and supply chain vulnerabilities.
Manufacturing
Production facility encryption and system compromise highlight manufacturing sector needs for zero trust segmentation and anomaly detection across operational environments.
Sources
- Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leakhttps://www.bleepingcomputer.com/news/security/anubis-ransomware-claims-coca-cola-fairlife-attack-threatens-data-leak/Verified
- Coca-Cola shuts down Fairlife dairy production lines following ransomware attackhttps://www.techradar.com/pro/security/coca-cola-shuts-down-fairlife-dairy-production-lines-following-ransomware-attackVerified
- Anubis Ransomware Rides Citrix Bleed 2 Past MFA: 91 Victims and a Playbook Built on Legitimate Toolshttps://breached.company/anubis-ransomware-citrix-bleed-2-91-victims-2026/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Implementing Aviatrix Zero Trust CNSF could have significantly constrained the Anubis ransomware group's ability to escalate privileges, move laterally, and exfiltrate data within Fairlife's cloud environment.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While initial access may still occur, CNSF would likely limit the attacker's ability to exploit this access to further compromise the environment.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation would likely limit the attacker's ability to escalate privileges by enforcing strict access controls based on identity and context.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security would likely limit the attacker's ability to move laterally by enforcing strict controls on internal communications between workloads.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control would likely limit the attacker's ability to establish and maintain command and control channels by providing comprehensive monitoring and control over network traffic.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement would likely limit the attacker's ability to exfiltrate data by enforcing strict controls on outbound traffic.
While initial access may still occur, CNSF would likely limit the attacker's ability to exploit this access to further compromise the environment.
Impact at a Glance
Affected Business Functions
- Production Operations
- Supply Chain Management
- IT Infrastructure
Estimated downtime: 7 days
Estimated loss: $5,000,000
Approximately 1 TB of corporate data, potentially including sensitive business information.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within the network.
- • Enhance East-West Traffic Security to monitor and control internal communications.
- • Deploy Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
- • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities.
- • Establish Threat Detection & Anomaly Response mechanisms to identify and mitigate threats promptly.



