Anubis Ransomware Claims Coca-Cola Fairlife Attack, Threatens Data Leak
Anubis Ransomware Claims Coca-Cola Fairlife Attack 🚨
The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola’s Fairlife dairy subsidiary, threatening to publish allegedly stolen corporate data unless the company pays a ransom. On July 16, The Coca-Cola Company disclosed that a ransomware attack had disrupted Fairlife’s operations, forcing the company to suspend production at its U.S. facilities. The company stated that attackers gained unauthorized access to a portion of Fairlife’s systems, including production-related systems, prompting it to activate its incident response and business continuity plans. Coca-Cola also assured that product quality and safety were not affected and that Canadian production operations continued as normal.
On Monday, the Anubis ransomware gang added Fairlife to its dark web data leak site, claiming responsibility for the attack and alleging it stole approximately one terabyte of corporate data. The ransomware gang warned it would publish the stolen data unless the company enters negotiations by the end of the week. Anubis claimed to BleepingComputer: “We attacked their systems a week ago. Just a few days later, they immediately reported the incident without attempting to follow the instructions we left on their network.” The gang further stated, “We have fully encrypted their Nutanix systems. They have no chance of recovering without our encryption key.”
Anubis is a ransomware-as-a-service (RaaS) operation that emerged in December 2024 and has since targeted organizations worldwide across multiple industries. The operation is known for combining data theft with file encryption and using stolen information as leverage to pressure victims into paying a ransom. Last year, Anubis added a data wiper to its arsenal that destroys the victim’s files to make recovery impossible.