AIO APEX

Coca-Cola halts US production of its $4 billion Fairlife dairy brand after ransomware attack

TechCrunch
Share:
Coca-Cola halts US production of its $4 billion Fairlife dairy brand after ransomware attack

Coca-Cola confirmed on July 16 that its Fairlife dairy subsidiary suspended production at its US facilities after a ransomware attack compromised systems tied to manufacturing operations. The company disclosed the incident in a filing with the Securities and Exchange Commission, stating that an unauthorized third party accessed a portion of Fairlife's systems, including production-related infrastructure, as first reported by TechCrunch.

What happened

Fairlife detected the unauthorized access and activated its incident response and business continuity protocols, according to the company's SEC disclosure. US production operations were temporarily suspended as a direct result, while Fairlife's Canadian operations continue running unaffected. Coca-Cola says product quality and safety have not been compromised, and the company has notified law enforcement while working with outside cybersecurity firms to determine the full scope of the breach.

No ransomware group has publicly claimed responsibility for the attack as of this writing, and Coca-Cola has not disclosed whether the attackers exfiltrated data or issued a ransom demand. The company says its investigation is ongoing and the full scope, nature, and impact of the incident remain undetermined.

Why this matters beyond one dairy brand

Fairlife is not a niche label — it's a roughly $4 billion annual revenue business for Coca-Cola, built on ultra-filtered milk and protein shakes that have become a fixture in US grocery and fitness retail. A production halt at that scale creates immediate supply disruption risk, and ransomware attacks that reach operational technology — the systems that actually run manufacturing lines, not just corporate IT — tend to cause the longest and costliest outages precisely because production can't safely resume until systems are verified clean.

This pattern has precedent in the beverage and food industry. Arizona Beverages suffered a ransomware attack in 2019 that took weeks to resolve, and United Natural Foods Inc. was hit in 2025 with disruption that stretched on for a similar period. Manufacturing environments are frequently harder to recover than office networks because production-line control systems can't simply be restored from a backup without risking physical safety or product quality issues.

The disclosure timing is notable

Coca-Cola moved quickly to file an SEC Form 8-K disclosing the incident, reflecting SEC cybersecurity disclosure rules that require public companies to report material breaches within four business days of determining materiality. The rapid, if still incomplete, disclosure stands in contrast to incidents where affected companies stayed silent for weeks. Coca-Cola's public position — that quality and safety are unaffected, but that scope and impact are still under investigation — leaves open the possibility of a more significant update once the forensic investigation concludes.

What to watch next

Three things will determine how serious this incident turns out to be: whether a ransomware group eventually claims credit and reveals what data it stole, how long the US production suspension lasts, and whether Coca-Cola discloses a ransom payment or refusal. Extended production downtime at Fairlife's scale would be a meaningful hit to a fast-growing product line Coca-Cola has invested heavily in expanding, and any confirmed data theft would trigger separate consumer and regulatory notification obligations beyond the SEC filing already made.

Originally reported by TechCrunch. Read the original article for additional details.

View original source
Share: