← All articles

redaction

Coca‑Cola/Fairlife: ransomware, production halt and data theft

Coca‑Cola confirms data theft following a ransomware attack against Fairlife. U.S. production was suspended mid‑July; the Anubis group claims up to 1 TB of data.

On July 27, 2026, The Coca‑Cola Company confirmed data theft following a ransomware attack on its dairy subsidiary Fairlife. U.S. production was suspended in mid‑July, and the Anubis group claims to hold up to 1 TB of exfiltrated data.

The facts

  • Who: The Coca‑Cola Company and Fairlife, LLC (brands Fairlife, Core Power, Nutrition Plan; over $3B in annual retail sales).
  • What: ransomware attack causing U.S. production disruption and confirmed data exfiltration; Anubis claims up to 1 TB of data.
  • Where: Fairlife systems in North America; Canadian operations reportedly unaffected.
  • When: incident disclosed July 16, 2026; U.S. production paused mid‑July; data theft confirmed July 27; gradual restart announced the week of July 27.
  • How much: Fairlife represents “over $3B” in annual retail sales; attackers claim 1 TB stolen.

Legal and regulatory context

  • GDPR: Article 32 requires appropriate security (availability, resilience, segmentation). Article 33 requires notifying the competent authority within 72 hours in case of a personal data breach. See our resources on GDPR obligations.
  • NIS 2: depending on sector and size, food and beverage companies may qualify as “important entities” with risk management, continuity and 24h/72h/1‑month notification duties. For Luxembourg specifics, consult NIS 2 obligations in Luxembourg.
  • Trend: double extortion (encryption + leak), with publication threats if talks fail.

What this means for Luxembourg companies

  • Immediate operational risk: an OT/SCADA compromise can halt plants and impact revenue from day one; GDPR and, where applicable, NIS 2 notifications apply.
  • Digital supply chain: subsidiaries, warehouses and vendors (OT integrators, MES, WMS, SaaS, hosting) are attack vectors with material economic impact.
  • Evidence and proportionality: ability to demonstrate IT/OT segmentation, phishing‑resistant MFA, hardened AD, EDR/XDR, immutable backups; tested plans and trustworthy logs.

Concrete actions to take this week

  • Run a timed “bare‑metal + data” restore test on a critical scope (production ERP, scheduler, WMS) and document achieved RTO/RPO; trigger updates to your business continuity and disaster recovery plan if objectives are missed.
  • Verify and evidence IT/OT segmentation: flow mapping, phishing‑resistant MFA, hardened vendor remote access; eliminate flat bridges between office IT and production.
  • Stand up a “24/72/30” process: GDPR/NIS 2 incident playbook (triage criteria, clock, notification content, legal/PR contacts, double‑extortion scenario). Align with the NIS 2 directive framework for timelines and content.
  • Hunt for credentials and exfiltration: EDR/XDR telemetry, proxy/SaaS logs, abnormal volume detection, Anubis IOCs; bolster monitoring with a managed SOC and EDR/XDR detection.
  • Harden servers and file services: block living‑off‑the‑land, application control, SMB signing, immutable off‑domain backups, sandboxed decryption tests.

Sources

If you need a NIS 2/ILR briefing or a production‑halt BCP/DRP workshop tailored to your environment, feel free to contact us for a 48‑hour turnaround kit.

Article generated by Luxgap regulatory watch. For tailored guidance on this topic, contact us.

LUXGAP NEWSLETTER

Get our analyses the moment they drop.

GDPR, NIS 2, AI expertise articles, plus invitations to free webinars + trainings at Luxgap. 1 to 2 emails per week max, one-click unsubscribe.

Your data is never shared. GDPR-compliant (we're DPOs after all).

A question on this topic?

Our team usually replies within one business day. Configure your quote or write to us.

Build my quote →