Coca‑Cola/Fairlife: ransomware, production halt and data theft
Coca‑Cola confirms data theft following a ransomware attack against Fairlife. U.S. production was suspended mid‑July; the Anubis group claims up to 1 TB of data.
On July 27, 2026, The Coca‑Cola Company confirmed data theft following a ransomware attack on its dairy subsidiary Fairlife. U.S. production was suspended in mid‑July, and the Anubis group claims to hold up to 1 TB of exfiltrated data.
The facts
- Who: The Coca‑Cola Company and Fairlife, LLC (brands Fairlife, Core Power, Nutrition Plan; over $3B in annual retail sales).
- What: ransomware attack causing U.S. production disruption and confirmed data exfiltration; Anubis claims up to 1 TB of data.
- Where: Fairlife systems in North America; Canadian operations reportedly unaffected.
- When: incident disclosed July 16, 2026; U.S. production paused mid‑July; data theft confirmed July 27; gradual restart announced the week of July 27.
- How much: Fairlife represents “over $3B” in annual retail sales; attackers claim 1 TB stolen.
Legal and regulatory context
- GDPR: Article 32 requires appropriate security (availability, resilience, segmentation). Article 33 requires notifying the competent authority within 72 hours in case of a personal data breach. See our resources on GDPR obligations.
- NIS 2: depending on sector and size, food and beverage companies may qualify as “important entities” with risk management, continuity and 24h/72h/1‑month notification duties. For Luxembourg specifics, consult NIS 2 obligations in Luxembourg.
- Trend: double extortion (encryption + leak), with publication threats if talks fail.
What this means for Luxembourg companies
- Immediate operational risk: an OT/SCADA compromise can halt plants and impact revenue from day one; GDPR and, where applicable, NIS 2 notifications apply.
- Digital supply chain: subsidiaries, warehouses and vendors (OT integrators, MES, WMS, SaaS, hosting) are attack vectors with material economic impact.
- Evidence and proportionality: ability to demonstrate IT/OT segmentation, phishing‑resistant MFA, hardened AD, EDR/XDR, immutable backups; tested plans and trustworthy logs.
Concrete actions to take this week
- Run a timed “bare‑metal + data” restore test on a critical scope (production ERP, scheduler, WMS) and document achieved RTO/RPO; trigger updates to your business continuity and disaster recovery plan if objectives are missed.
- Verify and evidence IT/OT segmentation: flow mapping, phishing‑resistant MFA, hardened vendor remote access; eliminate flat bridges between office IT and production.
- Stand up a “24/72/30” process: GDPR/NIS 2 incident playbook (triage criteria, clock, notification content, legal/PR contacts, double‑extortion scenario). Align with the NIS 2 directive framework for timelines and content.
- Hunt for credentials and exfiltration: EDR/XDR telemetry, proxy/SaaS logs, abnormal volume detection, Anubis IOCs; bolster monitoring with a managed SOC and EDR/XDR detection.
- Harden servers and file services: block living‑off‑the‑land, application control, SMB signing, immutable off‑domain backups, sandboxed decryption tests.
Sources
If you need a NIS 2/ILR briefing or a production‑halt BCP/DRP workshop tailored to your environment, feel free to contact us for a 48‑hour turnaround kit.
Article generated by Luxgap regulatory watch. For tailored guidance on this topic, contact us.
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →