The Anubis ransomware group has claimed responsibility for a disruptive cyberattack against Fairlife, a prominent dairy subsidiary of The Coca-Cola Company. The incident, which Coca-Cola first acknowledged on July 16, 2026, caused a temporary halt in U.S. production. On July 20, the Anubis group listed Fairlife on its dark web leak site, alleging the theft of 1 terabyte of confidential data and the full encryption of the company's Nutanix infrastructure. This incident is a classic example of a double-extortion ransomware attack targeting a high-profile manufacturing entity, highlighting the significant operational and data security risks faced by the food and beverage supply chain.
The attack follows the standard double-extortion model. The Anubis ransomware operators claim to have achieved two objectives: first, encrypting critical systems to disrupt operations, and second, exfiltrating a large volume of sensitive data to use as leverage for a ransom payment.
Anubis is a notable ransomware-as-a-service (RaaS) operation. Security researchers have previously identified a "wiper mode" in their malware, which allows the actors to permanently destroy data, adding another layer of threat beyond simple encryption.
While specific details of the initial access vector and lateral movement have not been publicly disclosed, the attack pattern is consistent with modern ransomware campaigns.
Likely Attack Trajectory:
The business impact of this attack is multi-faceted:
No specific Indicators of Compromise (IOCs) were provided in the source articles.
To hunt for Anubis or similar ransomware activity, security teams should look for:
vssadmin.exe delete shadowsPsExec.exe, wmic.exeDetection:
Coca-Cola confirms data theft in Fairlife ransomware attack, production mostly restored. Anubis group known to use CitrixBleed2 for initial access.
Fairlife production halted for over a week; Anubis ransom deadline passed without payment or data leak. Anubis group may be shifting to direct operations.
Maintain isolated, immutable backups to ensure recovery without paying a ransom.
Segmenting networks can help contain the spread of ransomware across an enterprise.
Mapped D3FEND Techniques:
Use EDR tools to detect and block malicious behaviors like rapid file encryption or deletion of shadow copies.
Mapped D3FEND Techniques:
The most critical defense against a ransomware attack like the one on Fairlife is a robust and resilient backup strategy. Organizations must implement the 3-2-1 rule: three copies of data, on two different media types, with one copy stored offline and isolated from the primary network. For virtualized environments like Nutanix, this means using backup solutions that create immutable snapshots and replicate them to a separate, air-gapped location or a cloud service with object lock enabled. Regularly test the recovery process to ensure backups are viable and that the organization can meet its Recovery Time Objectives (RTO). This countermeasure directly negates the primary leverage of ransomware (encryption) and provides a viable alternative to paying the ransom.
To combat the double-extortion tactic, organizations must focus on detecting data exfiltration before encryption occurs. Implement a Data Loss Prevention (DLP) or Network Detection and Response (NDR) solution to monitor and analyze outbound network traffic. Establish a baseline of normal data transfer patterns from critical servers, such as file servers and the Nutanix cluster. Configure alerts for any significant deviations from this baseline, such as a single host uploading terabytes of data to an unknown external IP address over a short period. This provides a crucial window of opportunity for security teams to intervene, isolate the compromised host, and prevent the final stage of the ransomware attack.
Proper network segmentation is key to containing a ransomware infection and preventing it from spreading from an initial entry point to critical infrastructure like Fairlife's Nutanix cluster. Implement a zero-trust network architecture where access between network segments is denied by default. Production manufacturing systems and core server infrastructure should be in a highly restricted zone. Access to this zone from the general corporate network should be strictly controlled and monitored. If an endpoint in the corporate environment is compromised, segmentation prevents the threat actor from easily moving laterally to encrypt the 'crown jewels' of the organization.
Coca-Cola discloses a ransomware incident at Fairlife that disrupted operations.
The Anubis ransomware group lists Fairlife on its dark web leak site.
Deadline set by Anubis for ransom payment.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.