Ransomware gang claims attack on Coca-Cola dairy unit - FoodWorld News
FoodWorldNews
Food News, World Wide
● Breaking

Ransomware gang claims attack on Coca-Cola dairy unit

Ransomware gang claims attack on Coca-Cola dairy unit - coca-cola ransomware
Ransomware gang claims attack on Coca-Cola dairy unit

A ransomware-as-a-service group called Anubis claimed responsibility for a cyberattack on Coca-Cola’s dairy products subsidiary, Fairlife. The threat group posted screenshots to its data leak site, stating it locked the company’s servers and stole 1TB of data. Anubis is demanding payment within a week, threatening to release the information publicly if the demands are not met.

Operational Disruptions and Corporate Response

Coca-Cola officials said the attack forced the company to suspend U.S. production at Fairlife while it investigated. The company stated there was no impact on the safety or quality of the dairy products. The disruption follows a broader trend in the food and beverage sector where supply chain networks become attractive targets for cybercriminals.

Fairlife represents a significant portion of Coca-Cola’s overall business. The company bought out the remaining majority stake in Fairlife in 2020. The subsidiary surpassed $1 billion in annual revenue in 2022 and has continued to expand its operations, including a planned $650 million expansion of a plant in Coopersville, Michigan announced in March.

Tactics and Technical Details

Researchers at Arctic Wolf said Anubis is a ransomware-as-a-service operation that emerged in late 2024 as a rebrand of Spinx ransomware. The group generally uses two methods to gain initial access, either through valid, stolen VPN credentials or the exploitation of vulnerabilities such as CitrixBleed 2, which is tracked as CVE-2025-57777. This vulnerability is linked to insufficient input validation, which can lead to memory overread when Citrix NetScaler is configured as a Gateway.

Related: Taco Bell Faces Diarrhea Outbreak Lawsuits

According to Halcyon researchers, Anubis often employs destructive tactics designed to undermine recovery methods. Before encryption, the group frequently shuts down the ability to create volume shadow copies and prevents other security processes from helping companies restore data. This approach complicates the remediation process for victims, extending the time needed to return to normal operations.

“Anubis affiliates have repeatedly secured initial access by exploiting internet-facing vulnerabilities and abusing stolen VPN credentials,” Stefan Hostetler, staff threat intelligence researcher at Arctic Wolf, told Cybersecurity Dive. “In our investigations, we’ve seen attackers take advantage of vulnerabilities that were not new or especially sophisticated, showing a persistent reality that threat actors often succeed by exploiting known weaknesses that organizations haven’t fully remediated.”

Coca-Cola has not provided any details about the specific threat group linked to the attack or the methods used to gain access to systems. The company did not respond to a request for comment regarding the incident.