
Coca-Cola’s Fairlife dairy brand experienced a ransomware attack in mid-July that halted U.S. production for nearly two weeks. The company’s public statements have not clarified whether hackers breached plant operations or if corporate systems were the initial target.
The missing details in Fairlife’s disclosures
Coca-Cola’s SEC filings on July 16 and July 28 described “unauthorized access by a third party to a portion of its systems, including its production-related systems.” The same wording appeared in both documents, yet the company avoided terms like “IT” or “operational technology.”
Such omissions are deliberate. Securities law requires companies to disclose only what they can confirm. Fairlife confirmed U.S. production stopped while Canadian operations continued without interruption. The company also acknowledged data theft but did not specify the volume. A group called Anubis later claimed responsibility, stating it stole 1 terabyte, though Coca-Cola has not verified the claim or the amount.
By July 28, Fairlife reported most U.S. production had resumed, and retail supply remained stable due to existing stock. Product safety and quality were unaffected, and authorities were notified. Still, the filings did not explain how the attack occurred.
Related: FDA’s GRAS rule takes effect in December
The significance of the unanswered question
In food and beverage manufacturing, the boundary between corporate networks and operational systems is often unclear. If either fails, production can stop—whether due to encrypted files or legal requirements to halt operations without proper documentation.
Fairlife’s shutdown may have resulted from a disabled manufacturing execution system or a locked database tracking pasteurization temperatures. Without those, plants cannot legally operate, even if machinery remains functional. The difference between IT and operational technology may matter less than identifying which critical dependency failed first.
Plant managers, not just IT teams, must understand which systems are essential to keep production running. If a company cannot identify these in advance, it risks the same situation Fairlife faced—assessing damage while operations remain stalled.
The contrast between U.S. and Canadian operations highlights the attack’s impact. Fairlife’s Canadian plants continued running, likely because they used separate infrastructure.
Related: Lettuce recall exposes food traceability gaps
Repeated vulnerabilities in food manufacturing
Fairlife is not the first food company to face such an incident. In May 2021, JBS Foods, the world’s largest meat processor, suffered a ransomware attack. Nine U.S. plants and several in Australia closed. JBS paid $11 million to restore operations after attackers initially demanded $22 million.
The two incidents share key similarities: production halts and data theft. Many plants still use older control systems connected to newer enterprise software, often with cloud links for maintenance or quality checks. These integrations improve efficiency but also create new attack opportunities.
Steps for food and beverage leaders
Companies do not need to wait for a breach to address these risks. They should determine what happens if the connection between a plant and corporate network is lost. Which systems keep production running, which trigger mandatory shutdowns, and how long can manual workarounds last before introducing new risks?
If no one can answer these questions in detail, the company is already at risk. Fairlife’s disclosures suggest this gap exists, and its customers and board are now facing the consequences.