CyberSecurity

Anubis Ransomware Gang Says It Stole 1TB of Data From Coca-Cola’s Fairlife Unit

Published

on

Anubis Group Claims Credit for Fairlife Disruption

The cybercriminal group known as Anubis has publicly claimed responsibility for the ransomware attack that forced Coca-Cola’s dairy subsidiary Fairlife to halt production. On its dark web leak site, the gang says it grabbed a full terabyte of confidential files before locking up the company’s servers.

The claim, posted July 20, gives Coca-Cola a week to pay up. If no ransom arrives, Anubis says the stolen data will be dumped online.

That’s a tight window, and it puts the beverage giant in an uncomfortable spot. Paying could fund more attacks. Refusing could mean sensitive corporate data ends up public.

What We Know About the Attack on Fairlife

Coca-Cola disclosed the incident last week, confirming that production at Fairlife had been suspended while the company assessed the damage. The full scope of the breach is still being determined.

Fairlife is a major player in the U.S. dairy market, known for its high-protein milk products and sports drinks. A prolonged shutdown doesn’t just hurt the bottom line — it can ripple through grocery shelves and supply contracts.

SecurityWeek has reached out to Coca-Cola for additional comment on the Anubis claims, but no further details have been released so far.

Who Is the Anubis Ransomware Group?

Anubis isn’t a household name like LockBit or BlackCat, but it’s been busy. Active since December 2024, the group has already listed roughly 100 victim organizations on its leak site.

The gang operates on the standard double extortion model: encrypt files to disrupt operations, then threaten to leak the stolen data if the victim won’t pay. It’s a tactic that’s become the industry norm because it works.

What sets Anubis apart is a darker feature. The group has a ‘wiper mode’ that can permanently delete files, making recovery impossible even with backups. That’s a threat that goes beyond financial damage — it’s aimed at destroying a company’s data forever.

Why the Wiper Mode Matters

Most ransomware gangs want to get paid and move on. A wiper function signals a group willing to burn everything down if negotiations stall. For incident responders, that changes the calculus entirely. Restoring from backups becomes a race against time, not a routine procedure.

The Growing Threat of Data Leak Extortion

This incident is another reminder that ransomware is rarely just about encryption anymore. The real leverage is the data. Companies like Fairlife now face the possibility that trade secrets, employee records, or financial documents could surface on the dark web.

Recent attacks on Estée Lauder and Clover Health show the pattern: a breach is disclosed, then weeks or months of fallout follow. The Ernst & Young data breach that exposed personal and financial information is a stark example of how far the damage can spread.

For security teams, the lesson is grim but clear. Assume that if attackers get in, they’ll get out with something valuable. Preparation for data theft is no longer optional.

What Happens Next for Coca-Cola and Fairlife?

The clock is ticking. Anubis has set a deadline, and the industry is watching to see how Coca-Cola responds. Will it negotiate, hold the line, or quietly pay?

There’s no easy answer. Law enforcement agencies generally advise against paying ransoms, but for a company facing a production halt and the threat of leaked data, the pressure is immense.

One thing is certain: this won’t be the last time a major brand finds itself in this position. Ransomware groups are getting bolder, and their tools are getting meaner. The Fairlife attack is just the latest example of a threat that keeps evolving.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version