CyberSecurity

Coca-Cola Halts Fairlife Production in US After Ransomware Attack Hits Dairy Unit

Published

on

Coca-Cola Confirms Ransomware at Fairlife, Halts US Production

Soft drinks giant Coca-Cola confirmed on Thursday that a ransomware attack has forced it to suspend production at its Fairlife dairy subsidiary in the United States. The company disclosed the incident in a filing with the US Securities and Exchange Commission (SEC) on July 16, saying hackers had compromised production-related systems.

Fairlife, based in Chicago, is a wholly owned Coca-Cola unit that produces ultra-filtered milk in five varieties: chocolate, fat-free, reduced fat, strawberry, and whole milk. The suspension means those products will not be made in the US until further notice.

“After detecting the issue, the Company promptly activated its incident response and business continuity protocols,” Coca-Cola told the SEC. The company said it is working with outside advisors and cybersecurity experts to investigate the breach and assess the damage.

What Coca-Cola Has Said — and What It Hasn’t

Coca-Cola’s SEC filing stressed that product quality and safety have not been compromised. But the company acknowledged that production operations at Fairlife in the United States are temporarily suspended.

Fairlife’s Canada production operations, however, are not currently affected. That suggests the attackers may have targeted systems specific to US facilities, though Coca-Cola has not confirmed that detail.

The company has not revealed how the ransomware attackers gained access, who is behind the attack, or whether any extortion demands have been made. SecurityWeek has reached out to Coca-Cola for additional information but has not yet received a response.

As of Thursday, no known ransomware group had publicly claimed responsibility for the incident.

SEC Filing Details a Rapid Response

The filing with the SEC outlines a fast-moving response: Coca-Cola said it notified law enforcement immediately after detecting the intrusion. The company’s investigation is ongoing, and it has not yet determined the full scope, nature, or impact of the incident.

“The Company’s investigation and assessment of the impact of the incident is ongoing, with the assistance of outside advisors and cybersecurity experts,” the filing reads. Coca-Cola added that it is “scrambling to complete its investigation” and to determine whether the incident will have any material impact on its business.

The disclosure comes amid a broader wave of ransomware attacks targeting critical infrastructure and food supply chains. Dairy operations, in particular, have been hit before. In 2021, a ransomware attack disrupted Fairlife’s operations, forcing the company to temporarily shut down some systems. This latest incident appears to be more severe, with production halted entirely in the US.

Fairlife’s Role in Coca-Cola’s Portfolio

Fairlife is a relatively small but strategically important part of Coca-Cola’s business. The brand focuses on high-protein, ultra-filtered milk and has carved out a loyal following among health-conscious consumers. It is sold in major US retailers including Walmart, Target, and Kroger.

A prolonged production halt could lead to shortages of Fairlife products on store shelves, though Coca-Cola has not commented on inventory levels or potential supply chain disruptions. The company’s statement that Canada operations are unaffected suggests some buffer, but US consumers may soon notice gaps in availability.

The incident also raises questions about the cybersecurity posture of Coca-Cola’s subsidiaries. While the parent company has robust security teams, smaller units like Fairlife may have different levels of protection — a common vulnerability in large corporate structures.

What Comes Next for Coca-Cola and Fairlife

Coca-Cola faces several immediate challenges: restoring production at Fairlife’s US facilities, determining whether any data was stolen, and potentially negotiating with the attackers if a ransom demand emerges. The SEC filing indicates the company is still in the early stages of its investigation.

Regulatory scrutiny is likely. The SEC has been aggressive in enforcing cybersecurity disclosure rules, and any delays or omissions in reporting could lead to penalties. Coca-Cola’s filing appears to comply with current requirements, but the agency may probe further if the incident turns out to be more serious than initially described.

For now, the company is focused on containment and recovery. “Product quality and safety have not been impacted,” Coca-Cola reiterated in its filing — a message designed to reassure consumers that the milk already on shelves is safe to drink.

But the production halt itself is a stark reminder that ransomware attacks can have real-world consequences far beyond data loss. When a dairy plant stops making milk, the effect is immediate: fewer cartons on the shelf, higher prices, and frustrated customers. Coca-Cola will be hoping its response is swift enough to avoid those outcomes.

SecurityWeek will update this article if Coca-Cola provides additional information or if a ransomware group claims responsibility.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version