
Anubis Ransomware Claims Fairlife Attack, Threatens Leak
.webp)
A ransomware group has stepped forward to claim the cyberattack that halted production at Coca-Cola's Fairlife dairy subsidiary earlier this month. The Anubis ransomware gang added Fairlife to its dark web leak site this week. The group says it stole roughly one terabyte of corporate data and is threatening to publish it unless the company opens negotiations by the end of the week.
The claim answers a question left open since Coca-Cola firstdisclosed the incident. We covered that initial disclosure when it broke,noting that production at Fairlife's U.S. facilities had been suspended whilethe company investigated the intrusion. At the time, no group had come forward.Coca-Cola had also not said whether any data was taken during the breach.
What Anubis Is Claiming
Anubis says it first broke into Fairlife's network about a week before Coca-Cola went public with the incident. The gang claims it fully encrypted Fairlife's Nutanix infrastructure during that window. According to the group, the company has no way to recover its systems without paying for a decryption key.
Anubis also claims Fairlife chose to report the breach rather than follow instructions the attackers say they left on the compromised network. The gang puts the volume of stolen data at approximately one terabyte. It has not detailed what that data actually contains or which departments it came from.
None of these claims have been independently verified. The alleged encryption of Fairlife's Nutanix systems, the exact volume of data taken, and the timeline the gang describes all come from the ransomware operation itself. That is a source with an obvious incentive to pressure its victim into paying quickly. Coca-Cola declined to comment when asked about the allegations directly.
How This Fits the Original Fairlife Ransomware Attack
Coca-Cola's original disclosure came through a securities filing that described unauthorized access to a portion of Fairlife's systems, including systems tied to production. That filing suspended manufacturing at Fairlife's American plants. Canadian operations kept running normally throughout. Coca-Cola said at the time that product quality and safety were not compromised.
What that earlier filing did not include was any word on attribution or stolen data. The Anubis ransomware Fairlife attack claim fills that gap now, but it does so unilaterally. Coca-Cola has not confirmed any part of the gang's account. Ransomware groups often inflate the scope of an intrusion to strengthen their negotiating position, so the terabyte figure should be treated as an opening claim rather than a settled fact.
Fairlife makes ultra-filtered milk, Core Power protein shakes, and other nutrition drinks sold across the United States. A dairy brand of this size losing a week of U.S. production already carries real supply chain weight. A confirmed data leak would add a second, separate front to the incident, since stolen corporate data can expose employees, business partners, and internal operations that have nothing to do with the factory floor.
Who Is Anubis
Anubis operates as a ransomware-as-a-service platform that first appeared in December 2024. Since then, the group has targeted organizations across a wide range of industries. It pairs file encryption with data theft, giving victims two separate reasons to pay rather than one.
Last year, Anubis added a wiper component to its toolkit. Once deployed, the wiper destroys files beyond recovery. That removes any fallback option for a victim who decides not to negotiate, because restoring from backups only works if the wiper never runs. The addition puts extra weight behind threats like the one now aimed at Fairlife.
The Anubis ransomware Fairlife attack is not this group's first attempt to combine encryption with public pressure. Naming victims on a leak site, publishing partial proof, and setting hard deadlines are all standard tactics for the operation, designed to force a response before a company finishes its own investigation.
What Comes Next
Anubis has set a deadline for the end of this week. The gang says it will publish the stolen files if Fairlife does not begin negotiations before then. Coca-Cola has not confirmed whether talks are underway.
Security researchers generally advise against paying ransomware demands. Payment does not guarantee that stolen data gets deleted, and it can mark a company as a repeat target for future attacks. For now, the true scale of what Anubis actually holds remains unconfirmed. Fairlife's next public statement will likely determine how seriously the threat should be taken, and whether the dairy brand becomes the latest entry on a growing list of ransomware leak sites.
Subscribe to receive the latest blog posts to your inbox every week.