// 7 ZERO-DAY · 10 CVE · 11 EXPLOIT · 2 ADVISORY IN THE LAST 24H
The Anubis ransomware group claims responsibility for an attack on Fairlife, a Coca-Cola subsidiary specializing in premium dairy products, on July 20, 2026. Coca-Cola confirmed a production halt at the affected facility the same week. Anubis is threatening to publish approximately 1 TB of allegedly exfiltrated data unless a ransom is paid within seven days.

The Anubis ransomware group claimed responsibility for an attack on Fairlife, a Coca-Cola subsidiary specializing in premium dairy products, on July 20, 2026. That same week, Coca-Cola confirmed a production suspension at the affected plant. Anubis now threatens to publish roughly 1 TB of allegedly exfiltrated data unless a ransom is paid within seven days.

Key Takeaways
  • Anubis claimed the Fairlife attack on July 20, 2026, listing the company on its leak site
  • Coca-Cola confirmed a production halt at Fairlife "last week," according to SecurityWeek
  • The group claims to have exfiltrated 1 TB of "confidential data," an assertion not independently verified
  • Anubis has operated since December 2024 with a double-extortion model and a "wiper mode" for permanent file deletion

The Anubis Model: Double Extortion with a Wiper Option

Anubis employs a double-extortion scheme that combines file encryption with sensitive data exfiltration. The wiper capability adds a third lever: the threat of permanent document deletion even if the victim refuses to pay. This mechanism increases pressure on victims, who must simultaneously contend with operational disruption, the risk of public data exposure, and permanent data loss.

The group has been active since December 2024 and has listed approximately 100 organizations on its leak site, according to the cited source. The engagement tempo suggests a structured operation, though the dossier does not document the specific technical infrastructure or the initial access chain used in the Fairlife attack.

Impact on the Food Supply Chain

The production halt at Fairlife disrupts a dairy supply line operating in the premium segment of the U.S. market. The attack illustrates how ransomware groups select targets in sectors critical to the availability of essential goods, betting on a higher propensity to pay driven by revenue loss and reputational pressure.

The timing of Coca-Cola's confirmation — the same week as the claim — indicates the incident was already underway for an unspecified period. The dossier does not clarify whether the production halt was ordered as a precautionary measure or as a direct consequence of system inaccessibility.

"locked" — Anubis group, in reference to the Fairlife attack

Immediate Actions

For organizations with supply chains that include partners in the food sector, the incident demands three concrete steps. First: verify operational continuity contracts with dairy suppliers, given that the Fairlife production halt demonstrated the vulnerability of entire supply lines to single ransomware points of failure.

Second: monitor the Anubis leak site for any publication of Fairlife data, as the group has set a seven-day deadline for ransom payment. Publication would occur on infrastructure known since December 2024, with listing patterns documented for roughly 100 previous victims.

Third: review cyber insurance and business interruption coverage for attacks that cause production stoppages without necessarily involving verified data exfiltration. The Fairlife case shows how operational disruption alone, combined with the threat of a leak, generates significant economic damage even without technical confirmation of the volume of stolen data.

Why This Matters

The brief does not document specific remedial measures taken by Coca-Cola or technical remediation interventions. The ransom amount demanded is unknown, as is whether the company intends to negotiate or has already refused payment. The seven-day deadline for data publication, reported by the source, expires in a window not specified by the dossier.

The dossier does not specify the nature of the exposed data: the claim of "confidential data" remains an assertion by the attacking group, not corroborated by independent evidence. At this stage, no infrastructure overlaps emerge linking the Anubis attack to other incidents in the food sector or to shared ransomware infrastructure-as-a-service.

What Remains to Be Verified

Several technical and strategic elements remain opaque. The dossier does not document the initial access vector — phishing, perimeter vulnerability, or compromised credentials — nor the type of systems affected. It is unclear whether Anubis actually completed the exfiltration of 1 TB or whether the figure represents an estimate or an inflated claim for negotiating purposes.

Also absent is any information on potential contacts between the group and Coca-Cola security officials, the status of negotiations, or the involvement of external consultants. The role of law enforcement authorities, if involved, is not mentioned by the source.

At the current state of verified facts, the incident remains a single attack confined to the Coca-Cola/Fairlife supply chain, with documented impacts on production and documented threats regarding data.

FAQ

What is Anubis's "wiper mode"?

According to the cited source, Anubis possesses a mode that allows for the permanent deletion of encrypted files, going beyond temporary inaccessibility. This mechanism eliminates the possibility of recovery even if decryption keys are available.

Are the 1 TB of data confirmed?

No. The 1 TB figure represents a claim by the Anubis group, reported by SecurityWeek, not independently verified or confirmed by Coca-Cola. The dossier contains no technical evidence of exfiltration of that volume.

What is the deadline for ransom payment?

The source reports a seven-day deadline from the claim, dated July 20, 2026. It is unknown whether this deadline has been extended, met, or ignored by the parties.

Information is based on the cited source and current as of publication.

Sources


Sources and references
  1. securityweek.com
  2. vulnerability.circl.lu