01Summary
Coca-Cola said in a Form 8-K on 16 July 2026 that fairlife found unauthorised access to part of its systems, including production systems, in a ransomware event. US production was suspended; Canadian production was unaffected. Anubis claimed to have encrypted servers and threatened to leak 1 TB of data. Coca-Cola refused to negotiate, restored most production by 27 July, and confirmed data had been taken. Product safety was not affected.
02Victims and impact
Countries affected
- United States
03Data exposed
Data types
- Corporate data
04Timeline
- 2026-07-16Coca-Cola discloses the attack; US production suspended.
- 2026-07-27Most production restored.
05Disclosure and media
Publishing organisations
- BleepingComputer
- SecurityWeek
- Help Net Security
- AJC
06Sources
Official documents
- The Coca-Cola Company Form 8-K (16 Jul 2026)
References
- [1]SEC: https://www.sec.gov/Archives/edgar/data/0000021344/000162828026048466/ko-20260716.htm
- [2]Help Net Security: https://www.helpnetsecurity.com/2026/07/28/coca-cola-fairlife-dairy-subsidiary-ransomware-attack/









