Coca-Cola’s Fairlife resumes operations after attack

Coca-Cola
Coca-Cola subsidiary Fairlife resumes operations after cyberattack. (Image: Getty Images/Mustafu)

Operations resume after Coca-Cola subsidiary Fairlife hit by ransomware attack


Coca-Cola cyberattack – overview

  • Coca-Cola’s Fairlife subsidiary has resumed most production after ransomware disruption
  • Attack halted operations and resulted in unauthorised data access
  • Coca-Cola has not disclosed stolen data or ransom demands
  • Retail availability remained stable due to existing product inventories
  • Incident highlights growing cyber risks facing food manufacturers today

Explore related questions

Beta

It’s ten days since The Coca-Cola Company was hit by a serious cyberattack, which impacted operations at its Fairlife facility, and operations are only now returning to normal.

Coca-Cola cyberattack

The beverage giant confirmed it had been hit by a ransomware attack on 17 July, stating it had identified “unauthorised access by a third party to a portion of its systems”, which led to the suspension of operations and the “taking of certain data”.

Coca-Cola did not disclose what data was taken or whether it included customer, employee or supplier information.

The company has also not disclosed whether it received a ransom demand or whether any stolen information has been published online.

Despite the continued lack of detail around the incident, the multinational has made progress in restoring operations.

More than a week after the disruption, it confirmed that its dairy subsidiary has “resumed the majority of production” at its facilities in the United States.

Fairlife has become an increasingly important part of Coca-Cola’s dairy portfolio since it acquired the remaining stake in the business in 2020. The brand is best known for its ultra-filtered milk and protein shakes, which have experienced strong demand in recent years.

Business impact

The owner of major brands including Coca-Cola, Sprite and Fanta says retail availability of Fairlife products has been “largely unimpacted” due to existing inventory, and product quality and safety “have not been impacted”.

It also stated that, “based on the information currently available”, it does not believe the incident has had, or is reasonably likely to have, a material impact on its financial condition or results of operations.

However, the attack underscores the growing risk cyber threats pose to food and beverage manufacturers, where operational technology and production systems are increasingly connected to digital networks. Even short periods of downtime can disrupt production schedules, supply chains and product distribution.

While Coca-Cola has maintained that retail availability has remained largely unaffected, the disruption highlights the importance of inventory buffers and business continuity planning in the event of a cyber incident.

Wider implications

The attack comes amid a rise in ransomware incidents targeting manufacturers and critical infrastructure operators. Food and beverage companies have become increasingly attractive targets for cybercriminals due to their reliance on continuous production and the potentially significant financial consequences of operational downtime.

Cybersecurity experts have repeatedly warned that attackers are shifting their focus towards organisations where production stoppages can create pressure to restore systems quickly. In such cases, ransomware attacks can result in both operational disruption and the theft of potentially sensitive corporate or personal data.

Investigation continues

Coca-Cola has confirmed that it’s working with law enforcement and is being assisted by “outside advisors and cybersecurity experts”.

As operations continue to recover, attention is likely to focus on the findings of the investigation, the nature and extent of any data exposure, and what lessons the incident may hold for the wider food and beverage sector as cyberattacks become an increasingly significant operational risk.