Anubis Ransomware Gang Claims Coca-Cola’s Fairlife Breach, Threatens to Leak 1TB of Data

Published
Written by:
Lore Apostol
Lore Apostol
Cybersecurity Writer
Key Takeaways
  • Ransomware claim: Anubis claimed responsibility for the Fairlife data breach, threatening to publish 1 terabyte of data unless paid a ransom.
  • Production halted: Coca-Cola said production at Fairlife's U.S. facilities was temporarily suspended following the hack.
  • Disruptive profile: Trend Micro analysis linked Anubis to file wiping software, giving its operations a particularly destructive edge.

Hacking gang Anubis claimed credit on Tuesday for an attack on Fairlife, the Coca-Cola-owned dairy company, threatening to publish stolen data unless it received an unspecified ransom. The Chicago-based firm produces dairy products including protein shakes and filtered milk drinks.

Anubis Claims Fairlife Data Breach on Dark Web

The Ransomware-as-a-Service (RaaS) group claimed the Fairlife data breach on its dark web site, stating it had stolen 1 terabyte of Fairlife data, according to Dark Web Informer. The announcement mentioned a published sample to back the claim.

Anubis is one of many cybercriminal gangs that encrypt victims' data until a ransom is paid, and it threatened to publish stolen data.

Anubis announced an alleged breach of Coca-Cola Fairlife | Source: Dark Web Informer
Anubis announced an alleged breach of Coca-Cola Fairlife | Source: Dark Web Informer

On July 16, The Coca-Cola Company said in an 8-K filing on behalf of Fairlife, LLC, that it “identified unauthorized access by a third party to a portion of its systems, including its production-related systems, in connection with a ransomware event.

Anubis’s attack chain | Source: Trend Micro
Anubis’s attack chain | Source: Trend Micro

Anubis Profile and File Wiping Capabilities

A 2025 Trend Micro analysis cited the group's optional "wipe mode" feature. That capability distinguishes Anubis from many extortion crews, since it can permanently destroy data rather than simply encrypt or exfiltrate it, raising the stakes for organizations weighing whether to pay.

Coca-Cola said last week that production at Fairlife's U.S. facilities was temporarily suspended after a hack, with operations in Canada remaining stable.

The company was also targeted in May 2025 by Everest Ransomware Group, which dumped stolen employee data after Coca-Cola refused to pay the ransom.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: