Ransomware halts fairlife dairy production across the US (Coca-Cola)
Ransomware has shut down all US production at fairlife, Coca-Cola's $KO dairy subsidiary, per an SEC filing dated July 16. Canadian plants keep running. The attack reached production systems directly, stopping physical output rather than just office IT.
Milk production at fairlife, the dairy brand owned by Coca-Cola $KO, has been suspended across the United States after a ransomware attack. The company said it discovered on July 16 that a third party had gained unauthorized access to parts of fairlife's systems, including systems tied to production. Coca-Cola considered the incident significant enough to report it in an SEC Form 8-K filing. According to the company, Canadian production is unaffected and product quality and safety were not compromised. Incident response and business continuity protocols were activated, outside cybersecurity experts were brought in, and law enforcement has been notified. Coca-Cola has not said whether data was stolen or whether it is being extorted, and no ransomware group has claimed the attack so far. What stands out is where the attack landed. The intrusion reached production-related systems, and the consequence is physical: dairy lines standing still nationwide. Manufacturing environments remain attractive targets because production systems are often harder to patch and segment than classic IT. Coca-Cola has not yet said when US lines will restart. Per Coca-Cola's official press release and the company's SEC 8-K filing; first reported by outlets including BleepingComputer and TechCrunch.