Coca-Cola suspended production at its Fairlife dairy after a ransomware attack

Coca-Cola has confirmed that dairy production at its Fairlife subsidiary has come to a halt across the United States after cybercriminals struck the unit with ransomware. The beverage giant disclosed the incident in a filing with the U.S. Securities and Exchange Commission, stating that systems controlling manufacturing at Fairlife were compromised and that output would stay offline while the company works through the fallout.
According to the filing, Fairlife's U.S. manufacturing lines are "temporarily suspended," though Coca-Cola did not specify when normal operations might resume. The company has not detailed which ransomware group is behind the intrusion, how the attackers gained entry, or whether any customer, employee, or financial data was stolen alongside the disruption to production systems.
Fairlife is no minor product line. The ultra-filtered milk brand, best known for its high-protein shakes and lactose-free drinks, has grown into one of Coca-Cola's most lucrative dairy investments, generating roughly $4 billion in sales as of 2024. Coca-Cola took majority ownership of the brand several years ago after initially partnering with its founders, folding it into a broader portfolio that spans soda, bottled water, juices, and now dairy-based beverages sold nationwide.
A halt at a brand of that scale carries real supply-chain weight. Retailers that stock Fairlife's shelf-stable milk and protein drinks could see gaps if the shutdown drags on, and Coca-Cola itself may face short-term revenue pressure tied to one of its faster-growing categories. The company has given no public estimate of the financial impact, and it remains unclear whether the disclosure reflects an abundance of caution or a more serious breach still being assessed.
The episode fits a broader pattern of ransomware operators targeting food and beverage manufacturers, an industry where production runs on tightly linked digital control systems that are difficult to take offline without halting physical output entirely. Security researchers have long flagged the sector as attractive to attackers precisely because plant downtime creates urgency to pay a ransom quickly.
History offers a cautionary comparison. When Arizona Beverages was hit by ransomware in 2019, the company's bottling operations were knocked out for an extended stretch. More recently, grocery distributor UNFI suffered a similar attack that triggered weeks of disrupted deliveries and left store shelves noticeably barer in some regions. Both cases suggest that even after systems are restored, downstream effects on retailers and consumers can linger well beyond the initial outage.
For now, Coca-Cola has offered few specifics beyond confirming the attack and the suspension of Fairlife manufacturing, leaving open questions about the scope of the breach, the attackers' identity, and the timeline for getting production lines running again. The company's SEC disclosure suggests it considers the incident material enough to warrant investor notice, a signal that the resolution may not be quick.
Source: TechCrunch
Related articles

OpenAI launches its new family of models with GPT-5.6
OpenAI's latest family of models promises improvements across a range of areas, including cybersecurity.
Create AI images with your own API key
aixipi runs on desktop/web, uses your own model API balance, and avoids subscription lock-in.
Try aixipi →
Netflix reportedly considers adding always-on channels
It’s apparently looking at streaming bundles, too.

Fidji Simo steps down from leading OpenAI’s AGI work due to illness
“For now, my focus is recovery.”