Confirmed Theft Extends the Fairlife Ransomware Risk
The break is no longer just interrupted production at Fairlife. Coca-Cola has confirmed that the incident involved taking data, so the remaining risk is leak exposure and stolen-records monetization even as facilities come back online.
Anubis had already claimed the attack, saying it encrypted systems and stole data, then used a countdown on its leak site to force payment. Coca-Cola now says most production has resumed at the four U.S. Fairlife facilities, but it has not said what data was taken.
That confirmation turns the extortion claim into a verified breach. The incident now carries the usual follow-on pressure from disclosure, notification, and public release of stolen records, not just recovery of operations.