Fairlife, the dairy subsidiary of The Coca-Cola Company, has temporarily suspended its U.S. production operations following a major cyberattack, the company announced.
The ransomware event resulted in unauthorized access to portions of Fairlife’s IT systems, including elements of its production processes. The company, which posted $4 billion in sales in 2024, said it has launched an investigation with external cybersecurity experts and has notified law enforcement.
“Product quality and safety have not been impacted. However, as a result of the incident, production operations at fairlife in the United States are temporarily suspended,” Fairlife said in a statement, noting that its Canadian operations remain unaffected.
“The company is working diligently to complete the investigation and restore the systems and impacted operations,” the statement continued.
Coca-Cola has not indicated when U.S. production will resume. Newsweek contacted The Coca-Cola Company for comment by email.
A Growing Threat to Supply Chains
The disruption highlights a shifting trend in cybercrime, where attackers increasingly target operational technology rather than just corporate databases. While data breaches frequently expose sensitive information—such as names, addresses, Social Security numbers, and financial records—attacks on industrial control systems can halt manufacturing and disrupt broader consumer supply chains.
The suspension at Fairlife comes amid a broader wave of cyber incidents targeting major U.S. food, consumer, and travel brands:
- Rich Products Corporation: In May, the major U.S. food manufacturer suffered a data breach linked to a phishing attack. According to state attorney general filings in New Hampshire and Massachusetts, the compromised data included names, dates of birth, Social Security numbers, and driver’s license numbers.
- Nike: In January, the apparel giant investigated a potential breach after the ransomware group World Leaks claimed to have published 1.4 terabytes of data online. “We always take consumer privacy and data security very seriously,” Nike said at the time. “We are investigating a potential cyber security incident and are actively assessing the situation.”
- Carnival Corporation: In May, the cruise line parent company disclosed an April cyberattack stemming from a compromised employee account. The breach affected nearly 6 million people, leaking names, addresses, and government identification numbers, according to the Maine Attorney General’s office.
Understanding a Ransomware Attack
Ransomware is a type of malicious software that blocks access to a victim’s files or networks, with perpetrators typically demanding a cryptocurrency payment to restore access. In recent years, cybercriminals have adopted “double extortion” tactics, stealing sensitive data before encrypting systems and threatening to publish it online if the ransom is not paid.
Cybersecurity experts recommend organizations and individuals take several foundational steps to mitigate the risk of ransomware:
- Exercise Email Caution: Do not open unexpected attachments, verify suspicious requests before clicking links, and remain wary of urgent messages regarding payments or credentials.
- Prompt Patching: Install operating system and software updates immediately, enabling automatic updates when available.
- Deploy Multi-Factor Authentication (MFA): Implementing MFA adds a critical layer of security, making it significantly harder for attackers to exploit stolen passwords.
- Maintain Backups: Keep secure backups of important data disconnected from the primary network to ensure recovery without paying a ransom.
- Utilize Security Software: Maintain active, updated antivirus and anti-malware protections to detect threats before they spread.
Contact Newsweek editors for this story: John Fitzpatrick and Anthony Murray.
Related Articles