Code on screen with skull showing ransomware attack

Ransomware Attack at Coca-Cola’s Fairlife Dairy Company Halts U.S. Operations

A ransomware attack has hit Fairlife dairy production facilities, forcing the milk processor to shut down its U.S. operations temporarily.

Chicago-based Fairlife is a subsidiary of beverage giant Coca-Cola with annual revenue of about $3 billion worldwide. Its products include high-protein ultra-filtered whole, chocolate, and fat-free milk, ultra-filtered milkshakes, and nutritional drinks.

According to a regulatory filing with the U.S. Securities and Exchange Commission (SEC), Fairlife learned of unauthorized third-party access to a portion of its IT systems on July 16, 2026.

It responded by activating its incident response protocols, launching an investigation with the assistance of third-party cyber forensics experts, and notifying law enforcement authorities.

Ransomware attack shuts down Fairlife U.S. operations

The cyber attack resulted in the company shutting down some systems to contain the threat, disrupting operations in the United States. However, Canadian production operations and product quality remained unaffected.

“Product quality and safety have not been impacted. However, as a result of the incident, production operations at Fairlife in the United States are temporarily suspended. Fairlife’s Canada production operations are not currently impacted,” the company stated.

Meanwhile, Fairlife is working to restore impacted systems and operations and to understand the full scope of the incident. However, the company has yet to determine if the ransomware attack would have any material impact on the company.

Similarly, the entity behind the ransomware attack, how they gained initial access, and whether they exfiltrated personal and corporate data, remains unknown. Fairlife has also not disclosed if the attackers have made ransom demands, and no cybercrime gang has taken responsibility for the ransomware attack.

“Fairlife is not a minor business buried inside Coca-Cola’s portfolio,” said Joseph Perry, Cybersecurity Researcher and Advanced Services Lead at Arcova. “Coca-Cola generated nearly $48 billion in net revenue last year and made a $6.1 billion contingent payment tied to its acquisition of Fairlife, which provides important context for the value of the operation now sitting idle.

“With production suspended across Fairlife’s U.S. facilities, every hour can compound the financial impact through lost output, delayed shipments, recovery costs, inventory exposure, and potential disruption for retailers. Coca-Cola has not yet quantified the loss, but the longer production remains offline, the more quickly a cyber incident becomes a material business event.”

Ransomware attacks continue to target the Food and Agriculture sector

The Food and Agriculture sector is among the 16 critical infrastructure sectors whose disruption could adversely affect public health, economic stability, national security, and the reliable supply of essential goods and services, making it a lucrative target for cybercriminals.

In 2021, the FBI and CISA warned of ransomware attacks targeting the Food and Agriculture sector, resulting in financial losses and negatively impacting the supply chain.

According to the Food and Agriculture Information Sharing and Analysis Center (Food and Ag-ISAC), the sector experienced 205 attacks in 2026, only third behind manufacturing and commercial sectors, with half of the incidents occurring in the USA.

“Ransomware groups aren’t targeting milk, they’re targeting downtime,” said Harry Thomas, CTO and Founder of Frenos. “Food and beverage manufacturers deal with perishable inventory, fixed production schedules, cold-chain requirements, and retailer commitments, so disrupting ordering, labeling, quality-control, or distribution systems can stop production without an attacker ever touching the machinery itself.”

“This is becoming an operational pattern, not an isolated incident: Fairlife, Arizona Beverages, UNFI, and others all show how an intrusion that starts in ordinary IT can disrupt production and distribution. The important question isn’t whether an attacker can get into the network, it’s what they can reach once they’re there,” added Thomas.

In 2021, a ransomware attack on JBS, the world’s largest meat processor, forced the company to shut down operations in the United States, Canada, and Australia, and pay $11 million in ransom to resume operations.

In the same year, hackers targeted NEW Cooperative, an 8,000-member alliance of soy and corn farmers, and demanded $5.9 million in ransom after disrupting operations. Other food and agriculture sector organizations victimized by cybercriminals in 2021 include Crystal Valley Cooperative, Yoshida Foods International, and Schreiber Foods.

In 2023, a ransomware attack on Dole Food Company shut down North American production and distribution operations, costing the company $10.5 million. Similarly, Whole Foods distributor United Natural Foods (UNFI) halted distributions after experiencing a cyber attack in 2025, which resulted in order cancellations.

“Production environments are also harder to recover than office IT. You can’t reboot a production line the way you reboot a laptop. These environments combine specialized equipment, older technology, and vendor access, and operators have to know the environment is actually clean, that recipes, configurations, safety controls, and quality processes can still be trusted, before they restart anything,” concluded Thomas.