Prevent This: Industrial Scale Ransomware
Fairlife, one of the largest US dairy companies was taken offline by a cyber attack. Here are some simple steps that companies and individuals can take to protect themselves.
In July 2026, a group of criminals reached into the systems of one of America’s biggest dairy companies and forced the company to stop milk production.
Coca-Cola’s fairlife brand, the ultra-filtered milk and the Core Power protein shakes suspended all of its US production after a ransomware attack. Not because the milk was unsafe, but because the computers that run the plants were compromised and the company pulled the plug to contain the damage.
Milk now joins gas and meat on the list of ordinary things a hack has taken offline. Ransomware stopped being an abstract problem for IT departments a while ago. It empties store shelves, cancels surgeries, and, as we will get to, it can lock up your family photos just as easily as it locks up a dairy.
Important Note: Coca-Cola stated that product quality and safety were not affected by this attack.
THREAT ACTOR DOSSIER
Ransomware-as-a-service crew, financially motivated
Also known as: evolved from an earlier strain called “Sphinx.” (Not the Anubis Android banking malware of the same name; a different threat entirely.)
In business since: December 2024
Assessed origin: Russian-speaking / former-Soviet region, based on which countries they avoid attacking (Moderate confidence)
Who they target: opportunistic, hitting healthcare, construction, engineering, and hospitality, with victims across the US, Canada, Australia, and Peru
How they break in: phishing emails, and stolen or guessed remote-login (RDP) passwords
Signature move: “wipe, leak, extort.” They steal your data before locking it, and, rare among these crews, their software has a wiper that can permanently destroy your files even if you pay the ransom.
Did they claim the fairlife attack? Yes. Anubis listed fairlife on its dark-web leak site and claims to have stolen 1 terabyte of data, giving Coca-Cola until “the end of the week” to pay. It has shown no proof, and Coca-Cola has not confirmed that Anubis was involved or that any data was takenOur assessment: it is LIKELY that Anubis is behind the fairlife attack, at MODERATE confidence. Our own dark-web monitoring has now captured the listing on Anubis’s leak site (first seen July 20), which corroborates outside reporting and confirms the claim is genuine. It stops short of confirmed because both trace back to Anubis’s own post: the group has shown no proof of the stolen data, and Coca-Cola has not confirmed it. (Likely means more probable than not. Moderate confidence means the sourcing is solid but the claim is not confirmed.).
Intelligence: Intruvent Codex, Intruvent Styx, with CyberDaily (the leak-site claim) and vendor analysis (Trend Micro, Barracuda, SOCRadar).
A Hack Stopped the Milk
Here is what is actually known, because the details matter and the internet has already run ahead of the facts.
On July 16, 2026, Coca-Cola disclosed in a securities filing that its dairy subsidiary, fairlife, had been hit by ransomware. Attackers reached its systems, including the ones that run production, so the company suspended all US manufacturing. Canadian production kept going, product quality and safety were not impacted, and Coca-Cola said the full scope was not yet known.
This Keeps Happening to the Things We Rely On
If the idea of a hack stopping milk sounds far-fetched, it should not, because we have seen this movie before with bigger props.
In May 2021, the Colonial Pipeline attack shut down the largest fuel pipeline in the United States for several days. The pipeline company paid roughly $4.4 million to the criminals, but the real damage was the panic. Gas stations across the Southeast ran dry as drivers rushed to fill up, and prices spiked. A single ransomware infection turned into a regional fuel shortage.
That same month, JBS Foods, the largest meat processor in the world, was hit. Plants in the US, Canada, and Australia went dark for about a day, taking roughly a fifth of American beef capacity offline with them. JBS paid $11 million to get running again.
And it is not just commodities. In May 2025, Kettering Health, a fourteen-hospital system in Ohio, was crippled by ransomware. Elective procedures were cancelled, staff were locked out of the systems they use to treat people, and the fallout included hundreds of lawsuits from patients who say their care was delayed. Healthcare is now the single most targeted sector for ransomware, which means the stakes are no longer measured only in dollars.
Gas. Meat. Hospitals. Milk. The pattern is the point. Ransomware has moved out of the server room and into the physical world you live in.
What Ransomware Actually Is (And Why “I Have Backups” Isn’t the Whole Answer)
Ransomware is malicious software that locks up an organization’s files by scrambling them, then demands payment for the key. That is the classic version, and for years the standard defense was simple: keep good backups, and if you get hit, restore your files and refuse to pay.
The criminals adapted. The dominant playbook now is called double extortion, and it works like this: before they scramble anything, the attackers quietly copy your data out. Then they encrypt your systems. Now they can squeeze you two ways. Pay up, or you do not get your files back, AND we publish everything we stole.
Some crews go further still. Anubis, the group that has claimed the fairlife attack, runs what researchers call a “wipe, leak, extort” model, and its software includes a rare feature that can permanently destroy your files, reducing them to nothing, even if you pay.
Why This Lands on You
You do not run a dairy or a pipeline, so why does this belong in a newsletter for regular people? Two reasons.
First, you are the data. When a company you buy from, bank with, or work for gets hit, the information they hold about you is what gets stolen and leaked. You did nothing wrong, and your name, email, and sometimes far more end up on a criminal’s website or for sale. The most common follow-on is targeted phishing: scammers who reference the real breach you just heard about to trick you into clicking. The milk company or the hospital took the hit, but you inherit the risk.
Second, ransomware also comes for individuals and small businesses directly. The same class of attack that locks up a hospital can lock up a freelancer’s laptop, a small shop’s point-of-sale system, or a family’s shared photo drive. If your livelihood or your memories live on a single computer with no backup, you are one bad click away from your own private version of the milk shutdown.
The good news is that the defenses that protect a Fortune 500 company are the same ones that protect your kitchen laptop. They are not expensive, and they are not technical.
The Numbers
7,874 organizations were named on ransomware leak sites in 2025, a record, up about 50 percent in a year (NCC Group)
$1 million average ransom payment in 2025, down from $2 million the year before, as more victims refuse to pay (Sophos)
36 percent of victims paid in 2025, down from 41 percent, because backups are improving (industry data)
Healthcare is the single most targeted sector, with roughly 410 attacks in the first half of 2026 alone (FBI / Comparitech)
72 minutes is the fastest observed time from break-in to stealing the data (Unit 42)
3 everyday things a ransomware attack has now taken offline: gas (2021), meat (2021), and milk (2026)
The Fix
There are two jobs here: protect your own stuff, and know what to do when a company that holds your data gets hit.
Part A: Make your own files ransomware-proof
1. Follow the 3-2-1 rule. Keep 3 copies of anything you cannot bear to lose, on 2different kinds of storage, with 1 copy kept offsite or offline. In plain terms: the photos on your laptop, plus a copy on an external drive, plus a copy in a reputable cloud service. CISA recommends exactly this.
2. Keep one backup disconnected. Modern ransomware hunts for backups and destroys them first. A backup drive that is always plugged in can be encrypted right alongside the original. Back up, then unplug it. An offline copy is the one they cannot reach.
3. Test that your backup actually restores. A backup you have never opened is a guess, not a safety net. Once in a while, actually pull a file back from it and confirm it works.
4. Turn on automatic updates and MFA. Most ransomware gets in through an unpatched program or a stolen password. Automatic updates close the holes, and multi-factor authentication (ideally an authenticator app or a passkey) stops a stolen password from being enough.
5. If you ever get hit, do not rush to pay. The FBI and CISA both advise against paying. It does not guarantee you get your files back, and it does nothing to stop stolen data from being leaked. Disconnect the device from the internet, and report it (see below) before you do anything else.
Part B: When a company you trust gets breached
1. Read the notice and check your exposure. When you get a breach notification, look for the line that says what information was involved. You can also check haveibeenpwned.com to see where your email has turned up.
2. Consider Freezing your credit. If a breach exposed your Social Security number, a credit freeze at all three bureaus (Equifax, Experian, and TransUnion) is something that you can do to limit the financial damage. It is free, it takes a few minutes online, and it stops criminals from opening new accounts in your name.
3. Expect the themed phishing. After any big breach, scammers send messages pretending to be the breached company, offering “help” or “compensation” and counting on the fact that you already know the breach is real. Do not click links in those messages. Type the company’s address into your browser yourself.
4. Change the password, and never reuse it. Update the password for the affected account, turn on two-factor authentication, and make sure that password is not protecting anything else.
The Bottom Line
A ransomware attack was serious enough to stop one of the country’s biggest dairies from making milk. That is where we are now. These attacks reach off the screen and into gas stations, hospitals, and the dairy aisle, and the criminals have shifted from simply locking data to stealing it, which means no single company can promise your information is safe.
You cannot stop other companies from getting hit. What you can do is make sure a ransomware attack never gets to hold your life or your company hostage. Keep three copies of what matters, with one of them unplugged. Turn on updates and MFA. And when a company you trust gets breached, freeze your credit and treat the “helpful” follow-up messages as the scams they usually are.
The milk will be back on the shelf soon. Take twenty minutes this week so that if the attack ever comes for your files, you can shrug it off just as easily.
If you are hit by ransomware or affected by a breach:
Report ransomware: FBI Internet Crime Complaint Center, ic3.gov, or CISA 24/7 at 888-282-0870
Ransomware help and guides: cisa.gov/stopransomware
Check your exposure: haveibeenpwned.com
Freeze your credit (free): Equifax, Experian, and TransUnion
Free credit reports: AnnualCreditReport.com
Identity theft recovery: IdentityTheft.gov
Sources
The Coca-Cola Company, SEC Form 8-K disclosure of the fairlife ransomware event (July 16, 2026)
BleepingComputer, “Coca-Cola says fairlife ransomware attack halts US dairy production” (July 2026)
TechCrunch and CBS News coverage of the fairlife incident (July 2026)
CyberDaily, “Exclusive: Coca-Cola fairlife hack claimed by Anubis ransomware” (July 21, 2026), for the leak-site claim
Trend Micro, Barracuda, and SOCRadar analyses of the Anubis ransomware group (2025), for the actor profile and wiper/affiliate model
Intruvent Codex and STIX (actor record); Intruvent Dark-Codex dark-web monitoring
Colonial Pipeline ransomware attack (May 2021); JBS Foods ransomware attack (May 2021)
Kettering Health ransomware attack (May 2025)
NCC Group Annual Threat Intelligence Report 2025; Sophos State of Ransomware 2025; FBI IC3 and Comparitech (healthcare, 2025 to 2026)
CISA, #StopRansomware Guide and Back Up Your Data guidance; FTC consumer advice on data breaches
Prevent This is a weekly cybersecurity newsletter from Intruvent Technologies. Each week, we break down one cyber threat in plain language and give you the tools to protect yourself and the people you care about. For our bi-weekly technical deep dive, check out Intruvent Edge.





