← The Desk 2026-07-27 The Wire
The Perimeter Site

Anubis Ransomware Steals 1TB of Data from Coca-Cola Dairy Unit Fairlife

Ray Delgado
2026-07-27
# Anubis Ransomware Steals 1TB of Data from Coca-Cola Dairy Unit Fairlife Listen up. If you're currently staring at a spreadsheet of "critical assets" and wondering why your budget for egress filtering got slashed, look at Fairlife. The Anubis group just put them on the board, claiming they locked the servers and walked out the door with 1TB of data. Let's get the obvious out of the way first. Fairlife is the dairy unit of Coca-Cola. When a subsidiary gets hit, the parent company usually spends the first forty-eight hours pretending they're separate entities for the sake of the stock price. Then they spend the next month wondering why the attackers used the subsidiary as a pivot point to see what else was on the network. I've seen this movie before. Back in 2017, NotPetya didn't care about "organizational charts." It just cared about reachable SMB shares. It turned Maersk into a very expensive collection of paperweights because the blast radius wasn't contained. The lesson then was the same as it is now: your security is only as good as your hardest internal boundary. If you have a "flat" network between your corporate HQ and a milk bottling plant, you don't have a network. You have a highway. Now, let's talk about how Anubis likely got in. They won't tell us, and Fairlife definitely won't. But look at the wire. We're seeing a massive spike in the tech sector—331 stories this week alone—and government is right behind it with 163. The attackers aren't inventing new physics. They're using the same three doors: a leaked credential from a third-party vendor, a phished admin who clicked a link on a Tuesday afternoon, or a known CVE that the patch management team decided was "low risk" because the server was "internal." The corporate statement will eventually arrive. It'll be a masterpiece of evasion. It will say they "detected unauthorized access" and are "working with leading cybersecurity experts." Here is what that actually means. "Detected unauthorized access" means they found the ransom note on the server. "Working with leading experts" means they just hired a firm to do the forensics they should have been capable of doing themselves. What they'll avoid saying is how 1TB of data left the building. One terabyte is a lot of milk. It's a lot of spreadsheets, payroll data, shipping manifests, and probably a few thousand emails that should have been deleted five years ago. To move a terabyte of data out of a corporate network without triggering a single alarm requires a level of negligence that borders on the intentional. You don't need a "sophisticated" attacker to exfiltrate a terabyte; you just need a network that doesn't monitor its own exits. I hate that word: sophisticated. Whenever a CISO uses "sophisticated" to describe a breach, he's trying to tell you that the attack was an act of God and therefore not his fault. It's a lie. Most of these groups are just disciplined. They use standard tools. They wait. They move slowly. They don't need to be sophisticated if the target is basically leaving the vault open and the guard is taking a nap. So, what does this cost you on a Tuesday? In the short term, it's the ransom demand—which we'll probably never know the exact number of, because paying it is the only way to keep the number secret. But the real cost isn't the payout. It's the cold chain. Fairlife isn't a software company. They move perishable goods. When the servers that manage logistics, routing, and inventory go dark, the milk doesn't stop being milk. It just stops being sellable. If the systems are down for three days, you aren't just losing digital uptime; you're losing millions of gallons of product that has a very strict expiration date. That is a physical cost that no insurance policy fully covers. Then there's the second-order effect. Think about the distributors. Think about the grocery stores. When a primary supplier's logistics engine dies, the ripple effect hits the retail shelves within 72 hours. The retailers then have to scramble to find alternative sources, which drives up spot prices and creates a logistics nightmare for everyone downstream. Anubis didn't just hit a dairy company; they threw a wrench into a regional food supply chain. The argument you'll hear from the "defense-in-depth" crowd is that you can't stop every intrusion. They'll tell you that the goal is "resilience," not "impenetrability." They're right, but they're using the word "resilience" as a shield for poor containment. Resilience isn't just having backups; it's ensuring that when the bottling plant gets hit, the corporate office doesn't automatically become a staging ground for the attacker. If you can't isolate a compromised segment in under an hour, you aren't resilient. You're just waiting for the bill. I've spent twenty years cleaning up these messes. The difference between a bad day and a company-ending event is almost always the blast radius. If Fairlife had a segmented environment and a strict egress policy, Anubis might have locked a few servers, but they wouldn't have walked off with a terabyte of data. The intrusion is common. The failure to stop the bleeding is a choice. Here is the uncomfortable question for the rest of you: If your most vulnerable subsidiary got hit right now, how long would it take for the attackers to reach your crown jewels? Don't answer that with "we have a firewall." A firewall is a fence. This is about what happens after the fence is jumped. If you're relying on a single perimeter to keep your entire organization safe, you're not running a security program. You're running a lottery. Watch the Anubis group. They aren't the biggest players on the wire, but they're picking targets where the digital failure has a physical consequence. That's where the leverage is. When the product spoils, the C-suite panics. And when the C-suite panics, they pay.
◼
← More from the Desk Live Wire →

DISCLAIMER: Articles on this site are generated automatically from public security news feeds for educational and informational purposes. They may contain errors, and nothing here constitutes security, legal, or compliance advice. Verify details against original advisories and vendor bulletins before acting on them.