Fairlife ransomware: day one is never the full scope
Coca-Cola went from 'scope not yet known' to 'certain data taken' in eleven days. Build your vendor incident process around provisional facts, not final ones.
On July 16, Coca-Cola told the market its dairy subsidiary fairlife had a ransomware incident and that US production was suspended. On July 27, it confirmed data had been taken. Nothing went wrong in between — that eleven-day gap is what a competent disclosure actually looks like. The mistake operators make is treating the day-one statement as the answer.
What actually happened
Coca-Cola's July 16 announcement described "unauthorized access by a third party to a portion of its systems, including its production-related systems, in connection with a ransomware event." US production at fairlife was temporarily suspended; Canadian operations were not affected. The company stated plainly that "the full scope, nature and impacts of the incident are not yet known," and that product quality and safety were unaffected.
Around July 20 the Anubis ransomware group added fairlife to its leak site and claimed roughly a terabyte of stolen files. On July 27, per BleepingComputer, Coca-Cola confirmed the event "involved access by an unauthorized third party to a portion of the company's systems and taking of certain data, and a temporary suspension of production operations." Most production has resumed across the four US plants, and existing inventory kept retail shelves stocked through the outage.
Read the two statements side by side. Nothing was retracted. The July 16 language was accurate and incomplete, which is what forensic reality looks like at day one. The scope moved because the investigation finished, not because anyone was hiding.
Why disclosure timing matters for your business
If you resell, distribute, or depend on a vendor that gets hit, your worst move is forwarding their first statement to your customers as reassurance. "Production impacted, no evidence of data loss" on Monday becomes "certain data was taken" eleven days later — and now you're the one who told your customers it was fine. Coca-Cola never said it was fine. You did.
Two things to change while this is fresh. First, in your own incident comms, distinguish loudly between what is known and what is not yet investigated, and commit to an update cadence instead of a conclusion. "We will update Thursday whether or not there is news" is a sentence that buys enormous trust and costs nothing.
Second, look at your vendor contracts. Most breach clauses specify a notification deadline and stop there. That gets you the day-one letter — the least useful artifact in the sequence. What you actually want written in is an update obligation: periodic status until the forensic scope is final, and explicit notice when the scope changes. Ask for it at renewal. Small vendors will agree to it far more readily than you'd expect, because nobody has asked them before.
And note the quiet operational lesson in the fairlife recovery: shelves stayed stocked because inventory existed. Buffer is not inefficiency. It's the thing that turns a supplier's two-week outage into a problem your customers never see.
Key takeaways
- Coca-Cola disclosed the fairlife ransomware event on July 16 with scope explicitly unknown, and confirmed data theft on July 27
- The Anubis group listed fairlife around July 20 claiming roughly 1TB of files; Coca-Cola reported the intrusion and did not negotiate
- A vendor's first statement is provisional by definition — never forward it to your customers as an all-clear
- In your own comms, commit to an update cadence rather than a conclusion, and separate known facts from open questions
- Negotiate an update obligation into vendor contracts, not just a notification deadline; inventory buffer is what absorbed the outage here
Would you know which vendors can stop your operation? We map the systems and suppliers a small business actually depends on, write the incident-comms path before you need it, and build the buffers that keep a vendor's bad week off your customers' radar. Talk through your dependencies or see how we work.
Sources: The Coca-Cola Company press release, July 16, 2026, BleepingComputer, Help Net Security.
- #ransomware
- #incident-response
- #vendor-risk
- #supply-chain
- #disclosure
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Qualcomm's price increase hits your hardware budget
Qualcomm told customers of a double-digit price increase on chips shipped after September 1. The AI buildout is now repricing hardware that has nothing to do with AI.
Read it24,000 exposed BMCs leak hashes: close your IPMI port
A 2004 protocol flaw with no patch is handing out password hashes from 24,000 internet-exposed server BMCs. The fix is network exposure, not a firmware update.
Read it