CiberLATAMbywhalemate

Fairlife halts U.S. production after ransomware

Fairlife paused U.S. production after a ransomware attack. A later analysis linked the case to CitrixBleed 2.

Whalemate Labs · AI-assisted researchPublished:Updated 2 min read

Coca-Cola said its U.S. dairy subsidiary Fairlife was hit by a ransomware attack that affected production systems. The company suspended manufacturing while it investigates the incident and works to restore impacted systems.

Update August 24, 2026: A later technical analysis linked the attack to exploitation of CitrixBleed 2 (CVE-2025-5777) as the initial access vector. It also said the encryption appears to have affected Fairlife's Nutanix infrastructure.

Coca-Cola said in a filing with the U.S. Securities and Exchange Commission (SEC) that its dairy subsidiary Fairlife was the victim of a ransomware attack that affected its production systems. Following the incident, the company decided to suspend Fairlife's U.S. production operations for an indefinite period while it addresses the case.

What did Fairlife report?

Fairlife said it temporarily paused milk production in the United States after a cyberattack hit its manufacturing operations. The company also said it is working with cybersecurity experts and law enforcement to investigate and remediate the incident.

The company warned that the disruption could lead to lower availability of its dairy products in U.S. stores while the issue is resolved.

How far did the incident spread?

TechCrunch reported that Coca-Cola described the attack on Fairlife as a ransomware incident that affected production systems, although no details were released about the responsible group or the ransom demand.

Engadget said, based on the SEC filing, that the impact was mainly limited to Fairlife's U.S. manufacturing operations systems, without affecting other subsidiaries or Coca-Cola's global corporate infrastructure. The company also acknowledged that, at the time of the report, it had not yet determined the total financial impact of the attack.

How did the company's response progress?

Associated Press said the cyberattack was initially discovered through unusual activity on Fairlife's systems, prompting the company to isolate and disconnect parts of its network as a containment measure before deciding to pause production.

The same coverage added that Fairlife began gradually restoring certain business functions unrelated to manufacturing while continuing work to recover the production systems affected by ransomware. AP also said the company stated that the quality of its dairy products was not compromised and that products already on the market are safe for consumption, meaning the incident affected operational systems but not food safety.

What did the later technical analysis add?

Eclypsium later said the incident likely began with exploitation of CitrixBleed 2, identified as CVE-2025-5777, and that encryption reached Fairlife's Nutanix infrastructure. That report expanded the technical description of the attack, although it did not change the company's decision to keep investigating and restoring its systems.

Sources

View all