Fairlife halts U.S. production after ransomware
Fairlife paused U.S. production after a ransomware attack. A later analysis linked the case to CitrixBleed 2.
Coca-Cola said its U.S. dairy subsidiary Fairlife was hit by a ransomware attack that affected production systems. The company suspended manufacturing while it investigates the incident and works to restore impacted systems.
Update August 24, 2026: A later technical analysis linked the attack to exploitation of CitrixBleed 2 (CVE-2025-5777) as the initial access vector. It also said the encryption appears to have affected Fairlife's Nutanix infrastructure.
Coca-Cola said in a filing with the U.S. Securities and Exchange Commission (SEC) that its dairy subsidiary Fairlife was the victim of a ransomware attack that affected its production systems. Following the incident, the company decided to suspend Fairlife's U.S. production operations for an indefinite period while it addresses the case.
What did Fairlife report?
Fairlife said it temporarily paused milk production in the United States after a cyberattack hit its manufacturing operations. The company also said it is working with cybersecurity experts and law enforcement to investigate and remediate the incident.
The company warned that the disruption could lead to lower availability of its dairy products in U.S. stores while the issue is resolved.
How far did the incident spread?
TechCrunch reported that Coca-Cola described the attack on Fairlife as a ransomware incident that affected production systems, although no details were released about the responsible group or the ransom demand.
Engadget said, based on the SEC filing, that the impact was mainly limited to Fairlife's U.S. manufacturing operations systems, without affecting other subsidiaries or Coca-Cola's global corporate infrastructure. The company also acknowledged that, at the time of the report, it had not yet determined the total financial impact of the attack.
How did the company's response progress?
Associated Press said the cyberattack was initially discovered through unusual activity on Fairlife's systems, prompting the company to isolate and disconnect parts of its network as a containment measure before deciding to pause production.
The same coverage added that Fairlife began gradually restoring certain business functions unrelated to manufacturing while continuing work to recover the production systems affected by ransomware. AP also said the company stated that the quality of its dairy products was not compromised and that products already on the market are safe for consumption, meaning the incident affected operational systems but not food safety.
What did the later technical analysis add?
Eclypsium later said the incident likely began with exploitation of CitrixBleed 2, identified as CVE-2025-5777, and that encryption reached Fairlife's Nutanix infrastructure. That report expanded the technical description of the attack, although it did not change the company's decision to keep investigating and restoring its systems.
Sources
- Fairlife pauses US production of milk after cyber attackusatoday.com· USA Today
- Coca-Cola suspended production at its Fairlife dairy after a ransomware attacktechcrunch.com· TechCrunch
- Fairlife pauses US production after cyberattack breached milk brand's systemsfinance.yahoo.com· Associated Press (vía Yahoo News)
- Coca-Cola's dairy company fairlife hit with a ransomware attackengadget.com· Engadget
- Coca-Cola suspends U.S. production of billion-dollar brand after cyberattackajc.com· The Associated Press
- Coca-Cola Confirms Data Breach After Fairlife Ransomware Attacksecurityweek.com· SecurityWeek
- Ransomware group Anubis claims Fairlife hackyahoo.com· Yahoo News
- When Patching Isn't Enough: What the Fairlife Incident Reveals About CitrixBleed and Critical Infrastructure Riskeclypsium.com· Eclypsium
- Coca-Cola halts US production of Fairlife milk after cyberattackupi.com· UPI


