Coca-Cola Halts Fairlife US Production After Ransomware Attack
Coca-Cola has disclosed that its fairlife dairy unit suffered a ransomware attack, leading to the suspension of all US production while an investigation is conducted.
July 17, 2026 – 9:17 am
Image by: The Coca-Cola company
According to a statement from Coca-Cola, fairlife experienced unauthorized access to its systems, including production systems. As a result, US production has been temporarily suspended while the company works to address the incident. Operations in Canada are not affected.
The company promptly recognized the issue, activated its incident-response and business-continuity plans, and has enlisted external advisors and cybersecurity experts. They have also notified law enforcement.
"The full scope, nature, and impacts of the incident are not yet known," Coca-Cola stated. It remains unclear whether this breach is "reasonably likely to materially affect" the company. The company assured that product quality and safety were not compromised and refrained from naming the attackers.
Why It Matters
fairlife is a significant brand for Coca-Cola, generating an estimated $4 billion in sales in 2024. The ultra-filtered milk brand has experienced rapid growth, riding the protein boom. Ransomware attacks on food and beverage companies have historically caused extensive disruptions, leading to empty shelves.
A Rough Run for Corporate Security
This attack is part of a concerning trend of third-party and enterprise breaches this year, ranging from espionage campaigns to stolen vendor access. It highlights the challenges organizations face in securing their systems against sophisticated cyber threats. Microsoft has been focusing on rebuilding its security business around AI to counter precisely these types of attacks.