Coca-Cola’s Fairlife ransomware attack: why risk doesn’t respect the org chart 

Key takeaways  How Fairlife’s cyberattack became a group governance issue  On July 16, 2026, Coca-Cola disclosed that Fairlife, its dairy business, had detected unauthorized access to a section of its network, including production-linked systems. Production at Fairlife’s 4 US factories stopped. Canadian production continued. Product on shelves stayed safe.  A ransomware-as-a-service group calling itself Anubis claimed responsibility, saying it had taken 1 terabyte of data and threatening to leak it. According to…

Corey Avatar

Key takeaways 

  • On July 16, 2026, Coca-Cola’s dairy business Fairlife detected unauthorized access to part of its own IT systems, halting US production at 4 plants. 
  • Ransomware group Anubis claimed the attack, said it encrypted Fairlife’s Nutanix systems and stole 1TB of data. Coca-Cola restarted most US production by July 27. 
  • Coca-Cola judged the incident unlikely to be financially material, a call made the day before its Q2 earnings release. 
  • Fairlife is a separate, wholly-owned business line with its own systems, yet the incident still reached Coca-Cola’s own investors, disclosures and brand. 
  • The lesson for GRC teams: risk doesn’t respect the org chart. A subsidiary’s incident becomes the parent’s problem the moment it’s material enough to matter. 

How Fairlife’s cyberattack became a group governance issue 

On July 16, 2026, Coca-Cola disclosed that Fairlife, its dairy business, had detected unauthorized access to a section of its network, including production-linked systems. Production at Fairlife’s 4 US factories stopped. Canadian production continued. Product on shelves stayed safe. 

A ransomware-as-a-service group calling itself Anubis claimed responsibility, saying it had taken 1 terabyte of data and threatening to leak it. According to a statement the group posted to its data leak site, reported by BleepingComputer, Anubis said: “We have fully encrypted their Nutanix systems. They have no chance of recovering without our encryption key.”  

By July 27, Coca-Cola said Fairlife had “resumed the majority of production” at all 4 US plants, adding that retail availability had been “largely unimpacted due to the availability of existing inventory.” 

As is typical in these cases, Coca-Cola has said little about the ransom itself. The company has declined to comment on whether it paid the attackers, and Anubis’s leak site continued to list Fairlife as a victim throughout, suggesting that no payment changed hands. When the group’s deadline passed on 27 July, the stolen files were reportedly published on the group’s site; Coca-Cola has not confirmed what the data contained or how sensitive it was. 

Coca-Cola also told the market that, based on the information available, it believes the incident “has not had, and is not reasonably likely to have, a material impact on the company’s financial condition or results of operations.”  

Coca-Cola as the parent company, not Fairlife, is answerable to the US Securities and Exchange Commission, to investors, and to the market, and its judgment was announced the day before Coca-Cola’s second-quarter earnings release. A cyber incident inside an independently-operated subsidiary didn’t just create a production problem. It created a disclosure problem, on a clock the parent company doesn’t control. 

Why does a subsidiary’s incident become the parent’s risk and compliance problem? 

Fairlife makes ultra-filtered milk, protein shakes and nutrition drinks under its own brand, in its own factories, on its own IT systems. Coca-Cola bought out the remaining stake in 2020 and has run it as a distinct business line ever since, entirely separate from the soft drinks business that built the parent company’s name. None of that stopped this incident from becoming Coca-Cola’s story to manage. 

This is an example of what GRC Analyst and Pundit Michael Rasmussen describes as Quantum GRC. In a recent article, he writes:  

“Traditional GRC is largely linear and deterministic. An assessment is distributed, someone completes it, another person reviews it, an issue is created, a remediation task is assigned, and a report is eventually presented to management.” 

Michael Rasmussen, GRC Analyst & Pundit, GRC 20/20 Research 

But, he says, in real life, risks are entangled

“In quantum physics, entangled particles remain related even when they appear physically separate. In business, risks, controls, objectives, processes, technologies, regulations, and third parties are similarly interconnected. A change in one area can alter the state of many others . . . A cyber incident is not merely a cybersecurity risk. It can become an operational disruption, a regulatory breach, a privacy incident, a financial loss, a supply-chain failure, a customer-trust issue, and a board-governance crisis.” 

Michael Rasmussen, GRC Analyst & Pundit, GRC 20/20 Research 

For Coca-Cola, a cyberattack inside one business line became an operational disruption (4 US plants offline), a financial materiality question (assessed the day before an earnings release), an investor communications event, and a reputational story running under Coca-Cola’s name rather than Fairlife’s. The attacker didn’t have to touch Coca-Cola’s corporate network for any of that to happen. 

Many organizations still structure their risk oversight around the “traditional”  assumption of linearity and determinism: that a business line’s incident is the business line’s problem until proven otherwise, particularly where the business line has its own board, its own management team and its own operational autonomy.  

Fairlife’s ransomware attack is a reminder that the assumption runs the wrong way. The default should be that a subsidiary’s incident is the group’s problem until it’s shown not to be, not the other way around, because reputational and regulatory exposure travel up an ownership structure far faster than operational detail travels down. 

“Full ownership of a business doesn’t automatically mean shared oversight of its risk. Coca-Cola ended up making a materiality judgment and an announcement about an incident inside a business it owns outright, in the same week it reported earnings. That’s exactly the kind of entangled risk GRC teams need to see coming: operational, financial and reputational consequences moving through the group faster than the org chart suggests they should.” 

Paul Cadwallader, GRC Strategy Director, CoreStream GRC 

Incident Management solution download

The risk boundary is bigger than the brand 

As Rasmussen’s Quantum GRC approach suggests, risk isn’t bounded or restrained by the brand. It gets entangled in every stage of the value-chain from inbound logistics and supply-chain to clients, sales and service. 

In the UK, the Cyber Monitoring Centre, an independent body that categorizes major cyber events, assessed the 2025 ransomware attack on Jaguar Land Rover as a Category 3 systemic event, with:  

  • £1.9 billion UK financial impact 
  • > 5,000 organizations affected across its manufacturing base.  

And when a ransomware attack on pathology provider Synnovis disrupted more than 11,000 NHS appointments in south-east London, the disruption moved straight from one organization’s systems into another’s ability to deliver care.  

As Verizon’s 2025 Data Breach Investigations Report found, the leading initial attack vectors used in cyber attacks are: 

  • 22% – Credential abuse, and 
  • 20% – Exploitation of vulnerabilities 

A login sitting outside your direct line of sight, whether it belongs to a supplier, a subcontractor or a subsidiary running its own systems, is still your exposure. 

Whatever the boundary, corporate ownership, a contract, a service relationship, the consequences of an incident routinely travel further than the systems it started in. 

That’s why materiality and reputational exposure can no longer be assessed one business unit at a time. Ransomware groups like Anubis tend to favor stolen credentials or known, unpatched vulnerabilities over novel exploits, which means the technical entry point is often mundane, even when the organizational consequences ripple all the way to the boardroom and the investor call. 

What GRC teams should do now to better manage this complex, cross-boundary risk 

Extend risk visibility across every business line, not just the parent’s own network  

Make sure something or someone in your organization is actively looking across subsidiaries, brands and business units, especially those running their own IT estates under common ownership, rather than assuming shared ownership means shared oversight. 

Build a joint playbook for cyber incidents and materiality judgments  

Fairlife’s production outage and Coca-Cola’s “not reasonably likely to be material” statement landed a day apart, ahead of earnings. Cyber response and disclosure decisions need to sit close together, not in separate workstreams that meet for the first time mid-crisis. 

Ask who assesses group-wide impact when the affected entity isn’t the parent  

If a business line, brand or subsidiary is hit, know in advance who owns the assessment of operational, financial and reputational impact across the whole group, and how quickly that assessment reaches the board. 

Treat credential hygiene and patching as a group-wide baseline, not a business-unit choice  

Ransomware groups like Anubis succeed more often through stolen credentials and unpatched, known flaws than novel exploits. That baseline should apply consistently across every business line, not only the ones with the most mature IT function. 

Strengthen your group-wide risk visibility 

Coca-Cola’s Fairlife business will recover its production numbers well before most observers move on from the headlines. But for GRC teams, the critical question is: when risk is entangled, does your organization see it coming from inside its own businesses? 

CoreStream GRC’s platform is purpose-built for enterprise complexity, engineered for the flexibility, scalability, and control that large organizations demand. 

Explore how CoreStream GRC can help you connect risk across every part of the business, inside and outside the org chart:

Frequently asked questions 

Why does a subsidiary’s cyber incident matter to the parent company’s GRC program? 

Because operational, financial and reputational consequences don’t stop at a subsidiary’s own walls. Fairlife’s incident shows how a breach inside one wholly-owned business line can still generate a materiality judgment, an investor communication and a reputational story for the whole group, regardless of how separate that business line’s own systems are. 

What does it mean for risk to be “entangled” across a business? 

It means that a change or incident in one part of an organization, a system, a business line, a regulation, a control, can alter the state of several others at once. A cyber incident can simultaneously become an operational disruption, a financial materiality question, a governance issue and a reputational event, which is why GRC programs increasingly need to track risk as connected rather than siloed by department or business unit. 

How should GRC teams handle materiality assessment when an incident happens outside core corporate systems? 

The same way they would for any incident that could affect group-wide performance or reputation: with a clear, pre-agreed owner for the assessment, a fast route to the board, and coordination between cyber, finance, legal and communications teams from the outset, rather than waiting for an incident to escalate before deciding who is responsible for judging its impact. 

How common are ransomware attacks that rely on stolen credentials rather than sophisticated hacking? 

Very common. Verizon’s 2025 Data Breach Investigations Report found credential abuse present in 22% of breaches, one of the two leading initial attack vectors alongside vulnerability exploitation. Groups such as Anubis are known to favor stolen credentials and unpatched, publicly known flaws over novel techniques. 

  • Coca-Cola’s Fairlife ransomware attack: why risk doesn’t respect the org chart 

    Coca-Cola’s Fairlife ransomware attack: why risk doesn’t respect the org chart 

    Key takeaways  How Fairlife’s cyberattack became a group governance issue  On July 16, 2026, Coca-Cola disclosed that Fairlife, its dairy business, had detected unauthorized access to a section of its network, including production-linked systems. Production at Fairlife’s 4 US factories stopped. Canadian production continued. Product on shelves stayed safe.  A ransomware-as-a-service group calling itself Anubis claimed responsibility, saying it had taken 1 terabyte of data and threatening to leak it. According to…

  • Simplifying risk in a complex world to achieve business objectives – key findings from the Spotlight on Women in GRC 

    Simplifying risk in a complex world to achieve business objectives – key findings from the Spotlight on Women in GRC 

    In this episode of CoreStream GRC’s Spotlight on Women in GRC podcast, Lucy Montague speaks with Sharon Sharples, Chief of Staff and Head of Operational Risk Governance and Insights at Barclays, about her journey from change management into risk leadership, the evolving role of GRC in modern organizations, and why curiosity, simplification, and flexibility will define the…

  • Regulatory compliance including SCF compliance frameworks

    Regulatory compliance including SCF compliance frameworks

    What is regulatory compliance? Regulatory compliance is the process of meeting the laws, rules, standards, and requirements set by regulators, governments, and supervisory bodies. It helps organizations understand which external obligations apply, assign ownership, operate controls, collect evidence, and report when required. In governance, risk, and compliance (GRC), regulatory compliance matters because regulatory expectations rarely…