Anubis menace Coca-Cola via Fairlife
The Anubis ransomware group is threatening to publicly release 1 terabyte of stolen data from Fairlife, a dairy products subsidiary of Coca-Cola, unless Coca-Cola pays a ransom by July 27th. Anubis claims to have encrypted Fairlife’s servers and is leveraging the threat of a public data leak to pressure Coca-Cola into negotiating. The group’s aggressive communication, including a reference to ‘returning the milk to the people,’ highlights a targeted and manipulative extortion strategy. Due to the lack of specific details regarding the intrusion and the nature of the stolen data, it remains unclear how significant the breach truly is, but the threat is substantial and requires immediate attention.
The Anubis ransomware group is threatening to publicly release 1 terabyte of stolen data from Fairlife, a dairy products subsidiary of Coca-Cola, unless Coca-Cola pays a ransom by July 27th. Anubis claims to have encrypted Fairlife’s servers and is leveraging the threat of a public data leak to pressure Coca-Cola into negotiating. The group’s aggressive communication, including a reference to ‘returning the milk to the people,’ highlights a targeted and manipulative extortion strategy.
Fairlife was initially created as a co-venture with the Select Milk Producers cooperative. In January 2020, it became a wholly-owned subsidiary of The Coca-Cola Company, solidifying the link between the attack and the parent organization. This connection is why Anubis is directly addressing Coca-Cola, aiming to impact not only Fairlife’s operations but also Coca-Cola’s reputation and governance structures.
The group’s message emphasizes a ‘solution commercial simple et confidentielle’ – a transaction designed to restore systems in a few hours, but with the continued control of the attackers over the compromised environment. They claim to have no information about the initial intrusion date, the specific systems affected, or the exact nature of the files being demanded. The lack of detail makes it difficult to verify the extent of the breach and whether Fairlife’s operations have been truly disrupted.
Despite the promise of a rapid restoration, the details provided are insufficient to verify the claims. The message deliberately obscures the ransom amount, using the phrase ‘agreement symbolique’ to avoid disclosing the financial demand. The group’s strategy is clearly focused on psychological pressure, exploiting the potential damage of a public data leak and leveraging the complex corporate structure to maximize the impact on Coca-Cola.
This incident underscores the value of criminal communications as a source of intelligence. The tone, timing, personalization of the message, and the volume of data claimed provide insights into the extortion tactics employed, demanding a careful distinction between assertions and confirmed facts. Coca-Cola must prioritize assessing the threat, protecting sensitive information, and understanding the true intentions of the attackers, rather than solely focusing on technical recovery.
