Key Takeaways
- Fairlife, a dairy subsidiary of Coca‑Cola, suffered a ransomware breach claimed by the emerging group Anubis, which alleges exfiltration of ~1 TB of data.
- The attackers follow a double‑extortion model, threatening to publish or misuse the stolen information if ransom demands are unmet.
- Anubis is linked to the earlier Sphinx ransomware operation and appears to be a rebranded spin‑off that surfaced in 2024.
- Initial infection vectors likely involve compromised VPN credentials or exploitation of unpatched vulnerabilities such as CitrixBleed 2.
- The ransomware disables Windows Volume Shadow Copies and other backup mechanisms, severely hindering data recovery.
- Coca‑Cola asserted that product safety, production, and quality were unaffected, noting the compromised data resided in archived, non‑operational systems.
- The incident underscores the necessity of robust patch management, multi‑factor authentication for remote access, resilient and isolated backups, and continuous threat‑intelligence monitoring.
Overview of the Attack
Fairlife, the Coca‑Cola‑owned dairy brand, became the latest high‑profile victim of a ransomware incident when the relatively new threat actor Anubis announced it had infiltrated the company’s networks and stolen approximately one terabyte of data. The claim surfaced in early November 2025, quickly drawing attention from cybersecurity researchers and industry analysts. While the full scope of the compromised information remains under investigation, the attackers have adopted the increasingly prevalent double‑extortion approach: they encrypt systems and simultaneously threaten to leak or otherwise exploit the exfiltrated data unless a ransom is paid. This tactic raises the stakes for victim organizations, as reputational damage and regulatory penalties can accompany data exposure even if backups allow for system restoration.
Anubis Ransomware Group Profile
Arctic Wolf’s threat‑intelligence team was among the first to identify and monitor Anubis activity, noting that the group emerged in 2024 and has rapidly evolved its tactics to avoid detection. Researchers describe Anubis as a sophisticated ransomware-as-a‑service (RaaS) operation that targets a broad range of sectors, including food and beverage, manufacturing, and technology. The group’s infrastructure shows signs of continual refinement, with new command‑and‑control (C2) servers and encryption routines being deployed to thwart signature‑based defenses. Despite its recent appearance, Anubis has already been associated with several high‑impact incidents, suggesting a capable and well‑resourced backend that can sustain prolonged campaigns against large enterprises.
Coca‑Cola’s Response
In response to the allegations, Coca‑Cola issued a public statement emphasizing that the cyberattack did not compromise the safety, production, or quality of Fairlife’s dairy products. The company clarified that the data believed to have been accessed originated from archived systems rather than active operational environments, thereby limiting the immediate impact on day‑to‑day business functions. Coca‑Cola also affirmed that it has engaged internal security teams and external forensic investigators to assess the breach’s extent and to implement containment measures. While the statement seeks to reassure consumers and stakeholders, cybersecurity experts caution that assertions about data origin must be independently verified, as attackers sometimes misrepresent the nature of compromised assets to manipulate negotiation leverage.
Technical Details and Attack Vectors
Preliminary analysis by security firms points to common initial access techniques employed by Anubis: the use of compromised virtual private network (VPN) credentials or exploitation of unpatched vulnerabilities in enterprise software. One specific flaw highlighted in the group’s campaigns is CitrixBleed 2, a critical vulnerability affecting Citrix ADC and Gateway products that can allow unauthenticated remote code execution if left unaddressed. Successful exploitation of such flaws enables attackers to establish a foothold within the network, move laterally, and deploy ransomware payloads. The incident reinforces the importance of timely patch management, rigorous credential hygiene—including multi‑factor authentication for remote access—and continuous monitoring for anomalous authentication attempts.
Link to Sphinx and Rebranding Strategy
Threat intelligence analysts observe strong similarities between Anubis and the earlier Sphinx ransomware operation, suggesting that Anubis may be a rebranded or spin‑off variant of Sphinx. Rebranding is a prevalent tactic among ransomware gangs seeking to distance themselves from prior law‑enforcement scrutiny while preserving the core capabilities of their malware families. By altering names, C2 infrastructure, and ransom notes, groups like Anubis can evade existing blacklists and confuse defenders who rely on historical indicators of compromise. This dynamic underscores the need for behavior‑based detection methods—such as anomalous file‑encryption patterns or process‑injection activities—rather than relying solely on known malware signatures.
Backup Disablement Tactics
Halcyon’s research highlights a particularly destructive feature of the Anubis ransomware: its ability to delete or disable Windows Volume Shadow Copies and other backup mechanisms before initiating file encryption. By eliminating these recovery points, the malware significantly raises the cost and time required for organizations to restore data from backups, thereby increasing pressure on victims to satisfy ransom demands. This approach reflects a broader trend in ransomware development where attackers actively target an organization’s resilience mechanisms. Effective defenses therefore require immutable, air‑gapped, or offline backup solutions that are inaccessible from the production network, coupled with regular integrity testing to ensure recoverability.
Broader Implications and Recommendations
The Fairlife incident serves as a stark reminder of the escalating sophistication and persistence of modern ransomware groups. Organizations must adopt a layered security posture that includes: (1) rigorous vulnerability management with prioritized patching of critical flaws such as CitrixBleed 2; (2) enforcement of strong authentication controls, especially for remote access vectors like VPNs; (3) deployment of endpoint detection and response (EDR) tools capable of spotting ransomware‑specific behaviors; (4) implementation of resilient backup strategies that are isolated from the corporate network and verified for integrity; and (5) continuous threat‑intelligence feeding to stay abreast of emerging groups like Anubis and their evolving tactics. By integrating these measures, businesses can reduce the likelihood of successful intrusion, limit the impact of any breach, and improve their ability to recover without yielding to extortion demands.

