Coca-Cola has revealed that a ransomware attack on its Fairlife dairy subsidiary disrupted operations and temporarily halted the production of Fairlife products across the USA. Fairlife produces ultra-filtered milk products, protein shakes, and nutrition drinks sold in the United States
The breach was revealed when Coca-Cola filed a Form 8-K filing with the U.S. Securities and Exchange Commission (SEC) stating that Fairlife detected unauthorised access to some of its systems, including its production-related systems. Coca-Cola says it promptly activated its incident response and business continuity protocols and that a full investigation into the incident’s impact is ongoing.
Ransomware attacks are on the rise
No ransomware group has yet claimed responsibility for the incident, but it is the latest in a string of attacks on high-profile retailers and brands. M&S, Harrods, Jaguar Land Rover, The Co-operative Group and JD Sports are among those who’ve been targeted – and faced serious operational and financial problems as a consequence.
As reports of ransomware attacks rise, the question is: are retailers ready? Not according to Crowdstrike’s recent State of Ransomware report, which found that a staggering 76% of organisations report a growing disconnect between how leadership and the security team perceive their ransomware readiness.
Crowdstrike suryeyed over 1,100 IT and cybersecurity decision-makers across Australia, France, Germany, India, Singapore, United Kingdom, and United States, and found that 78% had experienced a ransomware attack within the past year. While more than half (54%) of board members and C-level executives said that their organisations were “very prepared” to face a ransomware attack, just 46% of security teams shared that confidence.
The cost of ransomware attacks can be significant, with the downtime alone estimated at $1.7 million (£1.27 million) per incident by Crowdstrike. Victims also face reputational damage and often legal and regulatory penalties, and publicly released or stolen data carries an ongoing competitive and compliance risk.
Changing risk profiles
Commenting on the Coca-Cola incident, Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, said the attack highlights the unique risks facing operational technology (OT) environments: “What this incident reinforces is something the food and beverage sector has been warned about repeatedly: operational technology environments, the systems that run production lines, manage manufacturing processes, and control physical infrastructure, carry a fundamentally different risk profile to traditional IT.
He added: “When those systems go down, the impact isn’t measured in data loss. It’s measured in business impact with halted production, wasted inventory, and supply chain disruption that cascades outward fast. Ransomware groups know this. The leverage in hitting an OT environment is immediate and tangible in a way that stealing data often isn’t.”
The Coca-Cola Fairlife incident serves as another reminder that ransomware is no longer just an IT problem. As attackers increasingly target operational systems, organisations face the prospect of production stoppages, supply chain disruption and mounting financial losses. For manufacturers and retailers alike, strengthening cyber resilience across both IT and OT environments is becoming a business-critical priority rather than a purely technical concern.
Stay informed
Our editor carefully curates two newsletters a week filled with up-to-date news, analysis and research. Click here to subscribe to the FREE newsletter sent straight to your inbox. Why not follow us on LinkedIn to receive the latest updates on our research and analysis?




