Fairlife, the dairy subsidiary of The Coca-Cola Company, has temporarily suspended production across its US operations following a ransomware attack that affected parts of its information technology systems, including elements of its production processes.
The company, which reported $4 billion in sales in 2024, said unauthorised actors gained access to portions of its IT environment. Fairlife has engaged external cybersecurity specialists to investigate the incident and has notified law enforcement.
Production paused while investigation continues
In a statement, Fairlife said product quality and consumer safety have not been affected by the cyberattack.
The company confirmed:
- US production operations have been temporarily suspended.
- Canadian operations continue to operate normally.
- Product quality and safety have not been impacted.
- External cybersecurity experts have been appointed to investigate the incident.
- Law enforcement agencies have been notified.
Fairlife added it is working to restore affected systems and resume operations as quickly as possible but did not provide a timeline for restarting production.
Ransomware disrupted production systems
According to the company, the ransomware attack resulted in unauthorised access to parts of its IT infrastructure, including systems supporting production operations.
While many cyberattacks focus on stealing sensitive corporate or customer information, attacks targeting operational technology can interrupt manufacturing and business continuity.
The incident highlights how cyber threats are increasingly affecting physical production environments in addition to digital assets.
Manufacturers remain frequent targets
The Fairlife incident follows several cyber incidents involving major consumer-facing companies in recent months.
Among them:
- Rich Products Corporation disclosed a phishing-related data breach in May. According to filings with the attorneys general of New Hampshire and Massachusetts, compromised information included names, dates of birth, Social Security numbers and driver's licence numbers.
- Nike investigated a potential cybersecurity incident in January after the ransomware group World Leaks claimed it had published 1.4 terabytes of company data online.
- Carnival Corporation disclosed a cyberattack linked to a compromised employee account. According to the Maine Attorney General's Office, the breach affected nearly 6 million people and exposed names, addresses and government identification numbers.
The incidents reflect a broader trend of cybercriminals targeting organisations across manufacturing, consumer goods and travel industries.
Operational technology faces growing cyber risks
Cybersecurity experts have increasingly warned that ransomware attacks are evolving beyond traditional data theft.
Modern ransomware campaigns often involve so-called double extortion, where attackers first steal sensitive information before encrypting systems and demanding payment, threatening to publish stolen data if the ransom is not paid.
For manufacturers, attacks on operational technology can have immediate business consequences by disrupting production, delaying deliveries and affecting supply chains.
As Fairlife continues its investigation and system recovery efforts, the incident underscores the growing importance of cyber resilience for companies operating critical manufacturing infrastructure. With production temporarily halted in the United States, the company now faces the dual challenge of restoring operations while strengthening defences against future cyber threats.
