Fairlife, the nutrition and dairy company owned by the Coca-Cola Company, has suspended its U.S. production operations after a ransomware attack compromised a portion of its internal systems, including those tied directly to manufacturing.
Coca-Cola disclosed the incident in a statement released July 16, confirming that an unauthorized third party had gained access to Fairlife systems. The company said it detected the breach and immediately activated its incident response and business continuity protocols. Canadian operations were not affected and continue to run normally. U.S. production, however, has been halted while the company works to understand the full extent of what was accessed and the damage caused.
Fairlife clarified that the attack did not affect the quality or safety of its products. The concern is operational rather than consumer-facing, and the company is treating the disruption as a matter of urgency given its scale.
An attack still being assessed
An investigation is underway with outside cybersecurity experts brought in to assist. Law enforcement has been notified. Coca-Cola acknowledged in its statement that the full scope and impact of the attack remain unknown, a standard acknowledgment in the early stages of ransomware investigations that reflects how long it can take to fully map what was accessed, exfiltrated or compromised during an intrusion of this kind.
Ransomware attacks typically involve malicious software that encrypts a company’s data or systems and renders them inaccessible until a ransom is paid or the affected systems are restored from clean backups. Production-related systems are a common and deliberate target in these attacks because disrupting manufacturing operations creates immediate financial pressure on a company, increasing the likelihood that the victim organization will consider paying to restore access.
Fairlife has not disclosed whether a ransom demand was made or whether it has any intention of meeting one. Those details are common withholdings in the early stages of such incidents, particularly when law enforcement is involved.
Who Fairlife is and why the attack matters
Fairlife is headquartered in Chicago and generates more than $3 billion in annual revenue. The company specializes in lactose-free dairy products, including ultra-filtered milk and high-protein shakes that have found a large and growing consumer base in the health and wellness market. It became a wholly owned subsidiary of Coca-Cola in 2020 and has since grown into one of the beverage giant’s most valuable assets in the nutrition category.
A production shutdown at a company of that size and revenue profile carries meaningful consequences. Supply chain disruptions downstream from a major dairy brand affect retail availability at a national scale, and depending on how long the halt continues, shortages of specific products could follow in the weeks ahead.
A larger pattern in ransomware targeting
Fairlife joins a long and growing list of American companies that have faced ransomware attacks in recent years. A report released earlier this year by a nonprofit organization focused on cybersecurity threat sharing found that ransomware attacks were highly concentrated against companies operating in the United States. The trend reflects both the scale of the American economy and the willingness of organized criminal groups, some state-affiliated, to target major brands for maximum financial leverage.
The food and beverage sector has been hit repeatedly in recent years, with several high-profile incidents affecting processing plants and supply chains. The pattern has prompted warnings from federal cybersecurity agencies about the vulnerability of critical infrastructure and the importance of robust backup systems that can allow companies to restore operations without meeting ransom demands.
For Fairlife and Coca-Cola, the immediate priority is restoring U.S. production and containing the financial and reputational impact of a disruption that arrived without warning and has yet to fully reveal its scale.

