The notorious Anubis ransomware group has claimed responsibility for a recent cyberattack targeting Fairlife, a subsidiary of Coca-Cola. As the company grapples with the aftermath, the attackers are threatening to release sensitive data unless their ransom demands are met.
Impact on Fairlife’s Operations
Coca-Cola announced last week that Fairlife’s production was halted due to the ransomware incident. The full extent of the damage is still under evaluation, but the disruption has already raised significant concerns within the company.
On July 20, Anubis added both Coca-Cola and Fairlife to its list of victims on its leak site. The group claims to have encrypted the company’s servers and extracted a massive 1 TB of confidential data.
Ransom Demands and Threats
The cybercriminals have reportedly offered to assist Coca-Cola in restoring its systems within a few hours, provided the ransom is paid. The company has been given a one-week deadline to comply, failing which the stolen data may be publicly disclosed.
SecurityWeek has reached out for a statement from Coca-Cola, but no official comment has been provided so far.
Anubis Ransomware’s Tactics
Active since December 2024, the Anubis group has listed approximately 100 organizations as its targets. Their modus operandi involves a double-extortion technique, where they encrypt files and exfiltrate critical data to increase the likelihood of receiving payment.
What distinguishes Anubis from other cybercriminals is its unique ‘wiper mode’ feature. This capability allows them to permanently erase victims’ files, making recovery impossible and further pressuring victims into paying the ransom.
The increasing sophistication of such attacks highlights the growing threat that organizations face from ransomware groups. As the situation unfolds, the cybersecurity community remains vigilant in monitoring and responding to these evolving threats.
