Ransomware attack halts Coca-Cola's Fairlife dairy production in the US

Coca-Cola has confirmed that dairy production at its Fairlife unit will 'remain suspended' in the United States following a ransomware attack, halting output at a business that produces the company's high-protein milk brand, a fast-growing part of its portfolio in recent years. The company has not said when it expects production to resume.
Ransomware attacks work by encrypting a target organization's computer systems and data, with attackers demanding payment in exchange for a decryption key. When the affected systems control physical manufacturing equipment rather than just office computers, as is common in food and beverage plants, an attack can halt production lines entirely rather than simply disrupting back-office operations.
Coca-Cola has not publicly detailed which specific systems were compromised or attributed the attack to a particular group, both common practices in the early stages of an active incident response, when companies are often still working with cybersecurity investigators to understand the scope of a breach before disclosing further detail that could complicate negotiations or recovery.
The incident adds to a run of cyberattacks against food and beverage manufacturers in recent years, a sector security researchers describe as an increasingly attractive target for ransomware groups precisely because production delays are costly and highly visible, giving attackers leverage to pressure a quick ransom payment rather than a prolonged recovery.
A widely cited earlier case involved JBS, one of the world's largest meat processors, which paid an $11 million ransom in 2021 after an attack disrupted operations across multiple countries — an episode that prompted US government agencies to issue specific guidance to food and agriculture companies about ransomware preparedness in the years since.
Security researchers point to a structural vulnerability specific to manufacturing: many food production facilities run operational technology — the specialized computer systems that control physical equipment like mixers, packaging lines and refrigeration — that is older, harder to patch, and less consistently monitored than standard corporate IT systems, making it a comparatively soft target once attackers gain a foothold in a company's network.
For Coca-Cola and Fairlife, the immediate consequence is a gap in supply of Fairlife-branded products to US retailers for as long as production remains halted, though the company has not detailed how long that gap is expected to last or how it plans to manage distribution to existing retail partners in the meantime.
The US government has increasingly classified food and agriculture as critical infrastructure for cybersecurity purposes, a designation that brings additional federal reporting requirements and, in some cases, coordination support from agencies such as the Cybersecurity and Infrastructure Security Agency when a major producer is hit.
Cybersecurity specialists generally advise affected companies against paying ransoms, noting that payment neither guarantees full data recovery nor prevents attackers from striking the same organization again, though the advice is frequently weighed against the immediate commercial pressure of extended production downtime, which can run into significant daily losses for a large manufacturer.
Coca-Cola said it is working to restore operations at the Fairlife facility, without providing a specific timeline. The incident is likely to renew scrutiny of cybersecurity investment across the food manufacturing sector, where researchers say the gap between the potential cost of an attack and the cost of hardening operational technology systems in advance remains a persistent challenge for companies balancing security spending against other priorities.
Read next

Agent swarms explained: how running many AI models at once is reshaping cost economics
A growing number of AI coding tools now dispatch dozens of AI agents to work on a task in parallel rather than relying on a single model. Here is what an 'agent swarm' actually is, why it changes the cost calculus of building software with AI, and what tradeoffs it introduces.

AliExpress hit with record $625m EU fine over unsafe toys and cosmetics
The European Union has fined AliExpress a record $625 million under its Digital Services Act after the online marketplace failed to remove listings for unsafe toys and dangerous cosmetics despite repeated warnings. The company says it is shocked by the size of the penalty.

SpaceX in your index fund, explained
Index funds are marketed as one of the safest, most passive ways to invest, spreading risk across the whole market rather than betting on individual companies. As SpaceX moves toward a stock market listing at a valuation of roughly $1.77 trillion, ordinary index fund investors may end up owning a slice of it, whether they intended to or not.

Why is Google building its own AI chip, and what would it mean for Gemini
Google's parent company Alphabet is reportedly developing a new chip aimed at making its Gemini AI models run far more efficiently. Here is why custom silicon matters so much to AI companies right now, and what a more efficient Gemini could mean for costs and capability.

Anthropic's landmark $1.5bn AI copyright settlement gets final approval
A US court has given final approval to Anthropic's $1.5 billion settlement over its use of copyrighted books to train AI models, closing one of the most closely watched legal cases in the AI industry. The deal resolves this specific dispute but leaves the broader question of AI training and copyright unsettled.