Hackers Hit Coca-Cola's Fairlife Milk Brand, Stopping U.S. Production

Coca-Cola disclosed in a government filing on July 16, 2026 that its Fairlife dairy subsidiary was hit by ransomware, forcing a temporary halt to production across the United States (TechCrunch).
Ransomware is a type of malicious software that locks up a victim's computer systems by scrambling their data. The attackers then demand payment, usually in cryptocurrency, to unlock it. In this case, the attack hit the systems Fairlife uses to run its production facilities.
Fairlife is one of Coca-Cola's major brands, with about $4 billion in sales as of 2024. The company makes ultra-filtered milk and protein drinks sold under the Fairlife and Core Power names. A nationwide production halt for a brand that size carries immediate consequences for retailers, distributors, and food-service customers across the United States.
Coca-Cola did not say when production would restart. Fairlife's operations in Canada remain unaffected, according to TechCrunch's reporting.
The company disclosed the attack through a filing with the SEC, the U.S. government agency that oversees publicly traded companies. Since 2023, SEC rules require companies to report serious cybersecurity incidents within four business days of deciding the incident is significant enough to matter to investors. The July 16 filing suggests Coca-Cola recently made that determination, though the timeline of the attack itself, including when it began and when it was detected, has not been publicly detailed.
Several important details remain undisclosed. Coca-Cola has not identified who carried out the attack, which specific systems were compromised, whether any data was stolen, or whether the attackers demanded a ransom. The company has also not provided an estimated timeline for getting production back up and running.
What the filing does make clear is the scope: all U.S. production at Fairlife is suspended, and Canadian operations are intact. That split suggests the ransomware hit systems specific to U.S. facilities rather than a shared network spanning both countries, though this has not been confirmed.
Ransomware attacks on manufacturing and food-production companies have been a recurring pattern in recent years. Attackers often target industrial operations because when a factory stops running, the victim loses money every hour, which increases the pressure to pay. Production systems can be forced into shutdown even when the ransomware affects office computers rather than the factory equipment directly, as long as those networks are connected.
The financial stakes are real. A brand doing roughly $4 billion in annual sales generates over $10 million per day in revenue. Even a partial-week suspension could mean meaningful lost production, though the full impact will depend on how quickly Coca-Cola can restore its systems and whether existing inventory or Canadian production can fill the gap.
Coca-Cola has not commented beyond the SEC filing, and no further technical details have been released. The company's next disclosure will likely focus on restoration progress and any updated assessment of the incident's impact.
The broader context here is about how companies report cyberattacks. The SEC's cybersecurity disclosure rules, now in effect for over two years, are doing what they were designed to do: pushing serious incidents into a regulated, time-bound reporting framework instead of letting companies handle them quietly. But whether these disclosures are detailed enough to be useful to anyone beyond shareholders is an open question. This filing tells investors that something happened and that it matters. It tells security professionals almost nothing they can act on. That gap is not Coca-Cola's fault specifically; it is a built-in feature of the current rules, which prioritize telling investors over sharing technical details. As ransomware attacks become more frequent and more disruptive, regulators will likely need to revisit whether that balance still works.
For now, Fairlife's U.S. production lines are offline. The timeline for their return is unknown.


