fairlife (The Coca-Cola Company) — ransomware halts US dairy production, Item 8.01 8-K
Coca-Cola filed an Item 8.01 8-K on 16 July confirming a ransomware event at dairy subsidiary fairlife that suspended all US production; Canada unaffected.
- Target
- fairlife (The Coca-Cola Company) — ransomware halts US dairy production, Item 8.01 8-K
- Date public
- 16 July 2026
- Sector
- Consumer Goods
- Attack type
- Ransomware
- Threat actor
- Unattributed
- Severity
- High
- Region
- United States (Canada operations unaffected)
The Coca-Cola Company disclosed on 16 July 2026 that fairlife, LLC — the high-protein dairy brand it acquired outright in 2020 — had identified unauthorised third-party access to a portion of its systems, including production-related systems, in connection with a ransomware event. The company filed the disclosure with the US Securities and Exchange Commission as a Form 8-K under Item 8.01, “Other Events”, rather than under Item 1.05, the material-cybersecurity-incident item the SEC introduced in 2023. The filing states that US production operations at fairlife are temporarily suspended, that Canadian production is not affected, and that product quality and safety have not been impacted.
Coca-Cola says it activated its incident response and business continuity protocols on detection, is investigating with the assistance of outside advisers and cybersecurity experts, and has notified law enforcement. As of the initial disclosure the company had not said whether any data was exfiltrated, whether it faces an extortion demand, or which crew is responsible. No ransomware operation has publicly claimed the attack or listed fairlife on an extortion portal.
The disclosure choice carries the editorial weight here. West Pharmaceutical filed an Item 1.05 8-K in May for a broadly comparable production-halting ransomware attack; Coca-Cola, facing a national production stoppage at a wholly owned subsidiary, opted for 8.01. The two items send different signals — 1.05 asserts materiality, 8.01 flags an event without conceding it. Whether an attack that pauses all US output of a growing brand ultimately stays “not material” is a question the next 10-Q, and any restatement of scope, will have to settle.
The operational shape is the familiar geometry of industrial ransomware. An intrusion into a portion of the enterprise reaches production-related systems, and a business-network compromise becomes a plant-floor shutdown. The line between the systems that run the company and the systems that make the product is exactly the surface this class of attack lives on, and the fact that Canadian production kept running while US production stopped suggests that boundary — geographic, network, or both — is where the blast radius was ultimately drawn.
A deep-dive will follow if attribution is published by a primary source, an extortion listing appears, the data-theft question is answered, or the duration of the production halt becomes a measurable number. Until then this is the catalogue’s reference stub for the event.
Sources
- The Coca-Cola Company — Form 8-K, Item 8.01 (16 July 2026, SEC EDGAR) // primary
- BleepingComputer — Coca-Cola says Fairlife ransomware attack halts US dairy production // reporting
- TechCrunch — Coca-Cola suspended production at its Fairlife dairy after a ransomware attack // reporting
- The Register — Ransomware curdles production at Coca-Cola's Fairlife dairy biz // reporting