Technology

Ransomware Attack Forces Coca-Cola to Shut Down Fairlife Production Across the U.S.

Coca-Cola has suffered a ransomware attack that has caused it to suspend production at its Fairlife dairy facilities across the United States.

It shows how vulnerable manufacturing efforts can be in the age of growing cyberattacks.

The company has stated that consumer safety and product quality have not been affected. Canadian manufacturing facilities have continued to operate as usual.

It’s not yet known when the US factory will continue its operations.

What Happened at Fairlife?

The Coca-Cola Company has disclosed that there was an attack on its technology systems that came through unauthorized access.

The company activated the response plan designed to address such attacks.

It isolated affected systems and temporarily suspended production to prevent further disruption. The company is also running an investigation into the origins of the attacks.

Coca-Cola has brought in outside experts to contain the incident and to restore the system to full functionality. They’ve also notified law enforcement agencies, which launched a formal investigation.

They investigate who committed the attack, but also how the attackers gained access and what information or systems may have been compromised.

Ransomware attacks include both data theft and encryption of critical systems. However, Coca-Cola still hasn’t announced that any data was stolen.

It has also not disclosed the group that asked for ransom, if any such demand was made at all.

Why Production Was Suspended

Manufacturing relies on digital systems to run everything from inventory and scheduling to automated production lines.

There was no choice left but to stop production altogether once the ransomware attack started.

The pause is also used to investigate the breach, remove any malicious software, and restore systems.

“The food and agriculture sector has been pulled into the same broad, opportunistic targeting that hits every other sector,” Scott Algeier, executive director of the Food and Ag-ISAC, said.

“While some adversaries may be targeting the sector, they scan for exposed, vulnerable systems at machine speed and determine the victim’s details after initial access.”

Retailers and distributors have not been affected by the attack as of yet. But the production suspension can affect them if they start experiencing shortages.

The distribution systems are made to cover short-term shortages, but they are also very efficient and don’t store enough goods to cover the suspension of production, such as this one.

Why Fairlife Matters to Coca-Cola

Coca-Cola acquired its remaining 57% stake in Fairlife in 2020, following a joint venture with Select Milk Producers.

In March, it announced a $650 million investment to expand its facilities in Coopersville, Mich. 

Fairlife has expanded rapidly as consumer demand for high-protein and functional drinks has increased. The brand generates billions of dollars annually selling ultra-filtered milk, protein shakes, and nutrition-focused beverages.

Due to its size and importance for the Coca-Cola brand, the developments could have an impact on the bottom line for both brands.

Besides the loss in sales, the company will also have additional expenses covering cybersecurity investigations, system restoration, and enhanced security measures.

A Growing Trend: Ransomware Hits Food Manufacturers

Digital ransomware attacks have been common in some industries, but they’ve reached food manufacturers in recent years.

For instance, Bitcoin casinos have been among the first to introduce comprehensive measures to protect their players’ wallets.

Using cryptos as a payment method for gambling allows for fast and secure transfers, but they can be vulnerable to cyber-attacks.

Experts such as those from CryptoManiaks have also written about the increase in scrutiny coming from regulatory agencies that have increased the security measures for online gambling.

Several major food companies have faced similar incidents in recent years. Meat processor JBS also had to close down production for a while, and Fresh produce company Dole also experienced production and distribution issues following a cyber-attack.

UNFI wasn’t able to complete deliveries due to an attack.

What Happens Next?

We know very little about the timeline for the next moves. The company hasn’t released a schedule for when it plans to reopen production, and it will be closed during the investigation and updating the system.

We also don’t know how the investigation will progress. Much of it depends on the work of law enforcement and not Coca-Cola itself.

The industry, including retailers, investors, and cybersecurity experts, will monitor the situation closely, as it may become a standard for how others will handle such attacks.

Some of the most sophisticated consumer brands out there can soon experience a similar problem, and it can affect millions of customers.

Kavichselvan

Kavichselvan is a Cybersecurity Enthusiast and Journalist covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago