he Importance of Holistic Cybersecurity for the Food and Beverage Manufacturing Industry
Privacy secure. Network security technology with computer processor chip on digital motherboard background. Protect personal data and privacy from hacker cyberattack.

Key takeaways:

  • Coca-Cola’s own SEC filings on the Fairlife ransomware attack never use the words “IT” or “OT.” Nearly two weeks in, the company still hasn’t said whether attackers reached the plant floor, or whether production stopped because the systems that feed the plant floor went dark first.
  • In most food and beverage plants, the people who could answer that question cleanly sit in operations, not IT, because production execution systems and corporate networks are more connected than the organizational chart admits.
  • Fairlife’s incident marks the second time this has happened to a major US food company. JBS Foods answered the same question in 2021, and it cost $11 million.

On July 16, 2026, Coca-Cola told the SEC that Fairlife had found “unauthorized access by a third party to a portion of its systems, including its production-related systems, in connection with a ransomware event.” That single phrase, “production-related systems,” is doing a lot of work, because it’s the closest the company has come to saying what was actually hit.

US production stopped. Canada kept running. By July 28, Coca-Cola reported “significant progress”, with the majority of production resumed at Fairlife’s four US facilities and retail supply “largely unimpacted” on existing inventory. The company also confirmed data was taken, without saying how much or what kind. A ransomware group calling itself Anubis claimed credit on its leak site around July 20 and put the number at 1 terabyte. Coca-Cola hasn’t confirmed that group or that figure, and it’s worth remembering that extortion groups routinely inflate what they’ve stolen to pressure a payout.

What Coca-Cola has actually said, word for word

If we strip out the news coverage and go back to the filing itself, production-related systems were accessed, product quality and safety were not affected, law enforcement was notified, and the company “has not yet determined whether the incident is reasonably likely to materially affect” its business. There’s no ransom figure, no confirmed attacker, and no explanation of how the attacker got in, and that’s not an oversight. Companies disclose what they can defend under securities law, and right now that’s the outer edge of what they know for certain.

What the filing never says, in either the July 16 or July 28 update, is “IT” or “OT.” 

The sentence you should reread

“Production-related systems” could mean the enterprise software that schedules a run and logs the batch, the programmable controllers and SCADA systems actually driving a pasteurizer or a filler, or both, connected closely enough that losing one takes down the other. ShieldWorkz’s technical read on the incident walks through why a dairy plant would stop even if the physical controllers were never touched. If the manufacturing execution system that issues batch and recipe instructions gets encrypted, or the database that logs pasteurization temperatures for federal food safety compliance goes dark, a line can’t legally keep running blind. That’s informed speculation from an outside security firm, not something Coca-Cola has confirmed, but it points at the real issue. In a modern plant, IT and OT are close enough that “which one got hit” is often the wrong question. The right one is which dependency broke first.

That’s exactly why this usually isn’t an IT team’s question to answer alone. IT owns the network and the servers. Operations owns the knowledge of which specific system, on which specific line, has to be running for product to move, and what happens the moment that system goes quiet. Ask your own plant manager, not your CISO, what stops first if the plant’s connection to the corporate network gets cut right now. If the honest answer is “we’re not sure,” that’s the same gap Fairlife’s public disclosures are showing everyone right now.

Why Canada is the most interesting detail in the whole filing

Canadian Fairlife operations ran the entire time. Coca-Cola hasn’t explained why, but the most likely reason is boring and reassuring: separate infrastructure. A Canadian plant on its own network, its own credentials, and its own systems doesn’t go down because a US corporate domain got compromised. That’s the entire argument for segmentation in one real-world data point: the plants that were architecturally isolated from the incident kept making milk.

This is the second time, not the first

Food and beverage manufacturing has already run this experiment. In May 2021, REvil ransomware hit JBS Foods, the world’s largest meat processor. Nine US plants stopped. Plants in Australia stopped too. JBS paid $11 million to get back online, after the attackers first asked for $22 million. At the time, JBS accounted for close to a quarter of US beef processing capacity, so a few idle days moved the entire supply chain. Five years and one ransomware-as-a-service ecosystem later, a different company, a different attacker group, and largely the same shape of outcome: production down, data taken, a payment negotiation nobody wanted to be having.

The pattern here isn’t bad IT departments so much as an industry running plants with decades-old control systems bolted onto newer enterprise software, on a factory floor that increasingly talks to the cloud for reasons that have nothing to do with security. Predictive maintenance sensors, computer vision quality checks on the line, AI-driven scheduling tools: all of it adds another connection between the plant floor and the outside network, usually justified purely on the productivity case. Every one of those projects is also, quietly, an OT security decision, whether or not anyone in the room framed it that way.

What F&B leaders can do this week

You don’t need Fairlife’s incident response bill to learn this lesson, just one conversation. Ask whoever runs your plant floor what happens, specifically, if the connection between that plant and the corporate network gets severed. Which systems keep the line running, which ones force a stop for food-safety reasons, and how long can you operate on the manual fallback before it becomes its own risk? If no one in the room can answer that in specifics, you’ve just found out for free what Fairlife’s customers, and its board, are finding out the expensive way.

Supplier Catalog - Software - CAI Software