Coca-Cola halts US fairlife operations after ransomware breach
SEC filing reveals unauthorised access to production infrastructure; Canadian operations continue unaffected while financial impact remains unclear.

Coca-Cola has suspended operations at its US dairy subsidiary, fairlife, following a ransomware attack that compromised parts of the company’s digital infrastructure. The beverage giant disclosed the incident in a filing with the US Securities and Exchange Commission, confirming that on July 16, 2026, a third party gained unauthorised access to systems linked to production.
The company stated that external cybersecurity experts have been engaged to address the breach and that relevant authorities have been notified. While the full scope and nature of the incident remain under investigation, Coca-Cola emphasised that product quality and safety are not affected by the security event.
Operations at fairlife’s Canadian facilities continue to run normally, providing a partial buffer as the US suspension takes effect. The SEC filing noted that the company is working to resolve the issue, though it did not provide specific details regarding the mechanics of the attack or the extent of the data exposure.
Financial implications for the parent company are currently uncertain. Coca-Cola stated in its filing that it has not yet determined whether the incident is reasonably likely to materially affect the business. The subsidiary reported $4 billion in sales in 2024, highlighting the significant revenue stream at risk during the operational halt.
The suspension of US production is expected to persist until the security issues are fully resolved. Industry observers note that prolonged downtime could impact supply chains, potentially leading to reduced availability of fairlife dairy products in US grocery stores as the company works to restore normal operations.
