LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surface
Recent BreachesData breach tracker

Recent Breaches › Coca-Cola / Fairlife Listed by anubis Ransomware Group

HIGH severityUnverified claimHow we verify

Coca-Cola / Fairlife Listed by anubis Ransomware Group: What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 27, 2026
Coca-Cola / Fairlife Listed by anubis Ransomware Group

Reported July 27, 2026.

HIGH
Severity
1
Data types exposed
July 27, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Coca-Cola / Fairlife was listed by the anubis ransomware group on July 27, 2026, after internal files were exfiltrated in a ransomware attack; the actual date of the intrusion has not been established. Individuals are advised to check whether their data may have been exposed and to take appropriate protective steps.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Was your email in the Coca-Cola / Fairlife Listed by anubis Ransomware Group breach?
See every leak tied to your email — not just this one. 15-second check, no card, no account.

On July 27, 2026, the ransomware group known as anubis listed Coca-Cola, specifically in connection with Fairlife, a company owned by Coca-Cola, on its leak site. Public reporting describes the matter as a major data breach involving the exfiltration of internal files in a ransomware attack. The number of people affected remains unknown, and many operational details have not been disclosed.

What is confirmed so far is limited to the group's claim and the high-level description of internal files taken during the incident. For employees, partners, and others who may have ties to Coca-Cola or Fairlife, the listing raises ordinary questions about what was exposed and what practical steps follow, even while the full scope stays unconfirmed.

Inside the incident

According to the available record, anubis listed Coca-Cola / Fairlife and associated the event with a ransomware attack in which internal files were exfiltrated. The reported date for the listing is July 27, 2026. Public detail does not establish when the intrusion began, how long attackers may have had access, which systems were involved, or whether a ransom demand was paid or refused.

The scale of the incident is undisclosed. No figure has been given for the volume of data taken, the number of systems affected, or the number of individuals whose information may appear in the material. The facts state only that internal files were exfiltrated and that the matter has been characterized as a major data breach at a company owned by Coca-Cola. Method of initial access, lateral movement, and any encryption of production systems are not described in the public summary. Until Coca-Cola, Fairlife, or independent investigators release further verified information, those elements remain unknown.

Inside anubis

Anubis is a ransomware operation that has appeared in public reporting as a group that conducts double-extortion style campaigns: encrypting or disrupting systems while also claiming to steal data and threatening to publish it if demands are not met. Like other groups in this category, anubis has used dedicated leak sites to name victims and, in some cases, to stage samples or larger dumps of allegedly stolen material. Such listings are claims by the actors; they are not independent confirmation that every file described was taken or that every named organization suffered the full impact asserted.

Public knowledge of anubis centers on its pattern of targeting organizations across sectors, posting victim names to pressure payment, and relying on the reputational and regulatory cost of a data leak. Nothing in the facts supplied for this incident goes beyond the leak-site listing and the description of internal files exfiltrated in a ransomware attack. Any specific statements anubis may have made about Coca-Cola or Fairlife beyond that listing are not part of the verified record used here, and the listing itself should be treated as an unverified claim unless corroborated by the victim or other authoritative sources.

Coca-Cola and its sector

Coca-Cola is one of the world's best-known beverage companies, with a global footprint in manufacturing, distribution, marketing, and brand licensing. Fairlife is a Coca-Cola-owned business focused on dairy and related consumer products. Organizations of this type typically maintain extensive internal records: employee and contractor data, supplier and distributor contracts, manufacturing and logistics information, marketing plans, financial and operational documents, and customer or consumer-related datasets tied to promotions, loyalty, or direct sales channels.

A breach affecting a company in this sector matters because the same systems that support large-scale production and retail relationships often hold personal data on staff and business contacts, as well as commercially sensitive material. Even when the exact contents of a theft remain unconfirmed, the combination of a household-name brand and a ransomware group's public listing can create lasting concern for people whose details may have been stored in corporate environments, and for the organization itself in terms of trust, regulatory scrutiny, and operational continuity.

What data was at risk

The facts name the exposed material as internal files exfiltrated in a ransomware attack. No further breakdown—such as whether those files included human-resources records, customer lists, financial documents, intellectual property, or technical schematics—has been disclosed. The number of people affected is unknown.

Companies of Coca-Cola's and Fairlife's size and type commonly hold employee names and contact details, payroll and benefits information, vendor and partner records, internal correspondence, and various categories of consumer or trade-customer data. It is reasonable to note that such categories are typical; it is not established that any specific category was present in the files anubis claims to have taken. Exact contents remain unconfirmed, and no inventory of the exfiltrated material has been published in the record provided.

The real-world impact

For individuals, the primary risks when internal corporate files are stolen are misuse of personal information that may appear in those files—such as names, addresses, phone numbers, email addresses, or employment-related identifiers—and secondary harms like phishing, social engineering, or identity fraud that build on leaked context. Because the people-affected count is unknown and the file contents are not itemized, it is not possible to say who is directly exposed or how sensitive any given record set may be.

For the organization, consequences can include investigative and recovery costs, potential regulatory notification duties depending on jurisdiction and data types, strain on partner and employee trust, and the operational disruption that often accompanies ransomware events. A public listing by a ransomware group can also prolong attention on the incident even when technical containment is complete. None of these outcomes are asserted here as proven results of this specific event; they are the ordinary categories of impact that follow when internal files are claimed to have been exfiltrated at scale.

What to do if you're exposed

If you have a past or present relationship with Coca-Cola or Fairlife—as an employee, contractor, supplier contact, or customer—and you are concerned your information may have been involved, start with basic precautions. Monitor financial and account statements for unfamiliar activity. Treat unexpected emails, calls, or messages that reference the company or the breach with caution, and verify any request for personal data or credentials through official channels you already trust. Consider placing fraud alerts or credit freezes if you believe sensitive identity data could be at risk, following the processes available in your country.

Where your employer or the company provides official guidance or credit-monitoring offers, read those notices carefully and use only the contacts they publish. You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach datasets, which can help you decide how closely to watch particular accounts. Public detail on this incident remains limited; staying alert to verified updates from Coca-Cola or Fairlife is the most reliable way to learn whether your data was among the internal files claimed to have been taken.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyCoca-Cola security record
43/100
DoxxScan™ · Elevated doxx risk
C+ 71Fair record

4 reported incidents on record.

See Coca-Cola’s full breach history →
RelatedMore incidents at Coca-Cola

More recent breaches

Fairlife / Coca-Cola Listed by anubis Ransomware GroupJuly 20, 2026Eagle Crest Communities Listed by anubis Ransomware GroupJuly 26, 2026Bath Fitter Listed by anubis Ransomware GroupJuly 20, 2026Law Offices of Thomas J Skinner, IV Listed by anubis Ransomware GroupFebruary 3, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Coca-Cola / Fairlife Listed by anubis Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by anubis — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram