Anubis Ransomware Claims Coca‑Cola Fairlife Attack, Threatens 1 TB Data Leak
What Happened — The Anubis ransomware‑as‑a‑service gang announced that it had encrypted Nutanix infrastructure at Fairlife, the dairy subsidiary of The Coca‑Cola Company, and exfiltrated roughly one terabyte of corporate data. The group posted the claim on a dark‑web leak site and warned it would publish the data unless a ransom is paid.
Why It Matters for Compliance & Audit Readiness
- The incident tests the effectiveness of SOC 2 CC6.1 (System Operations) and CC7.1 (Incident Management) controls that require documented response plans and evidence of execution.
- Data‑theft extortion highlights the need for continuous monitoring of encryption keys, backup integrity, and proof that decryption or restoration can be performed without paying a ransom.
- Demonstrating that you have auditable logs, third‑party risk assessments for cloud providers (e.g., Nutanix), and a documented breach‑notification process is essential for a defensible SOC 2 audit.
Who Is Affected – Food & beverage manufacturers, dairy processors, and any organization that relies on shared‑infrastructure cloud platforms for production systems.
Recommended Actions –
- Map the incident to SOC 2 CC6.1 and CC7.1 controls; collect system logs, encryption key management records, and backup verification as audit evidence.
- Validate that Nutanix backups are immutable and can be restored without the attacker’s key; perform a tabletop ransomware response drill.
- Review third‑party risk documentation for the Nutanix service, ensuring continuous monitoring and contractual security clauses are in place.
Source: BleepingComputer
Technical Notes – The gang claims to have fully encrypted Fairlife’s Nutanix environment and stolen ~1 TB of data; the claim has not been independently verified. No specific CVE is cited; the attack vector is ransomware‑driven malware that combines encryption with data exfiltration. Source: same as above