HomeIntelligenceBrief
BREACH BRIEF🟠 High Ransomware

Anubis Ransomware Claims Coca‑Cola Fairlife Attack, Threatens 1 TB Data Leak

Anubis ransomware says it encrypted Fairlife’s Nutanix systems and stole about 1 TB of corporate data, threatening public release unless a ransom is paid. The claim underscores the need for SOC 2‑aligned incident response, backup integrity, and third‑party risk monitoring.

LiveThreat™ Intelligence · 📅 July 22, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
RW
Type
Ransomware
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Anubis Ransomware Claims Coca‑Cola Fairlife Attack, Threatens 1 TB Data Leak

What Happened — The Anubis ransomware‑as‑a‑service gang announced that it had encrypted Nutanix infrastructure at Fairlife, the dairy subsidiary of The Coca‑Cola Company, and exfiltrated roughly one terabyte of corporate data. The group posted the claim on a dark‑web leak site and warned it would publish the data unless a ransom is paid.

Why It Matters for Compliance & Audit Readiness

  • The incident tests the effectiveness of SOC 2 CC6.1 (System Operations) and CC7.1 (Incident Management) controls that require documented response plans and evidence of execution.
  • Data‑theft extortion highlights the need for continuous monitoring of encryption keys, backup integrity, and proof that decryption or restoration can be performed without paying a ransom.
  • Demonstrating that you have auditable logs, third‑party risk assessments for cloud providers (e.g., Nutanix), and a documented breach‑notification process is essential for a defensible SOC 2 audit.

Who Is Affected – Food & beverage manufacturers, dairy processors, and any organization that relies on shared‑infrastructure cloud platforms for production systems.

Recommended Actions

  • Map the incident to SOC 2 CC6.1 and CC7.1 controls; collect system logs, encryption key management records, and backup verification as audit evidence.
  • Validate that Nutanix backups are immutable and can be restored without the attacker’s key; perform a tabletop ransomware response drill.
  • Review third‑party risk documentation for the Nutanix service, ensuring continuous monitoring and contractual security clauses are in place.

Source: BleepingComputer

Technical Notes – The gang claims to have fully encrypted Fairlife’s Nutanix environment and stolen ~1 TB of data; the claim has not been independently verified. No specific CVE is cited; the attack vector is ransomware‑driven malware that combines encryption with data exfiltration. Source: same as above

📰 Original Source
https://www.bleepingcomputer.com/news/security/anubis-ransomware-claims-coca-cola-fairlife-attack-threatens-data-leak/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →